Privacy Policy
Last updated: May 15, 2026
Tavryne AI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our browser-based AI coding platform. Please read this policy carefully. By using Tavryne AI, you consent to the data practices described in this policy.
If you do not agree with the terms of this Privacy Policy, please do not access or use the platform. We reserve the right to update this policy at any time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date.
1. Information We Collect
We collect several categories of information to provide, improve, and secure our platform:
1.1 Information You Provide Directly
- Account Information: When you register, we collect your email address, display name, and profile photo (if you choose to provide one). If you sign up using Google or GitHub OAuth, we receive the profile information associated with that account.
- User Content: All prompts, code, text, files, images, and other content you submit to the platform for AI generation or storage. This includes code you write in the Monaco editor, screenshots you upload, and voice recordings you submit through our voice input feature.
- Project Metadata: Project names, descriptions, file structures, checkpoints, and sharing settings you configure within the platform.
- Communications: Any correspondence you send to us, including support inquiries, bug reports, and feature requests submitted through our GitHub repository or other channels.
1.2 Information Collected Automatically
- Usage Data: Token consumption, API request timestamps, features used, page views, session duration, and interaction patterns within the platform.
- Device & Browser Information: IP address, browser type and version, operating system, device type, screen resolution, and language preferences.
- Performance Data: Load times, error rates, and diagnostics related to the in-browser bundler (esbuild-wasm), Monaco editor, and preview pane.
- Cookies & Similar Technologies: We use essential cookies for authentication and session management. Analytics cookies are used only with your consent. See Section 8 for details.
1.3 Information from Third Parties
- Authentication Providers: If you sign up using Google or GitHub, we receive your email address and profile information from those providers.
- AI Providers: When you submit a prompt, it is routed through NVIDIA NIM, OpenCode Zen, and/or OpenRouter for code generation. These providers receive your prompt and return generated content. Each provider processes data according to their own privacy policies. We do not share personally identifiable information beyond your prompt content with these providers.
2. How We Use Your Information
We use the collected information for the following purposes:
- To Provide the Service: Process your AI code generation requests, maintain your account, display your projects, and enable sharing functionality.
- To Improve the Platform: Analyze usage patterns to enhance AI routing decisions, improve code generation quality, optimize performance, and develop new features.
- To Communicate with You: Send service updates, security alerts, and administrative messages. We may also send product announcements and tips, which you can opt out of at any time.
- To Ensure Security: Monitor for unauthorized access, detect abuse and fraud, enforce our Terms of Service, and protect the integrity of the platform.
- To Comply with Legal Obligations: Respond to lawful requests from regulators, courts, and law enforcement, and maintain records as required by applicable law.
- For Aggregated Analytics: Generate anonymized, aggregated statistics about platform usage, token consumption trends, and feature adoption. These aggregates cannot be used to identify you personally.
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), Switzerland, or the United Kingdom, our processing of your personal data is based on the following legal grounds under the General Data Protection Regulation (GDPR):
- Contractual Necessity (Article 6(1)(b)): Processing is necessary to perform our contract with you — to provide the Tavryne AI platform and its features. This includes account management, code generation, and project storage.
- Legitimate Interests (Article 6(1)(f)): Processing for security monitoring, fraud prevention, platform improvement, and aggregated analytics. We balance our interests against your rights and freedoms and have implemented safeguards to minimize privacy impact.
- Consent (Article 6(1)(a)): Where required by law, we obtain your consent for analytics cookies and marketing communications. You may withdraw consent at any time without affecting your ability to use the platform.
- Legal Obligation (Article 6(1)(c)): Processing necessary to comply with applicable legal requirements, such as data retention obligations and lawful government requests.
4. Data Sharing & Disclosure
We do not sell your personal information. We may share your data in the following circumstances:
- AI Providers: As described in Section 1.3, your prompts are sent to NVIDIA NIM, OpenCode Zen, and OpenRouter for code generation. These providers act as data processors under our instructions. They are prohibited from using your data for their own purposes, including model training.
- Cloud Infrastructure Providers: We use Google Cloud Platform (Firebase, Firestore), Vercel, and esbuild-wasm (loaded from unpkg CDN). These sub-processors have signed data processing agreements (DPAs) with us.
- Open Source Dependencies: The in-browser bundler (esbuild-wasm) and code editor (Monaco Editor) are open-source tools loaded from CDNs. They do not transmit your code to external servers.
- Legal Compliance: We may disclose information if required to do so by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such change and the applicable privacy terms.
- Aggregated Data: We may share anonymized, aggregated data that cannot reasonably identify you with partners, researchers, or the public for analytics and research purposes.
5. Data Storage & Security
We implement industry-standard technical and organizational measures to protect your data:
- Encryption in Transit: All communications with our servers are encrypted using TLS 1.3. API requests require Firebase JWT authentication tokens.
- Encryption at Rest: Your data is stored on Google Cloud Platform infrastructure with AES-256 encryption at rest. Firebase Firestore documents are encrypted using Google-managed encryption keys.
- Access Controls: Infrastructure access is restricted to authorized personnel with multi-factor authentication. Access is logged and audited regularly.
- Data Isolation: Each user's projects and data are isolated using Firebase security rules. Sharing is opt-in and per-session.
- Secure Development: Our code undergoes mandatory peer review, dependency scanning, and security testing before deployment.
- Incident Response: We maintain an incident response plan to promptly address any security breaches. We will notify affected users as required by applicable law.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy:
- Account Information: Retained for the duration of your account and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce agreements.
- User Content (Prompts & Generated Code): Retained as long as your account is active. When you delete a project, the associated content is permanently deleted from our systems within 30 days.
- Usage Data: Retained in aggregated form indefinitely for analytics purposes. Raw usage logs are retained for 90 days and then anonymized or deleted.
- Token Usage Records: Retained for billing and rate-limiting purposes for the duration of your account and for up to 12 months thereafter.
- Full Account Deletion: You may request complete deletion of your account and all associated data at any time by contacting us. We will process your request within 30 days.
7. Your Rights
7.1 GDPR Rights (EEA, Switzerland, UK)
If you are located in the EEA, Switzerland, or the UK, you have the following rights under the GDPR:
- Right of Access (Article 15): Request confirmation of whether we process your personal data and, if so, access to that data and information about how it is processed.
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal data we hold about you.
- Right to Erasure (Article 17): Request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or when you withdraw consent on which processing is based.
- Right to Restrict Processing (Article 18): Request restriction of processing in certain circumstances, such as when you contest the accuracy of your data.
- Right to Data Portability (Article 20): Request a copy of your personal data in a structured, commonly used, machine-readable format, and the right to transmit that data to another controller.
- Right to Object (Article 21): Object to processing based on legitimate interests, including profiling for direct marketing purposes.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Right to Lodge a Complaint: Lodge a complaint with your local data protection authority if you believe our processing of your personal data violates applicable law.
7.2 CCPA Rights (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share your information.
- Right to Delete: Request deletion of personal information we have collected about you, subject to certain exceptions.
- Right to Opt Out of Sale: We do not sell your personal information. You have the right to direct us not to sell your personal information at any time.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights, including by denying you access to the platform or providing a different level of service.
7.3 How to Exercise Your Rights
To exercise any of the rights described above, please contact us through our GitHub repository. We will respond to your request within 30 days. We may need to verify your identity before processing your request. Verification may require you to provide information matching that in our records.
8. Cookies & Tracking Technologies
We use cookies and similar tracking technologies to operate and improve our platform:
- Essential Cookies: Required for authentication, session management, and security. These cannot be disabled. Examples include Firebase Auth session tokens and CSRF protection cookies.
- Preference Cookies: Store your theme selection (light/dark mode), color theme preference, and editor settings. These enhance your experience but are not strictly necessary.
- Analytics Cookies: Used only with your consent to understand how you interact with the platform and identify areas for improvement.
You can control cookies through your browser settings. Disabling essential cookies may prevent you from using the platform. We do not use third-party advertising cookies or tracking pixels.
9. International Data Transfers
Tavryne AI operates globally. Your personal data may be transferred to and processed in countries other than your country of residence, including the United States, where our cloud infrastructure providers (Google Cloud, Vercel) are located.
When we transfer your data from the EEA, Switzerland, or the UK to countries that have not been deemed adequate by the European Commission, we rely on appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission, which we have executed with our sub-processors.
- Data Processing Agreements (DPAs) that incorporate the relevant data protection obligations and ensure an equivalent level of protection.
By using Tavryne AI, you acknowledge that your information may be transferred to and processed in the United States and other jurisdictions as described above.
10. Children's Privacy
Tavryne AI is not directed to individuals under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete that information promptly. If you believe we have collected data from a child, please contact us immediately.
11. Third-Party Services
Tavryne AI integrates with the following third-party services. Each service operates under its own privacy policy:
- Firebase (Authentication & Firestore): Privacy Policy at https://firebase.google.com/support/privacy
- NVIDIA NIM: Privacy Policy at https://www.nvidia.com/en-us/privacy-policy
- OpenCode Zen: Privacy Policy at https://opencode.ai/privacy
- OpenRouter: Privacy Policy at https://openrouter.ai/privacy
- Vercel (Deployment): Privacy Policy at https://vercel.com/legal/privacy-policy
- GitHub (OAuth & Support): Privacy Policy at https://docs.github.com/en/site-policy/privacy-policies
This Privacy Policy does not apply to third-party services. We encourage you to review the privacy policies of each third party before using their integrations.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. For significant changes, we may also provide a notification through the platform or via email. Your continued use of Tavryne AI after the effective date of the updated policy constitutes your acceptance of the changes.
13. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- GitHub: github.com/tavryneai
- Twitter / X: @tavryneai
Data Protection Officer: For GDPR-related inquiries, you may contact our Data Protection Officer through the channels above. We will respond to all legitimate requests within 30 days.