Privacy Policy

Denly · Operated by Control Plane · Effective: August 3, 2026

This Privacy Policy explains what Denly, operated by Control Plane (the "Service", at https://denly.dev) collects, what it deliberately does not, and how your information is handled.

The data boundary – what never reaches us. Denly agents run on your own machine. Your source code and your AI provider credentials (API key or subscription – Anthropic / Claude or whichever agent runtime you use) stay on that machine – they are never transmitted to, processed by, or stored on our servers. Your code goes to your code host (e.g. GitHub) directly from your machine. We only ever see whether a runner authenticates with a subscription or an API key – never the key material itself. When you enable end-to-end encryption, the free-text content that could quote your code – task descriptions, plans, and agent conversations – is encrypted on your device under a passphrase only you hold, before it is uploaded. We store only the resulting ciphertext and cannot read it; we hold no copy of your passphrase or key. What we still see in that mode is non-content metadata: status, timing, cost, and pull-request URLs.

1. Information We Collect

2. What We Do Not Collect

3. How We Use Information

To provide and operate the Service, coordinate agent work, show your dashboard, enforce plan limits, secure the Service and prevent abuse, communicate with you about your account, and comply with law.

4. Service Providers (Sub-processors)

Full detail on each one – what it receives and where it operates – is on our Subprocessors page. If your organization needs a Data Processing Addendum, see our DPA.

Not a subprocessor: Anthropic (Claude), and any other AI provider your runtime uses. Your agent runs locally on your own machine, authenticated with your own API key or subscription. It talks to your AI provider directly – we never see the request, the response, or your credentials. That provider is your processor for that traffic, under whatever agreement you have with them, not ours.

5. Cookies & Local Storage

The dashboard uses local storage for your session token and interface preferences. It does not use third-party advertising or tracking cookies.

6. Data Retention

We retain your information while your account is active and as needed to provide the Service and meet legal obligations. Disconnecting a project or deleting your organization removes the associated metadata from the control database.

Beyond that, these categories are deleted automatically on a schedule:

Deleting your account erases your personal data immediately rather than waiting for these periods – see §7.

7. Your Rights

Depending on your location, you may have rights to access, correct, export, or delete your personal information. You can manage or delete much of it directly in the dashboard, or contact us to exercise these rights.

8. Security

We use measures such as scoped runner tokens, per-organization isolation, and encrypted transport. Optionally, end-to-end encryption (above) keeps your task content unreadable to us even at rest. No method is perfectly secure, but the data boundary above minimizes what is ever at risk on our side.

9. International Transfers & Children

Your information may be processed in countries other than your own. The Service is not directed to children under 16, and we do not knowingly collect their information.

10. Changes

We may update this Policy; material changes will be posted here with a new effective date.

11. Contact

Privacy questions: legal@denly.dev.