AutonomLayer
Demo
Features
Product
Pricing
Blog
Download
Contact
Log in
Try Chill Coding
← All policies
  • Privacy
  • Terms
  • EULA

AutonomLayer Privacy Policy

Effective date: August 17, 2026

Version 1.5 · Last updated August 17, 2026

Support & privacy requests: support@autonomlayer.com

How AutonomLayer collects, uses, stores, and protects information when you use our website, macOS app, and cloud services — including AI processing, cookies, and regional rights (GDPR, CPRA, KVKK).


Introduction

This Privacy Policy explains how **AutonomLayer (a project of its founders, legal entity pending formation)** ("AutonomLayer," "we," "us," or "our") collects, uses, and shares information when you use autonomlayer.com, our macOS application, APIs, and related services (collectively, the "Services").

We collect personal data. That includes account identifiers, mission content you submit, technical logs, and — if you opt in — analytics or error reports. We do not collect that data secretly: required processing is described here; optional tracking waits for your choice on the cookie bar or Cookie settings.

If you do not agree with this policy, please do not use the Services.

1. Information We Collect

Account Information

Email address, internal user ID, password hash, account role, verification status, subscription or plan status, and optional promo or coupon metadata.

Profile and Preferences

Optional profile photo, experience or design mode preferences, and notification preferences you set in the app.

Mission and Product Data

Mission prompts, planning inputs, mission metadata, template selections, repo paths and project metadata you submit, plan quality signals, daily mission counts, queue priority tier, client type (web or macOS), and related product usage.

We do not upload or store your full codebase by default. Do not submit passwords, API keys, government IDs, or other secrets in prompts unless a feature explicitly requires it and you choose to do so.

Mission Screenshots

If screenshot capture is enabled for a mission, the macOS app may upload images to help with troubleshooting or support. You can disable capture where the product allows.

Device and App Data

macOS app version, build number, update-check identifiers, agent or Mac pairing identifiers, heartbeat and connectivity metadata, and coarse device identifiers used for updates and security.

Install Integrity Signals

To prevent abuse and duplicate free-tier accounts, we may store hashed install-root identifiers and related fraud-prevention signals. We do not collect raw hardware serial numbers for this purpose.

Payment Data

Billing status, Stripe customer and subscription identifiers, and limited transaction metadata. We do not store full payment card numbers.

Communications and Forms

Support emails, transactional messages (verification, password reset, billing), contact form submissions (name, email, message, optional IDE suggestions), waitlist signups (email and optional role), platform-notify interest (email and platform), and in-app feedback you submit (message, category, rating, app version, and device identifiers such as mac_id).

Usage Analytics

- **Website:** On public marketing pages only, we may use Google Analytics to understand traffic and page views. We do not load Google Analytics on signed-in app, admin, auth, or checkout routes.

- **Product:** The macOS app may send first-party analytics events (feature usage, surfaces viewed, coarse properties such as experience mode or truncated work paths) to our servers to improve the product.

Technical and Security Logs

IP address, browser or app type, approximate region from IP, session identifiers, cookies or local storage on the website, referral URLs, login session metadata (IP address and user agent), error and performance logs, and admin audit records of operator actions taken for support, billing, or security.

2. How We Use Information

We use information to:

- provide, operate, and secure the Services

- create and authenticate accounts and enforce plan limits (including free-tier demo rules)

- run missions, pairing, updates, and billing

- send transactional messages and, occasionally, product announcements to verified users

- provide support and respond to contact, waitlist, and feedback submissions

- monitor reliability, debug issues, prevent abuse, and investigate violations

- comply with law and establish, exercise, or defend legal claims

- improve the Services through aggregated or first-party analytics

Authorized Operator Access

A small number of authorized AutonomLayer operators may access user account data through our admin tools for support, billing, fraud prevention, security investigations, and service operation. Access is restricted by role and logged in admin audit records.

3. AI Processing

We use AI to generate mission plans, ImproveAI briefs, and related product features. Mission prompts, planning inputs, and related metadata may be processed by AI infrastructure we operate or configure (for example Google Cloud Vertex AI) and, if enabled, other providers (such as OpenRouter) or local models on your machine (for example Ollama).

This use of AI is disclosed here and in our Terms. We do not use your mission prompts, plans, or account content to train public foundation models. We process this data to provide mission planning and related features for your account.

AutonomLayer is not a crisis, medical, or mental-health service. Models are instructed not to assist with suicide, self-harm, or harming others, and to point people to emergency or crisis resources instead. Those guardrails can fail; if you or someone else is in danger, contact local emergency services immediately (US: 988; EU: local emergency numbers; Türkiye: 112 / 182).

Third-party AI and IDE providers (for example Anthropic, OpenAI, Cursor) process data under their own terms when you use their products. You are responsible for your use of third-party tools and for not submitting data you are not permitted to share.

4. Cookies and Analytics Choices

Our website uses cookies, local storage, and similar technologies.

Necessary (always on): authentication, session management, security, and storing your privacy choices.

Optional (off until you opt in via the cookie bar at the bottom of the site, or Cookie settings):

- Google Analytics on public marketing pages (not on signed-in app, admin, auth, or checkout)

- Sentry error reporting when enabled in the product

- first-party product insight events after you sign in

You can change optional choices anytime at https://autonomlayer.com/welcome (Cookie settings). Rejecting optional tools does not block accounts or missions.

Third-party collectors that may receive data if you opt in or as processors of the Services include Google (Analytics, Cloud / Vertex AI), Stripe (payments), Resend (email), Sentry (errors, if enabled), and OpenRouter (optional AI). They act as processors or independent controllers under their own policies.

We do not sell your personal information for money. We do not "share" personal information for cross-context behavioral advertising as defined under California law. California residents can use the same privacy-choices screen as a Do Not Sell / Do Not Share control.

5. Legal Bases (EEA/UK)

For users in the EEA/UK (GDPR / UK GDPR), we process personal data based on:

- performance of a contract (providing the Services)

- legitimate interests (security, fraud prevention, and strictly necessary operations), balanced against your rights

- compliance with legal obligations

- consent where required (optional analytics, error reporting, and similar cookies)

Türkiye (KVKK): AutonomLayer processes personal data as a data controller for the purposes in this policy. You may request information, correction, deletion, objection, and transfer (where applicable) by emailing support@autonomlayer.com. You may also complain to the Turkish Personal Data Protection Authority (KVKK Kurulu).

United States: California residents have CPRA/CCPA rights described in section 9. Other US state privacy laws (for example Virginia, Colorado, Connecticut) may provide similar access, deletion, and opt-out rights; email the same address to exercise them.

6. Sharing and Subprocessors

We may share information with service providers that process data on our behalf, including:

- Stripe — payment processing

- Google Cloud / Vertex AI — cloud hosting and AI inference (when configured)

- OpenRouter — optional AI inference (when configured)

- Resend and similar providers — transactional email

- Sentry — error monitoring (when enabled)

- Google Analytics — website analytics on public pages only (when enabled)

We share information only as needed for them to perform their functions, under contracts requiring appropriate confidentiality and security. We may disclose information if required by law, to protect rights and safety, to enforce our terms, or in connection with a merger, acquisition, or sale of assets, with notice where required.

We may share aggregated or de-identified information that cannot reasonably identify you.

7. International Transfers

We process and store information in the United States and other countries where we or our providers operate. Those countries may have different data protection laws than your country.

Where required for transfers from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms. Contact support@autonomlayer.com for more information.

8. Data Retention

We retain information as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.

Examples:

- account data: while your account is active, then deleted or de-identified within a reasonable period after closure (subject to backups, typically within 90 days)

- billing records: as required for tax and accounting (often up to 7 years where required)

- security and admin audit logs: typically up to 12–24 months unless longer retention is required

- contact, waitlist, and feedback records: typically up to 3 years unless deleted earlier on request

- website analytics: per provider settings (often 14–26 months)

Retention periods may vary by data type and legal requirements.

9. Account Deletion and Your Rights

You may request account deletion or exercise privacy rights by emailing support@autonomlayer.com from the email associated with your account, or from Settings in the signed-in app.

User uploads: profile photos and mission screenshots (when capture is enabled) are stored on private application storage, not a public cloud bucket. They are not listed on the open internet. When you request deletion, we delete or de-identify those files from active systems, then from backups within a reasonable period (typically within 90 days).

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information; object to or restrict certain processing; withdraw consent where processing is based on consent; and lodge a complaint with a supervisory authority (for example an EU DPA, the UK ICO, or Türkiye's KVKK Kurulu).

California residents (CPRA/CCPA): rights to know, delete, correct, opt out of sale/sharing (we do not sell; optional analytics is consent-based), limit use of sensitive personal information where applicable, and non-discrimination for exercising rights.

We may verify your identity before fulfilling requests and respond within timeframes required by applicable law.

10. Security

We use reasonable technical and organizational measures, including encryption in transit (TLS), access controls, hashed passwords, and administrative safeguards. User uploads (avatars, optional mission screenshots) are stored in private application storage with authenticated access — not a public object-storage bucket.

No method of transmission or storage is completely secure.

If we become aware of a personal data breach that triggers notification obligations, we will notify affected users and regulators as required by applicable law.

11. Children

The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you are in the United States and under 13, you must not use the Services (COPPA).

If you believe a child has provided us information, contact support@autonomlayer.com and we will take appropriate steps to delete it.

12. Changes

We may update this Privacy Policy from time to time. We will post the revised version on this page with an updated effective date and version number. For material changes, we may provide additional notice (for example by email or in-product notice) where required by law.

13. Contact

Privacy and data subject requests: support@autonomlayer.com

Legal notices: legal@autonomlayer.com

Postal address: Provided upon written request to support@autonomlayer.com.

AutonomLayer

Mission orchestration for macOS. Structured AI work in Cursor or Codex.

Product

  • Overview
  • Features
  • How it works
  • Pricing
  • Download

Company

  • Manifesto
  • Blog
  • Enterprise
  • Contact

Resources

  • Workshops
  • Docs
  • Demo
  • Log in
  • Sign up

© 2026 AutonomLayer

  • Privacy
  • Terms
  • EULA
  • Cookies