Privacy Policy

Last updated: October 1, 2026

Clisbot is local-first. Installing or using the open-source software does not send us your code, prompts, files, terminal output, or agent conversations. This policy explains the separate data boundaries for local Clisbot, the optional official relay, the hosted Clisbot Hub, and clisbot.com.

Who is responsible

Long Luong, operating as Clisbot
Email: clisbot@gmail.com

Long Luong is the data controller for personal data processed through the official Clisbot website, relay, and hosted Hub. Independently self-hosted daemons, Hubs, and relays are controlled by their operators and are not covered by this policy.

Local Clisbot apps and daemons

Clisbot runs on your machines. Usage analytics is optional and off by default. In versions with analytics support, you can enable or disable it in Settings → General → Privacy. The daemon does not send product analytics or crash reports.

When enabled, the app sends Google Analytics app opens, standardized screen names, usage duration, app version, and platform information. Android and iOS use Firebase Analytics, which also collects basic device and app lifecycle information. Electron sends these limited usage events through our Cloudflare collector. Analytics identifiers are pseudonymous and reset on this device when you turn analytics off. Advertising identifiers and personalization are disabled. Analytics never includes prompts, chats, code, project names, file paths, host addresses, or account email addresses.

Packaged desktop apps check GitHub Releases for updates. GitHub receives the ordinary network information needed to answer that request under its own privacy policy.

Agents such as Claude Code, Codex, and OpenCode communicate with their providers using credentials on your machine. Clisbot does not manage or intercept those provider API calls.

The official relay

The relay is optional. To connect your client and daemon, it processes:

  • IP addresses and connection timing
  • Session identifiers and public handshake keys
  • Message sizes and aggregate bandwidth
  • Temporary connection and routing state

Your client and daemon encrypt application traffic end-to-end with NaCl box encryption. The relay carries ciphertext and cannot read your code, prompts, terminal output, or agent conversations. Payloads exist in relay memory only while being forwarded. We do not store message contents. Infrastructure may retain limited operational logs and aggregate metrics for security, capacity planning, and troubleshooting.

Clisbot Hub

When you create or use a hosted Hub account, we process:

  • Your name, email, account credentials, sessions, IP address, and user agent
  • Your organization, members, roles, invitations, and daemon registrations
  • Identifiers and credentials for services you connect
  • Webhook events, messages, comments, attachment metadata, and related context received from those services
  • Workflow configurations, trigger inputs, outputs, execution state, activity, and audit records
  • Stripe customer identifiers and subscription information needed to provide access

Your repositories, local files, and agent-provider credentials remain on your infrastructure unless a workflow explicitly sends information to Hub or a connected service. Hub does not provide AI inference.

Who controls workflow data

Clisbot controls account, billing, security, and service-operation data. When an organization uses Hub to process personal data in its workflows, that organization decides why the data is processed and Clisbot processes it on the organization's behalf.

Why we process data

We process data to:

  • Provide accounts, Hub workflows, relay connectivity, billing, and support
  • Authenticate users, daemons, and connected services
  • Prevent abuse and protect the services
  • Maintain operational and audit records
  • Meet accounting, tax, and other legal obligations

The legal bases are performance of our contract with you, our legitimate interests in operating and protecting the services, and compliance with legal obligations.

Service providers

We use Fly.io for hosted infrastructure, Stripe for subscriptions and payments, and GitHub for software releases and connected GitHub features. Slack, Discord, Linear, and other services receive data only when you choose to connect or use them.

Some providers may process data outside the European Economic Area. Where required, we use appropriate contractual safeguards for those transfers.

We do not sell personal data, share it with advertisers, or use it to train AI models.

Retention and deletion

We keep account and organization data while your account remains active. We retain operational, workflow, and audit records while needed to provide and protect the service. Billing records may be kept for legally required accounting and tax periods. Short-lived authorization codes and sessions expire automatically.

You can request account deletion by emailing us. Some records may remain where the law requires it or where they form part of another organization's legitimate audit history.

Website analytics

If you accept analytics cookies, clisbot.com uses Google Analytics to measure page visits and understand website usage. Google receives page paths, browser and device information, approximate location, and pseudonymous browser identifiers. We do not send code, prompts, files, or agent conversations through website analytics. Advertising personalization and Google signals are disabled.

Analytics is optional and is not loaded before you accept. You can decline or withdraw consent using Cookie settings in the footer. Learn more in Google's privacy policy.

Cookies

The marketing website stores your analytics preference locally and uses first-party Google Analytics cookies only if you accept. It does not use advertising cookies. Hub uses the session and security cookies needed to sign you in and operate your account.

Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability of your personal data. Email clisbot@gmail.com. You may also complain to the Spanish Data Protection Agency.

Security

We use access controls, encrypted transport, and limited service permissions. No online service can guarantee absolute security. Read Clisbot's security model or report a vulnerability privately to clisbot@gmail.com.

Children

The official services are for professional developers and are not directed at children under 16.

Changes

We will update this page and its date when our services or data practices materially change.