last updated 21 August 2026
Privacy Policy
who we are
candlelit is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COMPANY REGISTRATION NUMBER]. We are the data controller for the account information described below.
Questions, or any request about your data: [PRIVACY CONTACT EMAIL].
what we collect
Account information. Your email address and display name. If you sign in with Google we receive these from Google — we never see your password, and we do not request access to your Gmail, Drive, Calendar or contacts.
Workspace content. Everything you or your coding agent create: goals, objectives, key results, epics, work items, sprints, contracts, deployment records and the decision log. This is your content. We process it to provide the service and do not use it to train any model.
Coding session records.When you enable session capture we record the start and end time of each session, which tools were called and how long each took, and token counts reported by your agent. We do not receive the contents of your prompts, your code, or your agent's responses — those never leave your machine.
Connected services. If you connect GitHub, Sentry, PostHog, Datadog, Grafana, Slack or Stripe, we store the credentials you supply. They are encrypted at rest with AES-256-GCM under a key bound to your workspace, and are never returned to the browser.
Billing. Your subscription status and a Stripe customer identifier. Card details go directly to Stripe; we never receive or store them.
Operational data. Request identifiers, error reports and basic access logs, used to keep the service running and to investigate faults.
why we process it
To perform our contract with you (providing the service, authenticating you, billing you). Under our legitimate interest in operating and securing the service (error monitoring, abuse prevention, rate limiting). Where the law requires it (retaining invoices and accounting records).
We do not sell your data, and we do not use it for advertising or profiling.
where it is stored
Your workspace database is hosted by Neon in the European Union (Frankfurt, eu-central-1). Some processors below operate outside the EU; those transfers rely on the European Commission's Standard Contractual Clauses.
who else processes it
Vercel (hosting). Neon (database). Clerk (authentication). Stripe (payments). Inngest (background jobs). Sentry (error monitoring). Upstash (rate limiting). Slack, GitHub, Sentry, PostHog, Datadog and Grafana only if you choose to connect them.
Each acts on our instructions under a data processing agreement.
how long we keep it
Workspace content and session records: for as long as your account is open, and for 30 days after you delete it, after which they are removed from our systems. Backups roll off within 30 days.
Invoices and accounting records: retained for as long as tax law requires, which is longer than the periods above and outside your right to erasure.
your rights
If you are in the EU or UK you may request access to your data, correction of it, deletion of it, a portable copy of it, restriction of its processing, or object to processing based on legitimate interest.
Write to [PRIVACY CONTACT EMAIL] and we will respond within one month. If you are not satisfied you may complain to your national supervisory authority — in France, the CNIL.
security
Traffic is encrypted in transit. Integration credentials are encrypted at rest with AES-256-GCM using a versioned key, bound to the workspace so a credential from one workspace cannot be decrypted in another. Access to a workspace requires membership of it, enforced on every request.
No system is perfectly secure. If we discover a breach affecting your data we will notify you and the relevant authority as the law requires.
cookies
We set only the cookies needed to keep you signed in. No advertising or analytics cookies are set, so there is no consent banner to click.
changes
If we change this policy materially we will tell account holders by email before the change takes effect. The date at the top always reflects the current version.