Introduction
cmd deck ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your data. This Privacy Policy explains how we collect, use, store, and protect your information when you use the cmd deck platform.
Data Usage Guarantee: No LLM Training
We explicitly guarantee that your data will NEVER be used for training large language models (LLMs) or any other machine learning systems.
This guarantee applies to all data you provide to cmd deck, including but not limited to:
- Task descriptions and content
- Comments and communications
- Code references or snippets
- Project names and metadata
- Session notes and workspace information
- Any other user-generated content
Your proprietary codebases, project information, and all associated data remain strictly confidential and are never used for AI model training purposes.
Information We Collect
Information You Provide
- Account Information: Email address, name, and authentication credentials
- Task and Project Data: Task titles, descriptions, comments, labels, priorities, and project metadata
- Agent Information: Agent names, session IDs, workspace paths, and session notes
- GitHub Integration Data: Branch names, pull request URLs, and PR status (if you choose to link GitHub)
- Billing Information: Payment details processed securely through Stripe (we do not store full credit card numbers)
Automatically Collected Information
- Usage Data: Features used, interactions with the platform, and error logs
- Technical Information: IP address, browser type, device information, and access times
- API Activity: MCP server requests and responses (when using AI agent integrations)
How We Use Your Information
We use your information solely for the following purposes:
- Service Delivery: To provide, maintain, and improve the cmd deck platform
- Authentication: To verify your identity and secure your account
- Communication: To send service updates, notifications, and respond to support requests
- Billing: To process payments and manage subscriptions
- Analytics: To understand usage patterns and improve user experience (aggregated and anonymized)
- Security: To detect, prevent, and address technical issues and security threats
We do NOT:
- Use your data to train AI models or LLMs
- Sell your personal information to third parties
- Share your proprietary code or project data with external parties
- Use your content for marketing purposes without explicit consent
Data Storage and Security
Storage Infrastructure
- Your data is stored securely using Supabase, a secure PostgreSQL database platform
- All data is encrypted in transit using TLS/SSL
- Data at rest is encrypted using industry-standard encryption protocols
- Database backups are encrypted and stored securely
Security Measures
- Row-level security (RLS) policies ensure users can only access their own data
- API keys and authentication tokens are required for all MCP server interactions
- Regular security audits and monitoring
- Access controls and permission management for team workspaces
Data Retention
- Active account data is retained for as long as your account is active
- Deleted tasks and projects are permanently removed from our systems
- Closed accounts: data is deleted within 30 days of account closure
- Backup retention: encrypted backups are retained for 90 days for disaster recovery
Third-Party Services
We use the following trusted third-party services:
These services are contractually obligated to protect your data and may not use it for purposes other than providing services to cmd deck.
AI Agent Integration & MCP Server
When you use cmd deck with AI agents through the Model Context Protocol (MCP):
- Remote MCP Endpoints: API calls are encrypted and authenticated with your personal API key
- Agent Data: Agent names, session IDs, and task interactions are stored to provide service functionality
- No Third-Party AI Training: Data accessed by AI agents through our MCP server is NOT sent to third parties for model training
- Your Control: You control what data agents can access through authentication and permissions
Your Rights and Choices
Access and Portability
- View all your data through the cmd deck dashboard
- Export your tasks, projects, and comments at any time
- Request a complete data export by contacting support
Modification and Deletion
- Edit or delete tasks, comments, and projects directly in the application
- Update your account information and preferences
- Delete your account and all associated data
Privacy Controls
- Manage team member access and permissions
- Control GitHub integration settings
- Generate and revoke API keys for MCP access
- Configure notification preferences
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data:
For data subject requests (access, deletion, portability), please include your account email address, a description of your request, and any relevant account or project identifiers.
We will respond to all requests within 30 days.
Summary of Key Commitments
- ✅ No LLM Training: Your data will NEVER be used to train AI models
- ✅ No Data Selling: We will never sell your personal information
- ✅ Encryption: All data is encrypted in transit and at rest
- ✅ Your Control: You can access, export, and delete your data at any time
- ✅ Transparency: Clear policies on what we collect and how we use it
- ✅ Security: Industry-standard security measures and regular audits