Legal
Privacy Policy
1. Introduction
This Privacy Policy describes how Nightcrew ("Company," "we," "us," or "our") collects, uses, and protects your personal information when you use our website, platform, and services (collectively, the "Service"). We are committed to protecting your privacy and handling your data with transparency and care.
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.
2. Information We Collect
We collect information in several categories as you use the Service:
2.1 Account and Identity Information
- Name and username from your GitHub, Google, or email account registration.
- Email address associated with your account.
- Profile picture or avatar URL from your authentication provider.
- GitHub user ID and account metadata.
2.2 GitHub Integration Data
- Repository names, descriptions, and metadata for connected repositories.
- GitHub App installation IDs and associated account information.
- Repository contents, commit history, and branch information necessary for task execution.
- Pull request and issue data generated through the Service.
- Webhook event payloads from GitHub.
2.3 Billing and Payment Information
- Stripe customer ID and subscription status.
- Payment method details are processed directly by Stripe and are not stored on our servers.
- Billing history and transaction records.
2.4 Usage and Technical Data
- IP address, browser type, and device information.
- Pages visited, actions taken, and interaction patterns within the Service.
- Task card content, descriptions, and AI-generated responses.
- Execution logs, error reports, and diagnostic data.
- API usage logs for MCP integrations.
2.5 Communications
- Email communications sent to or from the Service.
- Board invite messages and associated metadata.
- Setup error reports submitted through the Service.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, operate, maintain, and improve the automation beta, including task cards, repository setup, readiness checks, task execution, code generation, verification, and draft pull request creation when a run is configured and authorized.
- Account Management: To create and manage your account, authenticate your identity, and process subscriptions.
- GitHub Integration: To access connected repositories for planning and setup, and to clone code into containers, execute tasks, and create pull requests only when automation is configured and authorized.
- Communication: To send transactional emails (account notifications, task updates, billing receipts), respond to support requests, and send important service announcements.
- Analytics and Improvement: To understand usage patterns, diagnose technical problems, and improve the Service.
- Security: To detect, prevent, and address fraud, abuse, and security incidents.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
- Billing: To process payments, manage subscriptions, and fulfill our contractual obligations.
4. Data Sharing and Third Parties
We share your information with the following categories of third parties:
4.1 Service Providers
- Stripe: Payment processing and subscription management. Stripe processes payment data under its own privacy policy. We do not store your credit card number or full payment details.
- GitHub (GitHub, Inc.): Authentication, repository access, planning context, and configured pull request management. Your GitHub data is handled under GitHub's terms and privacy policy.
- AI Providers: Task content and repository context are sent to AI coding agents (such as Anthropic Claude, OpenAI Codex, or similar) only for configured card-building, repository analysis, or code generation workflows. These providers process data under their respective terms.
- Resend: Transactional email delivery. Email content is processed by Resend under its privacy policy.
- Infrastructure Providers: Cloud hosting and container orchestration services that process data on our behalf under contractual data protection obligations.
4.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal information may be transferred as part of the transaction. We will notify you of any change in ownership or use of your personal information.
4.4 With Your Consent
We may share your information for any other purpose with your explicit consent.
We do not sell your personal information to third parties.
5. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy:
- Account Data: Retained for the lifetime of your account and for a reasonable period after deletion to support data recovery, dispute resolution, and legal compliance.
- Repository Data: Task content and generated code are stored in your connected GitHub repositories. Temporary copies in our containers are destroyed after task completion.
- Billing Data: Retained as required by applicable financial regulations and for tax reporting purposes.
- Usage Logs: Retained for up to twelve (12) months for analytics and security purposes, after which they are aggregated or deleted.
- Communications: Support emails and related correspondence are retained for as long as necessary to address your inquiry and for a reasonable period thereafter.
6. Data Security
We implement industry-standard security measures to protect your information, including:
- Encryption of data in transit (TLS/HTTPS) and at rest.
- Secure container isolation for all task execution environments.
- Access controls and authentication for all internal systems.
- Regular security audits and vulnerability assessments.
- Automated deletion of ephemeral containers and temporary data.
While we take reasonable precautions, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your information.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete personal information.
- Deletion: Request deletion of your personal information, subject to certain legal exceptions.
- Portability: Request a copy of your data in a structured, commonly used, machine-readable format.
- Objection: Object to processing of your personal information for certain purposes.
- Restriction: Request restriction of processing in certain circumstances.
- Withdraw Consent: Where processing is based on consent, withdraw that consent at any time.
To exercise any of these rights, contact us at [email protected]. We will respond to your request within the timeframe required by applicable law.
If you are located in the European Economic Area (EEA), United Kingdom, or similar jurisdictions, you have additional rights under the General Data Protection Regulation (GDPR) and equivalent legislation.
8. Cookies and Tracking
The Service uses cookies and similar technologies for the following purposes:
- Essential Cookies: Required for authentication, session management, and security. These cannot be disabled.
- Functional Cookies: Remember your preferences and settings to provide a personalized experience.
- Analytics: We may use privacy-respecting analytics to understand how the Service is used and to improve the product.
You can control cookies through your browser settings. Disabling essential cookies may impair the functionality of the Service.
We do not use third-party advertising cookies or cross-site tracking technologies.
9. Children's Privacy
The Service is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information promptly.
If you believe a child has provided us with personal information, please contact us at [email protected].
10. International Data Transfers
Your information may be processed in countries other than your country of residence. These countries may have different data protection laws than your jurisdiction.
We take appropriate safeguards to ensure that your personal information receives an adequate level of protection, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission where applicable.
- Contractual obligations with service providers to protect your data.
- Compliance with applicable international data transfer frameworks.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a prominent notice on the Service at least thirty (30) days before the changes take effect. We encourage you to review this Privacy Policy periodically.
12. Contact Information
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
Nightcrew
Email: [email protected]
Website: nightcrew.dev
For GDPR-related inquiries, you may also contact our Data Protection Officer at [email protected].