StvenaMind · Legal

Privacy Policy

Effective date: 3 October 2026

In short: StvenaMind runs on your Mac, and we do not collect your code, prompts, or usage data. The app sends no telemetry, analytics, or crash reports to us, and we have no servers that receive them. Your code goes only to the AI Provider you choose, through that provider's own tool. If you join the waitlist on stvenamind.com, we keep a small account for it, described in section 5.

1. Who we are

Systemctl, a company registered in Georgia and based in Tbilisi ("we", "us"), provides StvenaMind. For data we process, which is mainly website visits, waitlist sign-ups, and messages you send us, we are the controller. Contact: [email protected].

2. Scope

This policy covers the StvenaMind App, the Engine (eng), the local dashboard, and the website stvenamind.com. It does not cover AI Providers, GitHub, or any other third-party service you use with StvenaMind. Their own privacy policies apply.

3. What stays on your Mac

The App and Engine store their working data locally in ~/Library/Application Support/EngineeringAgentOS (or the folder set in $ENG_HOME). Only your macOS user can read these folders. We cannot access this data.

Data

Where it lives

Sent to us?

Registered repositories, project settings, features, plans, run history, project memory, permission decisions

Local database eng.db

No

Copies of your code being worked on

worktrees/

No

Prompts and responses exchanged with AI Providers

Protocol logs in protocol/

No

Check logs and command output

logs/

No

Held-out checks (private tests)

held_out/

No

Backups (latest 10)

backups/

No

Token use and provider usage-limit readings

Local database

No

Git name, email, and signing settings; public SSH keys; hardware and disk details shown on the Profile screen

Read on demand. Not stored by us. Private keys are never read.

No

Provider sign-in tokens

Kept by the provider tool (e.g. the macOS Keychain for Claude, ~/.codex for Codex). StvenaMind does not read them.

No

The App talks to the Engine through a private local socket. The optional dashboard listens only on your own computer (127.0.0.1).

4. What goes to AI Providers

When you start a run, the Engine sends the parts of Your Content each agent needs to the AI Provider you chose for that role. This includes source code, file contents, feature descriptions, plans, and command output. Today the providers are Anthropic (Claude Code) and OpenAI (Codex). The data goes directly from your Mac to the provider through its own tool, never through us. The provider processes it under its own terms and privacy policy, which you agreed to when you set up that tool:

Held-out checks are never given to agents. Network access for agent commands is off by default.

5. What we may receive

We receive personal data only in these cases:

  • Website visits. The host that serves stvenamind.com (Usectl) processes standard request data to deliver the site and the download and to keep them secure. This includes IP address, browser type, requested pages, and time. The site does not use analytics or advertising cookies, and it sets no cookies of its own. If you join the waitlist, your browser stores a sign-in session so you stay signed in. It is used only for that.
  • Waitlist sign-ups. When you join the waitlist, you sign in with Google, GitHub, or a link we email you. Supabase, which runs our sign-in and waitlist database, then stores your email address, an account ID, how you signed in, your sign-in times, and when you joined, which sets your place in line. If you use Google or GitHub, we also receive the basic profile details that provider shares, such as your name, username, and profile picture. Supabase keeps security logs of sign-in requests, including IP address. Google and GitHub handle your sign-in under their own privacy policies.
  • Third-party site resources. Some pages load fonts from Google Fonts or scripts from jsDelivr. Your browser then sends your IP address and browser details to those providers.
  • Emails you send us. If you email us, we receive your email address, name, and what you write.
  • Run reports you choose to send. A run report is a redacted file you save yourself. If you send it to us, we receive what it contains: run records, events, permission history, excerpts of check logs, token use, and environment details such as macOS and tool versions. It contains a code diff only if you add one. Protocol logs, the database, and project memory are never included.

We do not knowingly collect special categories of personal data. We do not sell or rent personal data, or share it for targeted advertising.

6. How we use data and our legal bases

Purpose

Data

Legal basis (GDPR / UK GDPR)

Serve the website and download, and keep them secure

Request data held by the host

Legitimate interests in running a secure website

Answer your emails and support requests

Email address, name, message

Legitimate interests; steps you ask for before a contract

Run the waitlist: sign you in, hold your place in line, and email you about access

Email address, account ID, sign-in method and times, place in line, and profile details from Google or GitHub

Steps you ask for before a contract; legitimate interests in keeping sign-in secure

Diagnose bugs from run reports you send

Run report contents

Legitimate interests in fixing and improving the Service; consent where needed

Meet legal obligations and defend legal claims

Any of the above, as needed

Legal obligation; legitimate interests

We do not use your data for automated decisions that have legal or similarly significant effects on you. We do not use run reports or emails to train AI models.

7. Sharing

We share personal data only with:

  • Service providers who act for us, such as our website host (Usectl), Supabase (sign-in and the waitlist database), and our email provider. They may use it only to provide their services to us.
  • Authorities or other parties when the law requires it, or when needed to protect rights, safety, or the security of the Service.
  • A successor in a merger, acquisition, or sale of assets. That successor stays bound by this policy for data collected under it.

AI Providers are not our processors. They receive Your Content directly from you, under your own agreement with them.

8. International transfers

We and our service providers may process data outside your country, including in the United States. For personal data from the EEA, UK, or Switzerland, we rely on adequacy decisions or Standard Contractual Clauses, with safeguards where needed.

9. Retention

  • Local data stays on your Mac until you delete it. To remove it, quit StvenaMind and delete ~/Library/Application Support/EngineeringAgentOS (or your $ENG_HOME folder). Deleting the App alone does not remove this folder. The Engine keeps the 10 most recent backups. Git worktrees and branches created inside your repositories stay there until you remove them.
  • Emails are kept while we are in contact with you or until the beta ends, then for up to 24 months unless you ask us to delete them sooner.
  • Waitlist accounts are kept while you are on the waitlist or until the beta ends, then for up to 24 months unless you ask us to delete them sooner. Deleting your account removes your place in line. Supabase keeps sign-in security logs under its standard retention periods.
  • Run reports are kept until the issue is resolved, then for up to 12 months.
  • Website request logs are kept by our host under its standard retention periods.

10. Security

StvenaMind stores local data in folders only your macOS user can read. The App talks to the Engine over a private local socket, and the dashboard listens only on 127.0.0.1. Agent commands run in the provider's sandbox with network access off by default, and agents cannot read held-out checks. Run reports are redacted before you save them.

Your local data is only as secure as your Mac. Use FileVault, a strong login password, and current macOS updates. Protocol logs and worktrees may contain your source code and anything in it, including secrets. Treat them as sensitive. No system is perfectly secure.

11. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and get a copy;
  • correct or delete it;
  • restrict or object to our processing, including processing based on legitimate interests;
  • receive it in a portable format;
  • withdraw consent at any time, without affecting earlier processing;
  • complain to your local data protection authority.

California and other US states. We do not sell or share personal information for cross-context behavioral advertising, as those laws define these terms. We do not use sensitive personal information to infer characteristics about you. You may ask to know, delete, or correct your personal information. We will not discriminate against you for using these rights.

To use any of these rights, email [email protected]. We will reply within 30 days. We may need to confirm your identity first. Most StvenaMind data never reaches us, so you can view or delete it yourself on your Mac.

12. Children

StvenaMind is not meant for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has sent us personal data, contact us and we will delete it.

13. Changes to this policy

We will post any update here with a new effective date. If we make a material change, such as adding telemetry or payments, we will tell you on the website or in the App before it applies. Where the law requires it, we will ask for your consent.

14. Contact

Systemctl · Tbilisi, Georgia · [email protected]