Privacy Policy
Effective Oct 1, 2026
This policy explains what Buildful collects when you use it, why, who we share it with, and how to control it.
What we collect
- Account details. Your name, email address and avatar, taken from the GitHub or Google account you sign in with.
- Your repositories. For the repos you connect through the Buildful GitHub App, we read code and metadata and write branches and pull requests. Only the repos you select are accessible.
- Task content. The change you describe, the code and logs produced while running it, the pull request it opens, and its QA recording, if one is made.
- Repository settings. Base branch, working directory, setup and check commands, notes for the agent, encrypted env vars, and a captured login used to start browser tests signed in.
- Billing data. Your Stripe customer record — plan, invoices, prepaid credit balance. Card numbers are handled by Stripe and never reach us.
- Usage and analytics. Product events (pages viewed, tasks created) and standard technical logs such as IP address and user agent.
How we use it
- To run the service: connect your repos, execute your tasks, and ship pull requests.
- To bill you: keep your plan, usage and credit records accurate.
- To support you: answer email you send us and investigate problems you report.
- To improve Buildful: understand which features are used and where tasks fail. We do not use your code or task content to train models, and we do not sell your data.
- To keep the service safe: detect abuse, enforce rate limits and scope, and secure accounts.
Who we share it with
We share data only with the providers the product needs to work, each bound to process it on our behalf:
- GitHub — your connected repositories and the pull requests we open there.
- AI model and agent providers — the code and instructions for a task, so a model can write the change.
- Stripe — payments, invoices and card details (we never see the card itself).
- MongoDB Atlas — our application database, which stores accounts, teams, tasks and run logs.
- Vercel and Cloudflare — hosting and networking for the site.
- PostHog — product analytics.
- Integrations you connect — Composio, Slack, Linear and others, only if you connect them.
We may also disclose data if the law requires it. Everything in your account is scoped to your team: members of your team can see its repos, tasks and pull requests; nobody else's team can.
Cookies and analytics
We use a small number of cookies and similar storage to keep you signed in and to measure how the product is used through PostHog. We do not run advertising trackers.
Data retention
Task code and logs are kept so you can review your history; they are deleted within 30 days of your account being deleted. Sandbox workspaces are destroyed when a task finishes. Billing records are kept as long as tax and accounting law requires. Backups roll off within 90 days.
Your rights
You can view, export and delete your data from your account, and you can delete your account entirely, which removes your personal data as described above. Depending on where you live, you may also have the right to access, correct or port your data, or to object to certain processing. To exercise any of these, email hello@buildful.ai and we will respond within the time the law requires.
Security
We encrypt data in transit and at rest, scope every resource to your team, and broker credentials so that keys are available only to the task that needs them, only while it runs. No system is perfectly secure, but we take incidents seriously and will notify affected users where the law requires.
Changes to this policy
As the product changes, this policy may too. If a change is material, we will announce it on the site or by email before it takes effect.
Contact
Privacy questions? Email hello@buildful.ai. The service is operated by the Buildful creators, the makers of Hashnode.