Privacy Policy
Last updated: August 13, 2026
1. Overview
This Privacy Policy explains what information the pipper website (pipper.dev) and the Pipper Code desktop application (together, the "Service") collect, how we use it, and the choices available to you. We collect as little data as possible and never sell your personal data.
"Personal data" means information that identifies you, directly or indirectly. By using the Service, you acknowledge the practices described here. Most of the desktop application can be used without an account.
2. What We Collect
We collect only the information needed to run and improve the Service:
Usage analytics (website). The website uses Vercel Web Analytics to collect aggregate statistics, such as page views and referring sites. We use this information to understand how visitors use the site; it is not intended to identify you personally.
Newsletter signups. If you subscribe to the Sandesh newsletter, we collect the email address you provide.
Account data. If you create an account, Clerk provides authentication and processes identity data such as your name, email address, and avatar.
Local workspace data (desktop application). Your prompts, code, files, sessions, and agent activity stay on your machine and are not collected by us. See Section 6.
3. How We Use Your Data
We use the data we collect for the following purposes:
- to operate and secure the Service;
- to authenticate you and keep you signed in;
- to send you the newsletter you requested;
- to understand aggregate usage of the website;
- to comply with legal obligations.
We do not use your data for advertising or profiling, and we do not use it to train AI models.
4. Newsletter
If you subscribe to the Sandesh newsletter, we store the email address you provide in Mailchimp, our email provider, and use it only to send the newsletter you requested. You can unsubscribe at any time using the link in every email. We keep your address only while you remain subscribed.
5. Accounts and Authentication
Sign-in and account features are powered by Clerk. When you sign in, Clerk processes your identity data (such as your name, email address, and avatar, depending on your identity provider) to authenticate you. We receive only the account information needed for the Service to work. We never receive or store your password.
6. The Desktop Application
The Service runs AI coding agents locally on your device. Your prompts, code, files, sessions, and agent activity stay on your machine. The Service does not transmit your source code, prompts, or agent outputs to us. When the Service connects to an AI provider you choose, that traffic is between you and the provider and is governed by the provider's privacy policy.
When you visit the Download page, the website checks our servers for available versions so it can show the latest release. That request does not include your personal data.
7. Community
If you join our Discord server or contribute to our public GitHub repository, any information you share there is governed by those platforms' own policies and is visible to members of those communities.
8. Cookies and Local Storage
The website and the Service may use cookies and local storage to maintain sessions and remember preferences. We do not use them for cross-site advertising tracking.
9. Data Sharing
We do not sell your personal data. We share data only with the service providers described above — Vercel (website hosting and analytics), Clerk (authentication), and Mailchimp (newsletter) — as needed to operate the Service, or when required by law. Each provider handles your data under its own privacy policy and our instructions.
10. Data Retention
We keep personal data only as long as needed for the purposes described in this policy. We delete newsletter addresses when you unsubscribe. If you stop using your account, we retain your data only as long as needed to provide the Service or comply with applicable law, after which we delete or anonymize it.
11. Security
We use reasonable technical and organizational measures to protect personal data against unauthorized access, loss, or alteration. Because authentication is handled by Clerk, we never receive or store your password. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
12. International Data Transfers
The Service operates in part through providers that may process data outside your country of residence. Where personal data is transferred internationally, we rely on appropriate safeguards, such as standard contractual clauses, to protect it.
13. Your Rights
Depending on your jurisdiction (including under the GDPR, CCPA/CPRA, and similar laws), you may have the right to:
- access the personal data we hold about you;
- correct or update that data;
- request deletion of your data;
- opt out of marketing communications;
- object to or restrict processing of your data;
- receive a copy of your data in a portable format.
To exercise any of these rights, contact us via the Discord server linked from the site or through our public GitHub repository. We will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data protection authority.
14. Children's Privacy
The Service is not directed at children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us and we will delete it.
15. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above. If we make significant changes, we will notify you through the Service where reasonably possible.
16. Contact
If you have questions about this policy or how we handle your data, you can reach us via the Discord server linked from the site or through our public GitHub repository.