Data Protection • Effective September 2026

Privacy Policy

At Neotyk, LLC (“Neotyk”, “we”, “our”, or “us”), we engineer the aForce Platform on a foundation of Zero-Trust architecture and zero data retention. This Privacy Policy details how we handle information across neotyk.ai, console.neotyk.ai, and during 30-day trial evaluations.

Data Controller
Neotyk, LLC
LLM Training
Strict Zero-Training
Sandbox Lifetime
Ephemeral / Purged
Ad Trackers
0 (None Used)
Our Core Principle: Your Code is Never Model Training Data

Neotyk, LLC guarantees that customer source code, pull requests, backlog tickets, commit metadata, and session inputs are never used to train, retrain, fine-tune, or reinforce any public or third-party artificial intelligence models. All model inference is conducted over private enterprise APIs with contractual zero-retention policies.

01. Scope & Data Controller

This Privacy Policy applies to personal and organizational data processed when you visit our website (neotyk.ai), register for or use the digital workforce application (console.neotyk.ai), or initiate a 30-day evaluation trial.

The Data Controller responsible for your personal data is Neotyk, LLC, a Delaware limited liability company. For any privacy or data rights inquiries, our Data Protection team can be reached at privacy@neotyk.com.

02. Information We Collect

We collect only the minimum information necessary to provision agent fleets, authenticate users, and execute software development workflows:

Account & Trial Intake Data
  • Full name and corporate work email address
  • Company or engineering squad name
  • Authentication credentials (OAuth ID via GitHub/Google or SSO)
  • Capacity tier selection (Individuals, Teams, or Enterprise)
Integration & Workspace Metadata
  • Connected repository names and branch targets
  • Issue tracker tickets and descriptions (Jira, Linear, GitHub Issues)
  • Ephemeral Git access tokens authorized by customer
  • Webhook payload event headers and commit SHAs
Transient Execution Data
  • Source code diffs checked out into isolated micro-sandboxes
  • Automated test execution output and linting logs
  • Agent scratchpad reasoning and diff generation logs
  • Purged automatically when the agent session concludes
Technical & Telemetry Data
  • IP address and browser user-agent (for rate-limiting & security)
  • Platform session logs and API request timestamps
  • Agent task execution duration and model token volume counts
  • Aggregated performance and error diagnostics

03. How We Use Information

We process collected information solely for the following legitimate purposes:

  • Executing Autonomous Workflows: Orchestrating agent runs to inspect assigned tickets, clone isolated branches, write regression tests, and prepare pull requests.
  • Managing Trial Accounts: Provisioning capacity allocations (e.g. 5 agents for Individuals, 10 agents for Teams) and notifying users regarding onboarding status.
  • Zero-Trust Security & Sandboxing: Verifying authentication tokens, enforcing micro-sandbox isolation, preventing cross-tenant data leakage, and halting malicious abuse.
  • Customer Support: Responding to bug reports, operational inquiries, and engineering questions submitted to aforce@neotyk.com.

04. Zero-Trust Micro-Sandboxing & Isolation

Unlike traditional monolithic architectures, the aForce Platform enforces micro-sandboxing on every task:

Ephemeral Micro-VM / Container Lifetime

Each task assigned to an autonomous agent runs inside a dedicated, isolated micro-sandbox. When the task is complete, the entire container volume, temporary files, and checked-out files are destroyed.

Ephemeral In-Memory Token Vault

Customer Git credentials and API keys are injected exclusively in memory during task runtime and are never logged to persistent audit databases or disk.

05. Subprocessors & Infrastructure Partners

We rely on enterprise-grade infrastructure providers to deliver reliable, secure services. All subprocessors are bound by strict Data Processing Addendums (DPAs) and confidentiality agreements:

Partner / Service Function Location Data Safeguard
Cloudflare, Inc. DNS, Edge CDN, DDoS Protection, Static Portal Hosting Global / USA TLS 1.3, SOC 2 Type II, ISO 27001
Render Services, Inc. Cloud Application Hosting, Web Backend, Managed Databases United States Encrypted at rest (AES-256), SOC 2 Type II
Enterprise LLM APIs Model Inference & Agent Reasoning United States Strict Zero-Data-Retention & Zero-Training Agreements

06. Data Retention & Deletion

We retain personal information only for as long as necessary to fulfill the purposes described in this policy:

  • Task Code & Sandboxes: Wiped immediately upon completion or cancellation of each agent task.
  • 30-Day Trial Accounts: Account profiles and operational telemetry are kept active throughout the trial period. If a trial is not converted to a subscription, account data is decommissioned and scheduled for permanent deletion within 30 days of trial expiration.
  • Deletion Requests: Customers may request immediate deletion of their account, integration tokens, and workspace metadata at any time by emailing privacy@neotyk.com.

07. Your Privacy Rights (GDPR & CCPA/CPRA)

Regardless of your geographical location, Neotyk extends core data privacy protections to all customers:

  • Right to Access & Portability: You may request a copy of the personal information we maintain regarding your account.
  • Right to Rectification: You may correct inaccurate or incomplete contact details.
  • Right to Erasure (“Right to Be Forgotten”): You may request complete erasure of your account and related metadata.
  • Right to Revoke Integration Access: You may disconnect your GitHub/GitLab organizations or Jira instances at any time via platform settings, immediately revoking token authorizations.
  • No Sale or Sharing of Personal Information: We do not sell, rent, or monetize your personal information or code data under CCPA/CPRA or any other privacy regulation.

08. Cookies & Web Tracking

Our landing page and platform use strictly essential cookies required for session security, CSRF protection, and user authentication. We do not use third-party behavioral advertising trackers, data brokers, or retargeting pixels.

09. Security Measures

We implement administrative, technical, and physical safeguards designed to protect personal and organizational information against unauthorized access, loss, or misuse:

  • Encryption in transit using TLS 1.3 across all domains (neotyk.ai and console.neotyk.ai).
  • Encryption at rest using AES-256 for all stored configuration settings.
  • Principle of least privilege and strict multi-factor authentication (MFA) enforcement across all production engineering infrastructure.

10. Contact Information

If you have questions, feedback, or requests regarding this Privacy Policy or our data protection architecture, please contact our Privacy Team:

Neotyk, LLC
Attn: Data Protection Officer & Legal Department
Privacy Inquiries: privacy@neotyk.com
Legal Inquiries: legal@neotyk.com