This Privacy Policy explains how Spaceboy, Inc. ("Spaceboy," "we," "us," or "our") collects, uses, discloses, retains, and protects information when you use Spaceboy, including our website, dashboard, mobile applications, command-line tools, application programming interfaces, Slack interface, repository integrations, code agents, remote development workspaces, hosted deployments, and related services (collectively, the "Service").
This Privacy Policy is intended to be read together with the Spaceboy User Agreement and any applicable order form, data processing addendum, or enterprise agreement.
1. What Spaceboy Does
Spaceboy is an AI-assisted software development platform. Depending on your configuration, Spaceboy may help users create projects from templates or migrate existing repositories into Spaceboy-managed projects, run AI coding agents in remote development workspaces, interact with agents through the dashboard, CLI, Slack, or mobile app, deploy projects to hosted cloud environments, connect custom domains, send authentication emails for deployed applications, preview Shopify theme projects, build and distribute iOS applications, review code, and coordinate with third-party developer tools.
Because of this functionality, Spaceboy may process information from connected software development systems, including source code, repository metadata, project configuration, Slack messages directed to Spaceboy, prompts, chat messages, commands, logs, generated outputs, integration tokens, deployed application data, and other data needed to operate the Service.
2. Roles: Controller and Processor
For account registration, billing, product telemetry, security monitoring, support, marketing communications, and our own business operations, Spaceboy generally acts as a business or controller of personal information.
For Customer Data that a customer submits to the Service for processing in a project, repository, agent task, integration, workspace, or deployed environment, Spaceboy generally acts as a service provider or processor on behalf of that customer, subject to the User Agreement and any applicable data processing terms. This includes personal information belonging to the end users of applications that customers build and deploy through the Service, such as end-user accounts, authentication data, and application database content. The customer is responsible for determining what Customer Data to submit, which integrations to enable, what permissions to grant, and whether it has a lawful basis to provide personal information to Spaceboy.
3. Information We Collect
3.1 Account and profile information. We collect information such as name, email address, username, optional phone number, avatar, organization name, role, permissions, time zone, app theme, notification preferences, and account settings.
3.2 Authentication information. Platform sign-in is provided through our authentication provider (Supabase). If you sign in with email/password, magic link, Google, Apple, or Microsoft, we may receive identifiers, email addresses, names, profile images, authentication tokens, session metadata, and related information permitted by that provider and your configuration. Passwords are handled by our authentication provider; Spaceboy does not store plaintext passwords.
3.3 Organization and user administration data. We collect organization membership, invitations (including invited email addresses), roles, permissions, billing contacts, audit logs, user activity, and access-control settings.
3.4 Project, repository, and agent data. We may collect and process project names, repository names, repository owners, branches, commits, diffs, pull requests, issues, comments, file paths, file contents, code snippets, documentation, configuration files, dependency files, environment configuration, task descriptions, agent instructions, chat conversations and messages, generated code, generated documentation, plans, summaries, code review comments, and uploaded assets such as images and documents you add to your project library.
3.5 Connected integration data. If you connect GitHub, Slack, Google Cloud, Cursor, Shopify, Apple App Store Connect, or other supported services, we may collect data authorized by the integration, such as access tokens, API keys, installation IDs, organization metadata, repository metadata, channel IDs, messages directed to Spaceboy, Slack user email addresses used to match your Spaceboy account, store domains, project settings, deployment metadata, API responses, logs, and other data needed to perform requested actions. Integration credentials are stored in a dedicated secrets management system.
3.6 Prompts, messages, and commands. We collect prompts, chat messages, CLI commands, Slack commands and mentions, agent instructions, task descriptions, approvals, feedback, and other inputs you provide to the Service. Chat conversations are retained so that agent sessions can be resumed and reviewed.
3.7 Workspace and execution data. When Spaceboy runs agent sessions or deployments, we may collect command output, test results, build and deploy logs, dependency installation logs, error messages, stack traces, runtime telemetry, workspace snapshots used to speed up later sessions, agent session records, artifacts created during tasks, and audit information about agent, deployment, and integration actions.
3.8 Deployed environment and end-user data. If you deploy a project through Spaceboy, we provision and operate hosting, serverless functions, databases, and authentication services for that environment. In doing so we process your application's data on your behalf, which may include your application's end-user accounts, email addresses, authentication events, database contents, queries you run through the SQL console, and authentication emails (such as sign-in links and password resets) sent to your end users through our email delivery provider. We process this data as your service provider; you are the controller of your application's end-user data.
3.9 Custom domain and email sender data. If you connect a custom domain or configure a sender domain for authentication emails, we collect hostnames, DNS verification records, and certificate metadata needed to provision and operate those features.
3.10 Billing and transaction information. Payments are processed by our payment processor (Stripe). We and Stripe may collect billing contact information, payment method metadata, subscription plan, usage credit balances and ledger entries, invoices, tax information, transaction records, and payment status. If you enable automatic top-ups, a reference to your saved payment method is retained so it can be charged as you have authorized. Spaceboy does not store full payment card numbers.
3.11 Support and communications. We collect information you provide when contacting support, responding to surveys, requesting demos, joining waitlists, submitting feedback, or communicating with us.
3.12 Device, usage, and log information. We collect IP address, device identifiers, browser type, operating system, app version, CLI version, features used, time stamps, error logs, diagnostic data, and security logs. API keys you create are stored only in hashed form.
3.13 Cookies and similar technologies. We use cookies and browser storage for authentication, session management, and remembering your preferences (such as theme and layout settings). We do not currently use third-party advertising pixels or third-party product analytics services in the web app. Some pages load resources from third parties, such as web fonts served by Google Fonts and checkout pages hosted by Stripe; those providers may receive standard request data such as your IP address when the resource loads.
4. How We Use Information
We use information to:
- provide, operate, secure, maintain, and improve the Service;
- authenticate users and manage sessions;
- create and manage accounts, organizations, roles, and permissions;
- connect, operate, and maintain integrations;
- clone, inspect, and process repositories as authorized;
- run agents, remote workspaces, tests, commands, builds, code reviews, and development workflows;
- generate code, diffs, comments, documentation, summaries, pull requests, and recommendations;
- provision, deploy, and operate hosted environments, databases, authentication services, custom domains, and email sender domains where authorized;
- send authentication and transactional emails to your application's end users on your behalf;
- provide support, debugging, incident response, and customer success;
- monitor security, prevent abuse, enforce terms, and protect the Service;
- process payments, subscriptions, usage credits, automatic top-ups, taxes, and usage limits;
- personalize settings such as app theme, time zone, dashboard preferences, and notifications;
- analyze usage, diagnose errors, and improve reliability and performance;
- communicate about the Service, including updates, security notices, support messages, and administrative notices;
- develop new features, subject to commitments regarding Customer Data and model training described below;
- comply with law, enforce agreements, and protect rights; and
- perform other purposes disclosed at the time of collection or with your consent.
5. AI and Model Providers
Spaceboy uses AI systems to perform agent tasks, reason about code, generate outputs, summarize context, and support automation. Agent sessions are powered by Cursor's agent platform: to run an agent task, Spaceboy sends relevant prompts, code, repository context, logs, and metadata to Cursor, which in turn uses underlying AI model providers to generate responses. Spaceboy also uses OpenAI for limited features, such as translating natural-language questions into database queries in the SQL console and drafting authentication email templates. If you connect your own Cursor API key, agent runs are processed under your own Cursor account and Cursor's terms apply directly to you.
Unless otherwise stated in an order form or data processing terms, Spaceboy uses AI providers to process Customer Data solely for the purpose of providing the Service. We do not sell Customer Data to AI providers. We do not permit AI providers to use Customer Data to train their models except where you have expressly enabled that use, where a provider's terms independently apply to your own direct account with that provider, or where otherwise disclosed in writing.
You are responsible for deciding what information to submit to AI features and for configuring repository, project, and integration permissions appropriately. Do not submit regulated or highly sensitive personal information unless your agreement with Spaceboy expressly permits it.
6. How We Disclose Information
We may disclose information to:
6.1 Service providers and subprocessors. We use vendors to operate the Service, currently including Google Cloud and Firebase (hosting, compute, databases, storage, secrets management, and logging), Supabase (platform authentication), Stripe (payments), Cursor (agent execution), OpenAI (limited AI features), Resend (email delivery), Slack (when you connect the Slack app), GitHub (repository hosting), and Apple App Store Connect (iOS build distribution, using credentials you provide). The list of vendors may change as the Service evolves.
6.2 Integration providers. When you connect or use integrations, we disclose information as needed to operate those integrations, such as pushing commits and opening pull requests on GitHub, posting messages to Slack, running theme previews against your Shopify store, provisioning Google Cloud resources, uploading builds to App Store Connect, calling AI provider APIs, or processing payments through Stripe.
6.3 Organization administrators. If you use Spaceboy through an organization account, administrators and authorized users may access project content, user activity, integrations, billing data, usage history, audit logs, agent tasks, and settings for that organization.
6.4 Your authorized users and collaborators. We disclose information to other users you invite to projects, repositories, channels, agents, or organizations according to your permissions and settings.
6.5 Legal and safety purposes. We may disclose information if we believe disclosure is required by law, legal process, or government request; to enforce our agreements; to protect rights, privacy, safety, or security; to investigate fraud or abuse; or to respond to security incidents.
6.6 Business transfers. We may disclose information in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction.
6.7 Professional advisors. We may disclose information to lawyers, auditors, insurers, bankers, and other advisors under confidentiality obligations.
6.8 With consent. We may disclose information as you direct or with your consent.
7. Selling or Sharing Personal Information
Spaceboy does not sell Customer Data. Spaceboy does not sell personal information in the ordinary meaning of that term. We do not share personal information for cross-context behavioral advertising. If we ever adopt analytics or advertising technologies that would be considered a "sale" or "sharing" under certain privacy laws, we will update this Privacy Policy and provide any legally required notices and opt-out mechanisms first.
8. Data Retention
We retain information for as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business purposes.
Retention periods vary by data type and configuration. As a general framework:
- account and organization data is retained while the account is active and for a reasonable period after closure;
- project, repository, and chat data is retained while the project is active, until deleted by the customer, or as specified in an order form;
- integration tokens and credentials are retained in secrets management while the integration is enabled and are deleted or invalidated when access is revoked;
- workspace snapshots, agent session records, deploy logs, and caches are retained for performance, continuity, debugging, audit, and security for a limited period;
- deployed environment data, including provisioned databases and authentication data, is retained while the environment exists and is removed when the environment is torn down, subject to backup cycles;
- usage ledger, billing, tax, and transaction records are retained as required by law; and
- security and audit logs may be retained for incident response and abuse prevention.
Enterprise customers may request different retention settings where supported.
9. Security
We use reasonable technical and organizational safeguards designed to protect information. These include encryption in transit, encryption at rest, access controls, role-based permissions, storage of integration credentials and secrets in a dedicated secrets management system, hashed storage of API keys, isolated workspace environments, per-environment separation of deployed customer resources, logging, monitoring, audit trails, least-privilege practices, and vendor review.
No method of transmission or storage is completely secure. You are responsible for securing your own accounts, devices, repositories, branches, package registries, cloud services, identity providers, and credentials; limiting integration scopes; configuring least-privilege access; monitoring agent activity; and rotating credentials when needed.
10. Your Choices and Controls
You may be able to:
- access, correct, or update account information;
- change organization roles and permissions;
- configure project settings, agent permissions, and approval flows;
- connect or revoke integrations;
- delete projects, chats, deployed environments, uploaded assets, or other Customer Data where supported;
- export certain Customer Data, including by retaining full access to your source code on GitHub;
- manage notification preferences;
- control cookies through browser settings;
- request access, correction, deletion, portability, restriction, or objection where applicable; and
- opt out of marketing emails by using unsubscribe links or contacting us.
Some requests may be limited by law, security, backup retention, contractual obligations, or our role as a processor for a customer.
11. Privacy Rights
Depending on your location and relationship with Spaceboy, you may have rights to know, access, correct, delete, port, restrict, object to, or appeal certain processing of personal information. You may also have the right to opt out of certain selling, sharing, targeted advertising, or profiling if applicable.
To exercise rights, contact us at privacy@spaceboy.ai. We may need to verify your identity and authority. If your information is processed as Customer Data for one of our customers — for example, if you are an end user of an application a customer built and deployed through Spaceboy — we may direct your request to that customer or assist the customer in responding.
12. International Transfers
Spaceboy may process and store information in the United States and other countries where we or our service providers operate. These countries may have privacy laws that differ from those in your location. Where required, we use appropriate safeguards for international transfers, such as contractual commitments or other legally recognized mechanisms.
13. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us and we will take appropriate steps. Customers must not use the Service to process children's personal information unless expressly permitted by a written agreement and applicable law.
14. Sensitive and Regulated Data
Unless expressly permitted by a written agreement with Spaceboy, you must not submit protected health information, payment card data, government identifiers, biometric data, children's data, export-controlled technical data, highly sensitive personal information, or other regulated data to the Service, including to databases and applications you deploy through the Service. If you need to process regulated data, contact us before doing so.
15. Third-Party Services and Links
The Service may link to or integrate with third-party services, including services you connect (such as GitHub, Slack, Shopify, Google Cloud, Cursor, and Apple) and services we use to deliver features (such as Stripe checkout). We are not responsible for the privacy or security practices of third-party services. Your use of those services is governed by their own terms and privacy policies.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by posting the updated policy, sending email, or using in-product notice. The updated policy becomes effective on the stated effective date. Continued use of the Service after the effective date means you acknowledge the updated policy.
17. Contact
Spaceboy, Inc.
272 Citrus Drive, Summerville SC 29486
Email: privacy@spaceboy.ai
Security: security@spaceboy.ai
Legal: legal@spaceboy.ai
18. U.S. State Privacy Notice
This section applies to residents of states with comprehensive privacy laws, to the extent those laws apply to Spaceboy.
Categories of personal information we may collect include identifiers; account credentials; commercial information; internet or network activity; geolocation derived from IP address; professional or employment-related information provided through business accounts; inferences related to product usage; and sensitive personal information such as account credentials, access tokens, or private repository content only if you provide or authorize it.
Sources include you, your organization, your devices, connected integrations, identity providers, payment processors, and service providers.
Purposes include providing the Service, account administration, integrations, security, debugging, billing, support, product improvement, legal compliance, and other purposes described in this Privacy Policy.
Categories of recipients include service providers, subprocessors, integration providers, organization administrators, authorized collaborators, professional advisors, legal authorities where required, and business transfer recipients.
We do not knowingly sell personal information of consumers under 16. We do not use sensitive personal information for purposes that require a right to limit under California law unless we provide the required notice and choice.
19. European Privacy Notice
If European privacy laws apply, the legal bases for our processing may include performance of a contract, legitimate interests, consent, legal obligations, and, where applicable, the customer's instructions as controller. Legitimate interests may include providing and securing the Service, preventing abuse, improving products, communicating with users, and supporting business operations.
European users may have rights to access, correct, delete, restrict, object, port data, withdraw consent, and lodge a complaint with a supervisory authority. To exercise rights, contact privacy@spaceboy.ai.