Get

Privacy Policy

Effective September 1, 2026.

The short version

AirCode Ø keeps its control plane, project index and coding-session state on the server you configure. Coding-agent CLIs still send the context required for their requests to the AI provider you choose. If you enable the managed AirCode Ø relay, encrypted remote-access traffic passes through relay infrastructure operated for AirCode Ø.

Analytics are separate for the public website and for the product apps. Using aircodezero.com accepts the website usage statistics described below; if you do not accept them, do not use the website. Product apps collect the required product usage statistics described below after you accept the current End User License Agreement and Privacy Policy. We do not use analytics for advertising, and analytics never contains prompts, code, commands, file paths, project names, session names, server addresses or email addresses.

Controller

Spartacus lab SARL, 32 route du Vallon, 1224 Chêne-Bougeries, Switzerland, is the controller for the personal data described in this policy. Privacy questions and rights requests can be sent to privacy@aircodezero.com.

Website usage statistics

Using aircodezero.com accepts the collection described in this section. It starts when a page of the website loads, and we measure:

  • a normalized page category, such as home, pricing or docs;
  • foreground engagement time in short bounded intervals;
  • pricing and navigation CTA clicks; and
  • download-button clicks, including the artifact, platform, release channel and version shown by the website.

The analytics event contains the site origin and a separate normalized screen category, never the raw path, query string or fragment. When the Google provider is enabled, we disable advertising storage, advertising personalization, Google Signals and automatic enhanced measurement. Google may still process technical information normally associated with Analytics, including an analytics cookie or client identifier, browser and device information, network information, and approximate geography derived from the connection IP. AirCode Ø does not add an account ID or email address to these events. Browser analytics cookies are configured with separate website/product prefixes and an expiry of no more than 390 days from creation. Google may also derive first visits, app first opens, sessions and engagement from the allowed events and technical information.

A download click measures intent, not a completed download. We use aggregate delivery data and official Store reports to understand completed downloads and installations.

Required product usage statistics

The web app, Desktop apps and native mobile apps use a separate product analytics configuration. After you select Agree and continue on the versioned product startup screen, we measure:

  • app opens and the first measurable open in that app or browser storage;
  • normalized screens, without route identifiers or raw URLs;
  • foreground active time, in short bounded intervals;
  • onboarding start/completion and coarse server-connection outcomes; and
  • the start of a coding session, limited to engine, execution mode and launch mode; and
  • approval of a Guided setup blueprint, limited to fixed category buckets for decision completeness, unresolved items, accepted recommendations, developer overrides, reconsideration after changed constraints, contradictions resolved before approval, interaction count and elapsed setup time. No Guided setup analytics event is sent before blueprint approval; a completed recovery after approval may use one fixed action token; and
  • progress through the optional guided tour, limited to which of the two audiences was chosen, which of the six built-in chapters was started, completed or left, and the numbered position inside a chapter. Chapter names come from a fixed list shipped with the app; no project, file, prompt or free-form text is attached.

When the Google provider is enabled, native mobile analytics use Google Firebase Analytics. Automatic screen reporting and advertising identifiers are disabled. Firebase may process a pseudonymous app-instance identifier together with app version, operating system, device category, network information and approximate geography derived from the connection IP. AirCode Ø does not attach an AirCode Ø account ID or email address. Web and Desktop analytics do not send raw URLs, referrers or account identifiers. Analytics never contains prompts, code, terminal input or output, tool calls, file contents or paths, project names, session names, server hostnames, connection URLs, credentials, feedback text or email addresses. Guided setup analytics also exclude project and blueprint identifiers, decision identifiers and values, constraints, rationales, alternatives, starter or import URLs, deployment targets, and exact counts or timestamps.

When internal analytics are enabled, they receive the same allowlisted events described above. Website and product usage remain separate, and the stored events do not contain connection IP addresses, raw URLs, account identifiers or a persistent AirCode Ø user identifier. Authorized administrators use this data only for aggregate reporting and collection health.

Authorized administrators may also view aggregate Google Analytics reports and operational account totals. These sources remain separate and are not joined to pseudonymous analytics users. Viewing the reports does not create additional analytics events.

Analytics controls

Website usage statistics are part of using aircodezero.com and do not have a separate on-site opt-out. If you do not accept this processing, do not use the website. Browser-level controls such as cookie blocking, tracking protection or a content blocker keep working, and using them has no effect on website access. A refusal recorded in a browser before this policy took effect is still honoured in that browser.

Product usage statistics are part of using the product under the accepted End User License Agreement and do not have a separate in-product opt-out. If you do not accept this processing, do not select Agree and continue and do not use the product apps. To stop future product statistics, stop using the product apps; uninstalling a native app or clearing its local data also removes its local analytics state. You may still exercise the applicable rights described below.

To stop future website statistics, stop using the website. Clearing the browser’s site data for aircodezero.com removes AirCode Ø’s website Google Analytics cookies and the local analytics state it holds, but stopping collection does not retroactively remove aggregate reports or events already received. Because analytics are pseudonymous and are not linked to an AirCode Ø account, we may be unable to identify an event as belonging to a particular person.

Google Analytics event-level data is retained for no longer than 14 months. Internal analytics and collection-health data are retained for no longer than three months. Security and abuse-prevention logs have a separate, shorter operational lifecycle.

Other data the product sends us

Data When Contents
Update check periodically product version and release channel
License activation / validation if you activate online license key and a pseudonymous device identifier
Feedback submission only when you select Send feedback the information and optional attachments you choose to submit, plus the disclosed client surface, operating system, app/server versions, runtime, and coarse device/server hardware needed to investigate a bug; the technical context excludes device names, serial numbers, stable device identifiers, credentials, and project paths

Feedback is voluntary and is not sent in the background. Submitted information and optional attachments are stored securely, are available only to authorized personnel, and are retained only as long as reasonably needed to review and respond to the submission, meet legal obligations and protect the service.

No AI model currently receives feedback or attachments. If automated analysis is enabled later, this policy and the applicable safeguards will be updated before that processing begins.

Website, downloads and security

Our hosting and security providers process connection data, including IP addresses, as needed to deliver content, measure aggregate delivery, prevent abuse and protect the service. Analytics collection may also use the connection IP transiently for rate limiting; the IP is not stored with analytics events.

If you use the contact or feedback form, it sends the fields you enter. The current page category and user agent may be included for troubleshooting. Our security provider may process the request IP transiently to enforce abuse limits; the IP is not stored with the feedback submission or included in notifications.

Purchases

Production purchases are not currently available through the website or product apps. Isolated Marketplace Commerce tests use Stripe test mode and synthetic purchase data only. Stripe handles the test payment form; AirCode Ø stores bounded attempt, amount, consent, provider-id, and entitlement records, but no complete card number, bank detail, KYC document, billing address, Checkout URL, receipt URL, or raw webhook body. This policy and the applicable purchase terms must be reviewed again before any live purchase flow opens.

Voluntary support for AirCode Ø

The official Support AirCode Ø page checks a same-origin, non-cached status before it can hand you to the configured Buy Me a Coffee profile for Spartacus lab SARL. The website stores no supporter identity, amount, currency, payment method, receipt, provider transaction, payout record, or completion status for this flow. Buy Me a Coffee and its payment provider process the information you submit after leaving AirCode Ø under their own terms and privacy notices. Supporting AirCode Ø does not change your plan or unlock product features.

Marketplace listings, reports and external actions

Creators choose the public Marketplace profile, listing copy, captures, distribution model, source declaration, and optional external donation identity they publish. Open source listings may display the declared public GitHub repository, exact commit and SPDX license. Donation actions display an allow-listed provider and public recipient before leaving AirCode Ø; AirCode Ø does not receive the donation or store donor/payment information.

When a signed-in account rates a Marketplace app, AirCode Ø stores the account identifier, listing identifier, an integer from one to five, and creation and update timestamps. We use these fields to enforce one editable rating per account and app, reject self-ratings, calculate aggregate stars and the confidence-weighted Top rated order, prevent abuse, and let the account delete its rating. Ratings contain no review text and are not combined with direct Showcase feedback, product analytics, IP addresses, device identifiers, or inferred proof of app use. Public pages and publishers receive only an aggregate after at least five eligible ratings; they do not receive rater identity. Publishers receive a monotonic aggregate-change cursor so their app can refresh without learning who rated it.

Deleting an AirCode Ø account deletes its Marketplace ratings, and deleting a listing deletes its ratings. If a listing is unlisted, suspended, offline, or unavailable because its publisher’s plan lapsed, rating actions and public aggregates are hidden while the records remain retained so restoration does not reset social proof and abuse controls. You may also delete an individual rating while signed in.

An app report requires no account. We retain the public listing identity, an allow-listed reason, the bounded explanation you submit, its review state and timestamps, and an optional contact email only when you choose to provide one. The page returns an opaque receipt number after acceptance. A supplied contact address is protected report evidence used for clarification and decision follow-up; it is not disclosed to the publisher or copied into the moderation event stream. The connection IP and bot-verification token may be processed transiently to prevent abuse but are not retained with the report. Do not put passwords, payment information, private app content or other sensitive data in a report.

Authorized Marketplace operators can review bounded listing, source, donation, seller-readiness and aggregate purchase/support evidence. The moderation projection does not include buyer identity, account email, payment details, identity documents, bank details, raw provider requirements or hosted payment URLs. Reports and audit decisions are retained to handle abuse, appeals, fraud, disputes and legal obligations. The exact financial and trader-retention schedule must be legally approved before live Marketplace purchases open; no automatic deletion of that evidence is currently authorized.

Service providers

Current providers relevant to this policy are:

  • Google Analytics for optional website analytics and required product usage statistics, and Firebase Analytics for required Android product usage statistics;
  • Cloudflare as an infrastructure provider for website delivery, downloads, security, feedback handling and internal analytics;
  • Cloudflare Email Routing and Google Gmail for receiving privacy and support correspondence.

These providers may process data in Switzerland, the European Economic Area, the United States and other countries in which they operate. Where applicable, international transfers rely on recognized adequacy decisions or contractual safeguards.

Your privacy rights

Depending on the law that applies to you, you may request access to, correction or deletion of your personal data, object to or restrict processing, request portability, withdraw website analytics consent for future processing, or object to product analytics where applicable. Withdrawing consent or objecting does not affect the lawfulness of processing performed before the request.

Send requests to privacy@aircodezero.com and describe the right you want to exercise. We may request only the additional information reasonably necessary to verify your identity and protect data from unauthorized disclosure. We respond without undue delay and within the period required by applicable law. You may also complain to the Swiss Federal Data Protection and Information Commissioner or another competent supervisory authority.

Contact

For privacy questions or rights requests, email privacy@aircodezero.com. For general feedback, use the contact form.