Legal
Privacy policy
How website, account, Services, product, provider, and telemetry data are handled.
1. Scope
This policy explains how Gamibase handles information across this website, accounts, billing, public Services requests, early-access registration, product clients, support, and product telemetry. It also explains the boundary between information that stays in your local project environment and information sent because you request a network operation, upload telemetry, contact us, or arrange an engineering engagement.
2. Website, account, and billing data
When you sign in or use account features, we may process your email address, display name, authentication identifiers, session state, organization membership, roles, entitlements, device sessions, and account audit records. Billing providers handle payment details through their hosted checkout. We receive the customer, transaction, subscription, refund, and entitlement state needed to provide and reconcile access. Download and updater requests may include an account or installation reference, current product version, release channel, platform, architecture, settings, artifact reference, and the result of an entitlement or compatibility check.
3. Services and early-access requests
A Services request may include your name, work email, company or team, team-size range, requested engagement, technical version and build context, urgency, budget range, and a description of the outcome you need. Team requests may also include an expected seat range and use case. Early-access registration may include your email address, referral source, and registration status. Public forms are qualification and contact surfaces: do not submit credentials, proprietary source, private assets, or sensitive project logs through them. Project access or secure transfer is arranged separately after scope and authority are agreed.
4. Local product data
Gamibase products are designed around local-first project work. Depending on the capabilities you enable, local data may include project paths and files, conversations, approved project intent, plans, queues, policy decisions, run journals, operation requests, build logs, generated outputs, evidence references, captures, annotations, and redacted diagnostic records. Project content stays local by default. Account and updater operations send their required metadata to the website; an explicit telemetry upload sends the allowed batch to the telemetry service; an approved provider request sends the selected payload to that provider; and support or Services material reaches Gamibase only when you submit it through an agreed channel. Deleting an online account does not delete project files, journals, captures, exports, backups, or version-control history stored on your machines.
5. Configured provider requests
Some operations can use an external provider or a locally authenticated worker selected through the configured route. When you authorize one of these operations, the provider may receive the prompt, selected project context, file excerpts, tool output, worker transcript, or input assets required for that request. Provider privacy, retention, training, licensing, billing, and geographic-processing terms apply to that route. Review them before sending confidential or regulated material. Product services are designed to keep raw provider credentials in the applicable local secret store and out of agent context, product journals, and exported diagnostics.
6. Product telemetry
Product clients may create a telemetry spool locally. Under the current product contract, a producer does not upload that spool automatically; an operator must explicitly invoke the available upload flow. An uploaded batch may include a hashed installation identifier, product and contract version, producer and source provenance, operation type, status, timestamp, runtime scope, and allowlisted technical classifications. The telemetry contract excludes names, email addresses, credentials, tokens, raw project source, asset contents, raw paths or arguments, log bodies, and crash-dump bodies. K-anonymity applies to downstream aggregate exports, not to every uploaded event, and uploaded telemetry is not automatically linked to your website account.
7. Capture, speech, and visual data
Where capture features are enabled, screenshots, clips, annotations, evidence, and decision records are stored in the project-controlled local environment unless you export or transmit them. Hiding or archiving evidence may preserve its records. Purging media may still leave integrity metadata or an append-only decision record. If a feature uses audio, speech-to-text, image analysis, or frame analysis, the product will identify whether processing is local or remote and what information is sent before remote processing is enabled.
8. Public technical sources
Gamibase may process publicly available technical information from official documentation, public repositories, and community discussions to maintain compatibility and engineering reference data. That material may retain source links, attribution, public usernames, excerpts, metadata, and content hashes. Private or access-restricted sources are excluded unless their use is separately authorized and reviewed. Customer accounts and project material are not used as the public technical reference-data source.
9. How we use information
We use information to operate and secure the website, authenticate accounts, qualify and respond to requests, administer early access, provide purchases and entitlements, deliver support, perform agreed engineering work, prevent abuse, investigate failures, and satisfy accounting or legal obligations. Depending on the activity and applicable law, processing is based on providing a requested service, taking requested steps before an engagement, complying with law, protecting legitimate security and operational interests, or acting on your direction or consent. A public Services request does not authorize access to your project.
10. Sharing and processing
We share information only with providers and recipients needed for the purposes described here, such as authentication, database, hosting, email, payment, support, telemetry, and user-selected product providers. We may also disclose information when required by law, to protect rights or security, to advisers working under appropriate duties, or as part of a lawful business transaction. Providers may process information in the countries where they operate and are governed by their own terms and applicable data-protection obligations. We do not treat a user-directed provider request as local-only processing.
11. Retention and deletion
We retain website, account, request, billing, updater, support, and security records only for as long as needed for the stated purpose or required for accounting, fraud prevention, dispute handling, security, or law. Local project information remains under the project owner's control. Account deletion does not automatically remove local files or telemetry that is not linked to the account. A telemetry access or deletion request may require the batch identifier or hashed installation identifier retained in local product state. Aggregated statistics, backups, version-control history, and records required by law may not be removable through an account request.
12. Your choices, rights, and security
Where applicable under law, you may request access, correction, deletion, restriction, portability, or objection and may withdraw consent where processing relies on consent. We may need to verify a request and may retain information required to complete a transaction, protect security, or comply with law. Product controls govern local data, provider routes, and telemetry uploads. We use signed sessions, access controls, database policies, rate limits, local secret isolation, and redaction rules, but no website, local environment, or provider network can guarantee absolute security. You remain responsible for protecting your devices, credentials, provider accounts, backups, and repository access.
13. Updates and contact
The site and Services are not directed to children who cannot legally consent to the applicable processing or enter the relevant agreement. We may update this policy when products, providers, processing, or legal obligations change. For privacy, account, or Services-request data questions, use the service request page and do not include project files, credentials, or sensitive logs.
Privacy or account question? Start with the service request page, without attaching project files or sensitive material.