Privacy Policy
Effective Date: August 7, 2026
1. The short version
Community Edition (self-hosted): Giljo HQ runs entirely on your machine. We cannot see, access, or collect your data. There is no telemetry, no analytics, no phone-home behavior. Your products, projects, agent configurations, and 360 Memory entries never leave your local system.
Hosted (SaaS): If you use the Hosted service, your data is stored on our infrastructure in the United States, encrypted at rest, and processed only to deliver the service. See Section 6 for the full Hosted data practices and subprocessor list.
The giljo.ai website is a standard informational site with minimal data practices.
2. What Giljo HQ stores (Community Edition, on your machine)
This section describes Community Edition data practices. For the Hosted service, see Section 6.
All of the following data is stored in your local PostgreSQL database, on hardware you control:
- Account data (username, bcrypt-hashed password, recovery PIN hashed, API keys hashed)
- Product definitions
- Vision documents
- Project data
- Agent data
- 360 Memory
- Git history (if git integration is enabled)
- Session data
3. What Giljo HQ does NOT do
- No telemetry. The software never phones home.
- No cloud dependency. Everything runs locally.
- No data collection. We never receive your data.
- No tracking. No analytics, no cookies, no user profiling.
- No account registration with GiljoAI. Your account is local to your installation.
4. Third-party AI tools
Giljo HQ coordinates with AI coding agents that you configure. When your AI coding agent connects:
- It sends requests to your local Giljo HQ server
- Giljo HQ responds with context and coordination data
- Your AI coding agent communicates with its own provider's servers
Data sent to AI model providers is governed by that provider's privacy policy. You can review their policies here:
5. The giljo.ai website
- Static informational site
- Standard server logs maintained by our hosting provider
- Site analytics: we use Google Analytics 4 to measure aggregate traffic (page views, referral sources, approximate region). It sets analytics cookies in your browser only after you accept via the cookie notice, and visitor data is processed by Google LLC on our behalf under Google's privacy policy. We use it only to understand site traffic. No advertising use, and we never sell it.
- If you decline, or make no choice, no analytics script loads and no analytics cookies are set. You can change your choice anytime via the "Cookie preferences" link in the footer.
- No user accounts on the website itself
- Contact form submissions are retained only for the purpose of responding to inquiries
6. Hosted (SaaS) data practices
This section applies if you sign up for the Hosted service at giljo.ai (or its subdomains). It does not apply to Community Edition.
6.1 What we collect and store
- Account data: email address and bcrypt-hashed password
- Subscription data: subscription status, plan, billing period, and our payment processor's customer and subscription identifiers (no card numbers; see 6.3)
- Product content: the product definitions, vision documents, project data, agent configurations, 360 Memory entries, and any other content you create in the dashboard
- Operational logs: timestamped records of API requests, agent job runs, and errors, retained for service reliability and security
- Session data: standard authentication session tokens
6.2 Where it is stored
Your Hosted-service data runs on managed PostgreSQL on Railway Pro, hosted on SOC 2 Type 2 infrastructure (Railway on GCP), with encryption at rest and US East region pinning. Access is restricted to the GiljoAI operations team for the purpose of delivering, maintaining, and securing the service.
6.3 Subprocessors
The Hosted service relies on the following third-party subprocessors. Each is contractually bound to handle your data only as needed to provide their service:
- Polar: payment processing and Merchant of Record. Receives your email, name, billing country, tax details when provided, and the amount charged. Stores your card details on its PCI-compliant infrastructure. Polar does not share full card numbers with us. See polar.sh/legal/privacy.
- Resend: transactional email delivery (account verification, password reset, billing notifications). Receives your email address and message content. See resend.com/legal/privacy-policy.
- Sentry: error monitoring. Receives stack traces and anonymised request metadata when errors occur, to help us diagnose and fix bugs. See sentry.io/privacy.
- Cloudflare: DNS, CDN, and reverse proxy. Sees the IP addresses, request headers, and request URLs of traffic to our domains. See cloudflare.com/privacypolicy.
- Railway: application hosting (SaaS deployment). Hosts the backend and database infrastructure for the Hosted service in the United States. See railway.com/legal/privacy.
- Tigris Data: object storage. Stores our encrypted database backup archives and point-in-time recovery archives on infrastructure located in the United States. Provided as part of our hosting provider's storage service. See tigris.dev.
We will update this list when subprocessors change. Material changes will be reflected in the effective date at the top of this page.
6.4 How long we keep your data
- While your subscription is active: we keep your data for as long as your subscription is active.
- If you cancel or your subscription lapses: your account becomes read-only. You can still sign in to view your data, export it, or resubscribe. We keep it for one year from the date your paid access ended, then delete it permanently. We email you a reminder about 30 days before that happens.
- If you ask us to delete your account: you choose immediate deletion, or a 30-day grace period in which you can change your mind. An erasure request made under GDPR Article 17 is completed within the one-month period the law requires.
- What deletion removes: your database records and your stored backup archives are both erased, and your subscription with our payment processor is cancelled as part of the same process.
- Backups: we keep your 7 most recent daily archives, 4 weekly archives, and up to 5 manual archives; older ones are removed automatically. Our hosting provider also takes daily platform snapshots of the database, kept for 6 days, and maintains a continuous point-in-time recovery archive covering up to approximately the last four weeks. Deleted data can persist in these provider-side backups until they age out on those schedules.
- Operational logs: retained for a limited period for service reliability and security, then deleted.
- Deletion receipts: retained for 7 years, then deleted. The receipt contains no personal data: a cryptographic hash of your tenant identifier, the timestamps of each deletion step, and the payment processor's cancellation confirmation, signed with HMAC-SHA256.
6.5 Your rights for Hosted data
Regardless of where you live, you can at any time:
- Access your data through the dashboard
- Export your full dataset as a downloadable ZIP from the dashboard's data-export feature (one click, GDPR-style portability)
- Correct any data through the dashboard, or by emailing us
- Delete your account. If you still have paid Hosted access, cancel your subscription first and wait until the paid period ends before deleting your account. Once deletion is available, we cascade-delete your GiljoAI SaaS data from active systems and retain a tamper-evident deletion receipt for 7 years. Payment records needed for tax, accounting, fraud prevention, or legal compliance may be retained by Polar as payment processor and Merchant of Record.
- Cancel your subscription at any time from the dashboard
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you additionally have rights under the GDPR / UK GDPR including the right to object to processing, restrict processing, lodge a complaint with your national data protection authority, and request data portability in a structured format. GiljoAI LLC is the controller for Hosted-service data. Email [email protected] to exercise any of these rights.
If you are a California resident, you have rights under the CCPA / CPRA including the right to know what personal information we collect, the right to delete it, the right to correct it, and the right to opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information. Email [email protected] to exercise these rights.
6.6 International transfers
Hosted-service data is stored in the United States. If you are accessing the Hosted service from outside the United States, you understand that your data will be transferred to and processed in the United States. Where required by law (such as for EU/UK customers), we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses with our subprocessors.
6.7 What the Hosted service does not do
- We do not sell your data. Not to advertisers, not to data brokers, not to anyone.
- We do not use your project content to train AI models. Your vision documents, projects, and 360 Memory entries are yours.
- We do not read your project content except as needed to deliver the service (for example, an operator may access encrypted backups to investigate a reported outage).
- We do not run third-party advertising inside the product or on the giljo.ai website.
7. Children's privacy
Giljo HQ is a developer tool and is not intended for use by children under 13 years of age.
8. Changes to this policy
Any changes to this privacy policy will be posted on this page with an updated effective date.
9. Your rights (Community Edition)
This section describes your rights for Community Edition. For your rights under the Hosted service, see Section 6.5.
You have complete control over your data. Because Giljo HQ Community Edition runs on your machine, you can:
- Access all your data at any time through the dashboard or directly via PostgreSQL
- Modify any data through the application interface
- Delete any or all data at any time
- Export your data in standard formats
- Uninstall the software and remove all data completely
No request to GiljoAI is needed for any of these actions.
10. Contact
If you have questions about this privacy policy:
[email protected]
GiljoAI LLC
Nashua, NH 03063