Privacy Policy
Last updated: 15 July 2026
1. Overview
2. What we collect
- Account data: your name, email, and profile photo from Google sign-in.
- Connected-system data: read-only metadata about your cloud resources, repositories, deployments, and dependencies, used to build your graph. This can include personal data such as commit and pull-request author names, and ticket assignees.
- Usage data: logs and events needed to operate, secure, and improve the Service.
3. How we use it
4. Read-only by design
5. Service providers
We use a small number of vetted providers to run the Service - managed database and file storage, cloud hosting, transactional email, and payment processing. Each is bound by data-protection obligations consistent with this policy, and none of them is permitted to use your data for their own purposes.
A current list of these providers, and the role each one plays, is available to customers and to anyone conducting a security review on request.
AI processing works one of two ways, and which one applies to you depends on a setting you control. If your organization configures its own AI provider (bring-your-own key), the relevant context is sent to that provider under your agreement with them, not ours. If it does not, questions are answered using an AI provider engaged by Atlex, under our agreement with them. In both cases only the context needed to answer the question is sent, and no AI provider we engage is permitted to train on your data.
You can see which applies at any time in Settings, and switching to your own provider takes effect immediately.