Privacy Policy
Last updated: 28 July 2026
Bivy is a local-first, open-source AI agent workspace that runs on your own machine. For launch, Bivy Cloud is the hosted control plane and relay; it is not a hosted AI inference service. This policy explains what the hosted services do and do not collect. It does not apply to software you run entirely on your own hardware without signing in to the hosted service.
What we collect
| Data | Why |
|---|---|
| Email address | To create your account and send passwordless magic-link sign-in emails. |
| Billing data (via Stripe) | If you subscribe, Stripe processes your payment. We store your Stripe customer and subscription identifiers, plan, and subscription status — not your card details. |
| Machine registry metadata | The identifier and display name you give each machine, plus online/offline status and last-seen time, so you can manage your machines. |
| Session/work metadata | Optional cross-machine session and webhook/work-queue metadata such as machine id, session id, status, repo slug, issue number, and timestamps. This is routing metadata, not transcript content. |
| Encrypted credential sync blobs | If enabled, machines may upload encrypted model-auth vault ciphertext and per-machine wrapped keys so another enrolled machine can sync credentials. Bivy Cloud cannot decrypt these blobs. |
| Operational logs | Connection counts, timestamps, and privacy-safe product milestones used to keep the service running, understand activation, and detect abuse. These never contain session payloads, prompts, account identifiers, or email addresses. |
| Aggregate website usage | Cookie-free page views and actions such as clicking Start free or copying the install command, collected through Plausible Analytics. We use this to understand whether the website helps visitors get started; it is not joined to product accounts or session activity. |
What we never collect
- The content of your agent sessions — prompts, responses, files, or tool output.
- Your plaintext model provider API keys, provider OAuth tokens, GitHub repo tokens, or other local secrets.
- Agent transcripts, terminal output, prompts you type into an active session, workspace files, or tool output.
- Your model calls: Bivy Cloud does not proxy normal AI inference at launch.
- The end-to-end encryption keys used between your machine and your devices (the relay never holds them).
Third parties we share data with
- Stripe — payment processing and subscription management (privacy policy).
- Resend — delivery of sign-in and account emails (privacy policy).
- Plausible Analytics — cookie-free, aggregate marketing-site analytics (privacy policy).
- Our hosting provider — runs the control plane and relay servers.
We do not sell your personal data.
Cookies and local storage
The web and remote-control interfaces store a session token in your browser's local storage to keep you signed in. The marketing site uses cookie-free Plausible Analytics. We do not use third-party advertising or tracking cookies, and Plausible events are not linked to your Bivy account.
Data retention
We keep account and machine metadata for as long as your account is active. Magic-link and connection tokens are short-lived and expire automatically. When you delete your account, we remove your account and machine metadata; billing records may be retained where required by law.
Data controller
The data controller for the hosted services is Sjulstad Labs (Norwegian organization number 923640940), Norway. For any privacy or data-protection question, contact us at support@bivy.sh.
Your rights
Depending on where you live (including the EU/EEA under the GDPR), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict its processing. To exercise these rights, contact the data controller, Sjulstad Labs, at support@bivy.sh.
Work queues
For GitHub issue and comment jobs, the hosted control plane retains routing metadata such as repository, issue number, target machine, status, and timestamps. It does not retain the issue title or body; the claiming machine fetches that content directly from GitHub immediately before running. Sanitized outcome reports contain allowlisted routing, check, retry, branch, and pull-request metadata — never prompts, transcripts, diffs, file contents, secrets, or raw tool output.
Changes
We may update this policy from time to time. Material changes will be reflected by the "last updated" date above.
Contact
Questions about privacy? Email support@bivy.sh. The hosted services are operated by Sjulstad Labs (Norwegian organization number 923640940), Norway.