Privacy Policy
At Neotyk, LLC (“Neotyk”, “we”, “our”, or “us”), we engineer the aForce Platform on a foundation of Zero-Trust architecture and zero data retention. This Privacy Policy details how we handle information across neotyk.ai, console.neotyk.ai, and during 30-day trial evaluations.
Neotyk, LLC guarantees that customer source code, pull requests, backlog tickets, commit metadata, and session inputs are never used to train, retrain, fine-tune, or reinforce any public or third-party artificial intelligence models. All model inference is conducted over private enterprise APIs with contractual zero-retention policies.
01. Scope & Data Controller
This Privacy Policy applies to personal and organizational data processed when you visit our website (neotyk.ai), register for or use the digital workforce application (console.neotyk.ai), or initiate a 30-day evaluation trial.
The Data Controller responsible for your personal data is Neotyk, LLC, a Delaware limited liability company. For any privacy or data rights inquiries, our Data Protection team can be reached at privacy@neotyk.com.
02. Information We Collect
We collect only the minimum information necessary to provision agent fleets, authenticate users, and execute software development workflows:
- Full name and corporate work email address
- Company or engineering squad name
- Authentication credentials (OAuth ID via GitHub/Google or SSO)
- Capacity tier selection (Individuals, Teams, or Enterprise)
- Connected repository names and branch targets
- Issue tracker tickets and descriptions (Jira, Linear, GitHub Issues)
- Ephemeral Git access tokens authorized by customer
- Webhook payload event headers and commit SHAs
- Source code diffs checked out into isolated micro-sandboxes
- Automated test execution output and linting logs
- Agent scratchpad reasoning and diff generation logs
- Purged automatically when the agent session concludes
- IP address and browser user-agent (for rate-limiting & security)
- Platform session logs and API request timestamps
- Agent task execution duration and model token volume counts
- Aggregated performance and error diagnostics
03. How We Use Information
We process collected information solely for the following legitimate purposes:
- Executing Autonomous Workflows: Orchestrating agent runs to inspect assigned tickets, clone isolated branches, write regression tests, and prepare pull requests.
- Managing Trial Accounts: Provisioning capacity allocations (e.g. 5 agents for Individuals, 10 agents for Teams) and notifying users regarding onboarding status.
- Zero-Trust Security & Sandboxing: Verifying authentication tokens, enforcing micro-sandbox isolation, preventing cross-tenant data leakage, and halting malicious abuse.
- Customer Support: Responding to bug reports, operational inquiries, and engineering questions submitted to
aforce@neotyk.com.
04. Zero-Trust Micro-Sandboxing & Isolation
Unlike traditional monolithic architectures, the aForce Platform enforces micro-sandboxing on every task:
Each task assigned to an autonomous agent runs inside a dedicated, isolated micro-sandbox. When the task is complete, the entire container volume, temporary files, and checked-out files are destroyed.
Customer Git credentials and API keys are injected exclusively in memory during task runtime and are never logged to persistent audit databases or disk.
05. Subprocessors & Infrastructure Partners
We rely on enterprise-grade infrastructure providers to deliver reliable, secure services. All subprocessors are bound by strict Data Processing Addendums (DPAs) and confidentiality agreements:
| Partner / Service | Function | Location | Data Safeguard |
|---|---|---|---|
| Cloudflare, Inc. | DNS, Edge CDN, DDoS Protection, Static Portal Hosting | Global / USA | TLS 1.3, SOC 2 Type II, ISO 27001 |
| Render Services, Inc. | Cloud Application Hosting, Web Backend, Managed Databases | United States | Encrypted at rest (AES-256), SOC 2 Type II |
| Enterprise LLM APIs | Model Inference & Agent Reasoning | United States | Strict Zero-Data-Retention & Zero-Training Agreements |
06. Data Retention & Deletion
We retain personal information only for as long as necessary to fulfill the purposes described in this policy:
- Task Code & Sandboxes: Wiped immediately upon completion or cancellation of each agent task.
- 30-Day Trial Accounts: Account profiles and operational telemetry are kept active throughout the trial period. If a trial is not converted to a subscription, account data is decommissioned and scheduled for permanent deletion within 30 days of trial expiration.
- Deletion Requests: Customers may request immediate deletion of their account, integration tokens, and workspace metadata at any time by emailing privacy@neotyk.com.
07. Your Privacy Rights (GDPR & CCPA/CPRA)
Regardless of your geographical location, Neotyk extends core data privacy protections to all customers:
- Right to Access & Portability: You may request a copy of the personal information we maintain regarding your account.
- Right to Rectification: You may correct inaccurate or incomplete contact details.
- Right to Erasure (“Right to Be Forgotten”): You may request complete erasure of your account and related metadata.
- Right to Revoke Integration Access: You may disconnect your GitHub/GitLab organizations or Jira instances at any time via platform settings, immediately revoking token authorizations.
- No Sale or Sharing of Personal Information: We do not sell, rent, or monetize your personal information or code data under CCPA/CPRA or any other privacy regulation.
08. Cookies & Web Tracking
Our landing page and platform use strictly essential cookies required for session security, CSRF protection, and user authentication. We do not use third-party behavioral advertising trackers, data brokers, or retargeting pixels.
09. Security Measures
We implement administrative, technical, and physical safeguards designed to protect personal and organizational information against unauthorized access, loss, or misuse:
- Encryption in transit using TLS 1.3 across all domains (
neotyk.aiandconsole.neotyk.ai). - Encryption at rest using AES-256 for all stored configuration settings.
- Principle of least privilege and strict multi-factor authentication (MFA) enforcement across all production engineering infrastructure.
10. Contact Information
If you have questions, feedback, or requests regarding this Privacy Policy or our data protection architecture, please contact our Privacy Team: