Privacy Policy

Effective date: July 20, 2026 · Last revised: July 30, 2026

This Privacy Policy describes how Alvitur ("Alvitur", "we", "us") - the operator of the Alvitur AI coding agent - collects, uses, shares, and protects information when you use the Alvitur Desktop application, the alvitur.ai website and account dashboard, and the Alvitur cloud proxy and APIs that connect the agent to third-party AI models (together, the "Services"). It is written specifically for how Alvitur works: a subscription desktop agent that reads, edits, and runs code on your own machine while routing AI requests through Alvitur's metered cloud to third-party model providers. If you have questions, contact us at [email protected].

1. Who we are

Alvitur provides the Services and acts as the controller of the personal information described here. The Alvitur Desktop application is a locally installed program (built on the Electron desktop shell with a bundled local agent runtime); the website at alvitur.ai handles sign-up, sign-in, billing, and account management; and the Alvitur cloud proxy at alvitur.ai authenticates your agent, meters usage against your plan, and forwards your AI requests to model providers. Contact for all privacy matters: [email protected].

2. Information we collect

a. Account and sign-in data (website). When you create or use an Alvitur account we collect your email address, display name, and a securely hashed password. If you sign in with Google (OAuth), Google shares your basic profile and the email address associated with your Google account so we can create or match your account; we do not receive your Google password. If you verify by phone, we process your phone number through an SMS provider to send a one-time code.

b. Billing data (website). Payments are processed by Stripe. We store your Stripe customer and subscription references, your plan and interval, renewal and payment status, and your billing country if provided. We never receive or store full payment-card numbers - those go directly to Stripe.

c. Desktop application and AI request data. The Alvitur agent works with the content you direct it to. When you run the agent, the following may be transmitted through the Alvitur cloud proxy to the AI model that fulfils your request: your prompts and instructions, and the code, repository contents, files, file paths, diffs, terminal output, and selections you or the agent include as context. This content is sent only to generate the response you asked for. Your agent's memory, generated skills, chat/session history, and local configuration are stored on your own device in the Alvitur data folder (on Windows, %LOCALAPPDATA%\alvitur) - not on our servers.

d. Usage metering and telemetry. For each AI request we record metering data needed to enforce your plan: the model used, input/output token counts, computed cost, timestamps, and a session identifier. We do not store the body of your prompts or your code in these metering records. The desktop app and our servers also generate diagnostic telemetry - error messages, stack traces, application version, and operating-system type - so we can diagnose crashes and failures.

e. Referrals. If you join through a referral link, we record which account referred you so referral credits can be applied.

f. Essential cookies and tokens. The website uses a session token/cookie to keep you signed in and to secure the account dashboard. The desktop app stores agent keys and session tokens locally to authenticate to the cloud proxy.

3. How we use information

We use the information above to: authenticate you and keep your account secure; run the agent and forward AI requests to model providers; meter and enforce plan allowances and budgets; process subscriptions and payments through Stripe; grant and reconcile referral credits; detect, prevent, and investigate fraud and abuse; provide support; and diagnose and fix errors. We process this data to perform our contract with you, to meet legal obligations, and for our legitimate interest in operating and securing the Services.

4. What we do not do

We do not sell your personal information, and we do not use your prompts, code, files, or repository contents to train AI models - ours or anyone else's. We do not share your content with third parties except the processors listed below that are strictly needed to deliver the Services.

5. Third-party AI providers and subprocessors

The Services depend on the following third parties, who process data on our behalf or as needed to provide their part of the Services:

We may also disclose information where required by law, to enforce our Terms, or to protect the rights, safety, and integrity of the Services and our users.

6. Data retention

7. Deleting your data and your rights

Depending on where you live, you may have additional rights - such as access, correction, portability, deletion, and objection - under laws like the EU/UK GDPR or the CCPA/CPRA. We honour verified requests to the extent required by applicable law; California residents may note that we do not sell or "share" personal information as those terms are defined under the CCPA/CPRA.

8. Security

Passwords are stored using strong one-way hashing, and agent keys and API tokens are stored hashed. All traffic to the Services is encrypted in transit with TLS, and our origin sits behind Cloudflare with access restricted to Cloudflare's network. Access to production systems is limited to authorised personnel. No method of transmission or storage is perfectly secure; please report suspected vulnerabilities to [email protected].

9. International transfers

We and our subprocessors may process information in the United States and other countries. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers.

10. Children

The Services are intended for adults and are not directed to children under 18. We do not knowingly collect personal information from children; if you believe a child has provided us data, contact [email protected] and we will delete it.

11. Changes to this Policy

We may update this Policy as the Services evolve. When we make material changes we will update the "Last revised" date above and give notice by email or in-product before the changes take effect.

12. Contact

For privacy questions or to exercise your rights, contact Alvitur at [email protected].