Privacy Policy

Last Updated: August 12, 2026 · Version 1.3.0
Zero Workspace Telemetry Guarantee. The local thumbgate CLI and open-source engine operate on your host disk (~/.thumbgate/, .claude/). Zero workspace source code, repository contents, or project file data is fetched, transmitted, or publicly rendered by ThumbGate.
Local-first is not “zero personal data.” Account, billing, device pairing, support, and cloud-runner metadata may still be processed when you use hosted or paid surfaces. Local-first means workspace source stays on your machine by default.

Data Collection

We collect information only as needed to operate the product you use:

Data Sharing

We do not sell customer data. Hosted data is used to operate the service and is shared with subprocessors only as needed for infrastructure, payments, email, analytics, or when required by law.

Your Privacy Choices

ThumbGate does not sell or share personal information as those terms are defined by the California Consumer Privacy Act (CCPA/CPRA, Civil Code §1798.140). Because there is no sale or sharing, there is nothing to opt out of.

We honor the Global Privacy Control (GPC) browser signal, and Do Not Track, as opt-out preference signals. When either is set, our marketing pages suppress first-party telemetry at the point of collection rather than collecting and discarding it.

Absent such a signal, marketing-page analytics are pseudonymous, not anonymous: pages attach a visitor identifier and a session identifier to page-view and conversion events so we can count distinct visits. These identifiers are not linked to a name or email unless you submit one to us. CLI telemetry is separate and can be disabled with THUMBGATE_NO_TELEMETRY=1 or DO_NOT_TRACK=1.

To exercise any California privacy right — to know, delete, correct, or limit use of sensitive personal information — email igor@igorganapolsky.com. We respond within the statutory period.

Subprocessors

SubprocessorFunction
StripePayment processing
Railway / cloud hostsApplication hosting and runners
Plausible / PostHogPrivacy-oriented web analytics (where configured)
ResendTransactional email (where configured)
GitHubSource hosting and marketplace surfaces

Listing a vendor is not a claim that ThumbGate is SOC 2 or HIPAA certified, or that a signed GDPR DPA is automatic for every customer.

Data Retention

Local data is retained until you delete the files. Hosted account data is retained while the account or API key remains active, or until you request deletion, subject to operational or legal retention. Cloud-runner logs target a 30-day purge. Billing records may be retained longer for tax and fraud prevention.

Deletion & DPA

Request deletion or export at privacy@thumbgate.ai. Enterprise customers may request a DPA covering GDPR / UK GDPR / CCPA where applicable. Security incidents affecting customer personal data target notice within 72 hours under signed enterprise terms when those terms apply.

Contact

privacy@thumbgate.ai · security@thumbgate.ai · support@thumbgate.ai