LEGAL / PRIVACY
Privacy Policy
Effective 15 September 2026 · last reviewed 15 September 2026
1. Controller and scope
This policy covers the Sourceweave website, account service, desktop software, mobile companion, subscriptions, and support. The organisation identified above is the data controller. Privacy requests can be sent to support@sourceweave.app.
2. Information we collect
We collect account identity data such as name, email, verified status, and identity-provider identifier; subscription and billing identifiers; support messages; security and access logs; and limited device, browser, and technical data needed to operate and protect the service. Stripe provides payment status and identifiers, but not your full card details.
3. Sources of information
Information comes from you, your selected identity provider, payment and infrastructure providers, your device when it communicates with our service, and support correspondence. We do not buy personal information for advertising profiles.
4. Local project data
Sourceweave is designed to keep repositories, terminals, and development processes local. Opening a project does not by itself upload your code to us. Information may leave your device when you use a model provider, GitHub integration, browser or voice service, remote or mobile connection, feedback form, support channel, or other external integration. Review what each selected feature sends before using it with confidential information. Local Blackbox records can contain file paths, prompts and structured event data; local retention can be unlimited depending on your settings. Local storage is not the same as uploading these records to Sourceweave. You control your local files and should review recording, retention and deletion settings.
5. Purposes and lawful bases
- Account identity, sign-in and subscription status: to create your account and provide the access you request, on the basis of contract. Without the necessary identity or payment information, we cannot provide that account or paid service.
- Payment records, contract acceptance, cancellation notices and tax evidence: to perform the contract and comply with applicable accounting, tax and consumer-law obligations.
- Support messages: to answer your request and resolve contractual problems; other enquiries and complaint handling are based on our legitimate interest in assisting users and resolving issues, or legal obligations where applicable.
- Access and security information: our legitimate interests in preventing abuse, protecting accounts and keeping services reliable. We consider the effects on your rights and limit access and use accordingly.
- Optional marketing: consent where required. You can withdraw consent or unsubscribe without losing paid access. We do not treat acceptance of these terms as marketing consent.
We do not use account information to make solely automated decisions producing legal or similarly significant effects. You may object to legitimate-interest processing. Any new optional analytics or other purpose requires its own assessment and, where required, consent.
6. Sharing and processors
We share only what is reasonably necessary with providers that support identity, payment processing, hosting, storage, email, monitoring, and customer support. Our hosted account infrastructure uses Cloudflare for website hosting and account storage, Elestio for hosting our Keycloak identity service and its authentication database on Netcup infrastructure in Nuremberg, Germany, Stripe for payments and billing, Resend for transactional and support email delivery, and Zoho Mail’s EU service for our business and support inboxes. Google receives sign-in information when you choose Google sign-in. Payment and identity providers may also act as independent controllers for their own legal, security and account purposes; they are not necessarily processors for every activity. Providers and integrations you choose receive the information needed for the feature you request. We may also disclose information where required by law or during a properly managed corporate transaction. We do not sell personal information.
7. Cookies
We use essential cookies and similar storage for authentication, security, and requested account functions. They are not used for third-party behavioural advertising. If we introduce non-essential analytics or advertising technology, we will provide the required information and consent controls first.
8. Retention
Account data is kept while the account is active and then deleted or anonymised when no longer needed. Ordinary company accounting records are generally retained for six years after the relevant accounting period, with longer retention where required. EU VAT One Stop Shop transaction evidence must be retained for ten years from the end of the calendar year of the transaction. That longer period applies to the relevant tax evidence, not every piece of account or project data. Contract and cancellation records are retained as needed to demonstrate the transaction and resolve claims. We review support and security records for deletion when the enquiry, protection or legal purpose ends; an active dispute or legal hold may require longer retention. Ask us about the period applicable to a particular record. Local files and local recordings remain subject to your device settings and deletion choices.
9. International transfers
Some providers may process information outside the UK. A restricted transfer requires an applicable adequacy decision or appropriate contractual safeguards and the associated assessment. Provider locations and applicable transfer arrangements must be checked for the particular service; we do not treat a provider’s brand or encryption alone as a transfer safeguard. You may contact us for information about the safeguard used for a relevant transfer.
10. Your rights
Depending on the law that applies, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent at any time where processing relies on consent. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk. We may need proportionate information to verify your identity before acting. Rights requests are normally answered within one month, subject to lawful extensions and exceptions. You can also complain to the competent supervisory authority where applicable, including in the EU. To complain directly about our handling of personal information, email support@sourceweave.app with “Privacy complaint” in the subject, or write to our registered office. We acknowledge privacy complaints within 30 days, investigate without undue delay, keep you informed and explain the outcome. You do not have to give up your right to contact a regulator. The complaint acknowledgement period does not replace the separate deadline for a rights request.
11. Security and children
We use access controls, secure sessions, scoped clients, encryption in transit, and separation between hosted account services and local project execution. No system is completely secure. Sourceweave is intended for adults and we do not knowingly create accounts for people under 18.
12. Changes
We may update this policy as the service, providers, or law changes. We will update the review date and give reasonable notice of a material change where appropriate.