Builds · Legal
Privacy Policy
Builds (builds.one, app.builds.one, the Builds apps and the builds software)
Builds lets you drive coding agents on your own machines from your phone, the web or a terminal. The design choice that shapes this page: your code, your conversations and your AI credentials stay on your own machines. Our server, app.builds.one, connects your devices to your machines and keeps what it needs to do that. This page says exactly what that is.
1 · Who is responsible
The controller of your personal data is:
| Company | Digital One Technology Consulting Limited |
|---|---|
| Registered office | 6-9 Trinity Street, Dublin 2, D02 EY47, Ireland |
| Company number | 793205 (Companies Registration Office, Ireland) |
| Privacy contact | info@digital1.one |
| Post | Digital One Technology Consulting Limited, 6-9 Trinity Street, Dublin 2, D02 EY47, Ireland |
Builds is a Digital One product. There is no separate Builds company. The company is Irish, with people in Dublin and Budapest. The GDPR and Ireland's Data Protection Act 2018 apply.
Data Protection Officer. We have not appointed one: the GDPR requires one only for large-scale monitoring or large-scale special-category data (Art. 37), and Builds does neither. Write to info@digital1.one and a person who can answer reads it.
Teams. If your organisation uses Builds, for the organisation's own data (what its members do on the organisation's machines, its keys, its knowledge) the organisation decides and we act for it. See §9.
2 · The short version
- We never receive your AI credentials. You sign in to Claude, ChatGPT/Codex, Grok and the rest on your own machine, with the vendor's own tool. API keys are stored on that machine, encrypted; one you type in the app is sealed to that machine on your phone, and our server cannot open it.
- We do not store your conversations. They live on your machine. While you watch one from the app, it passes through app.builds.one on its way to you and is not written to our disk. Section 4 lists the small exceptions (a notification's first words, a document's title, your own instructions).
- Your prompts and code go from your machine straight to the AI vendor you chose, under your account and that vendor's terms. We are not in that path (except for a team's own key, §9).
- We keep: who you are (Digital One account id and email), your devices and machines, your settings, and counts of use.
- Crash reports and usage counts go to PostHog in the EU only if you say yes. They never carry a message's words, a file's name or a path.
- We do not sell data, show ads, or train any model on your data.
Your right to object. Where we rely on our legitimate interests (§4 names each one: for example security logs, spending caps, and invitations before they are accepted), you may object at any time, on grounds relating to your situation, by writing to info@digital1.one. We then stop unless we have compelling legitimate grounds that override yours, or need the data for a legal claim. (GDPR Art. 21; shown here separately, as Art. 21(4) requires.)
3 · Where your data lives
| Place | What is there | Who controls it |
|---|---|---|
| Your machines (your Mac, your Linux server, a DispatChai residence, an organisation's machine) | Your code, your conversations (~/.builds/sessions), checkpoints, your AI vendors' sign-ins in their own folders, your API keys (encrypted at rest) | You (or, on an organisation's machine, its administrator — §9). We keep no copy of it; see the note under this table. A DispatChai residence is run by DispatChai (also Digital One): its own privacy policy says who can reach it |
| app.builds.one (our server, Hostinger, Frankfurt, Germany) | Your account, devices, machines, settings and usage — §4 | Us |
| Your phone, browser or computer (the Builds app) | Your sign-in, your settings, and a copy of the conversations you recently opened, so they open fast | You. Deleting the app, or clearing the site's data in your browser, removes it. Signing out does not remove the conversation copies yet: on a shared computer, clear the site's data after you sign out. See Cookies and local storage |
| The AI vendors you use | What your agents send them | You and the vendor, under your agreement with them (§7) |
Said plainly: our server can reach your linked machines. A machine you link to your account does what comes over that link from your account (start a turn, answer a question, make a desk). We use that path only to carry what you do in the app, and we never read your machine's files on our own initiative. But the possibility exists, so we say it, and the security page says how we guard it. To close it for a machine, unlink it; Builds keeps working there from the terminal.
4 · What we process, why, on what basis, and for how long
The bases are Article 6(1) GDPR: (b) to provide the service you asked for (our contract with you), (c) a legal obligation, (f) our legitimate interests (named in the row), (a) your consent.
| What | The data | Why | Basis | How long |
|---|---|---|---|---|
| Your account | Your Digital One account id (sub) and email address, from Digital One's sign-in; when you first signed in | To know who you are and whose machines are whose | (b) | Until you delete your account (§11) |
| Signing in on a device | Each app you signed in on: its name (for example "Anna's iPhone"), platform, first and last seen; only a hash of the device's sign-in token. The web app uses a sign-in cookie | To keep you signed in and let you sign a device out from Settings | (b) | Up to 20 devices; the longest unseen is forgotten first. A token lasts 30 days (app) or 7 days (web) unless renewed by use |
| Your machines | Each machine you pair: its name, host name, platform, Builds version, what hardware it reports, when it was last seen, a hash of its credential; its last report of its desks (desk name, repository name and branch, engine); a short history of changes (renamed, desk made or removed: when, from which app or device) | To show your machines and desks, even while a machine is offline, and to route your commands to the right one | (b) | Until you remove the machine. A removed machine's record (what was removed, when and by whom) is kept 12 months after the removal, so you can see it, then deleted |
| Accounts on your machines | Which AI accounts are signed in on each machine, as the machine reports them (for example the email a Claude plan is under), and whether each sign-in still works. Never the credential | To show you which plans a desk can use and warn you when a sign-in expires | (b) | While the machine reports them |
| Signing a machine in to an AI vendor from the app | The one-time code you paste from the vendor's page | To pass it to your machine, which completes the sign-in | (b) | Not kept: it passes through once and is never logged |
| An API key you add from the app | Only a sealed envelope that your machine alone can open; the key's provider, a fingerprint and the spending caps you set | To install the key on your machine without our server ever seeing it | (b) | The envelope is not kept; the machine keeps the key, encrypted |
| Your settings | Accent colour, how new conversations start (mode, effort), notification choices, quiet hours and time zone, desk-health checks you chose to ignore | To apply them on all your devices | (b) | Until you change them or delete your account |
| Your instructions | The "About me" and "How to answer" texts you write in Settings, and a history of their last 30 changes (when, from which app, how long each text became — never the words of old versions) | Your machines use them as the standing instructions of your conversations | (b) | Until you change them or delete your account |
| Where you are in each conversation | When you last acted in, opened and read each conversation, unread counts, which questions you were already told about, the documents an answer marked for you (the document's path and title, and when you opened it) | So every device shows the same unread state and nothing buzzes twice | (b) | Until you delete your account; document marks: the last 30 per conversation |
| Notifications | Your devices' push tokens (Apple, and Google for the Android preview) and web push subscriptions (with the browser's name) | To tell you when a desk asks something, a machine goes offline, a plan nears its limit, or a document is ready | (b), and your device's own permission | Until you sign out, switch notifications off, or the token stops working |
| Notification text | A notification shows a few words: the desk's name and the first words of its question, plan or result | So you can decide from the lock screen | (b) | We do not keep it. Apple, Google or your browser's push service delivers it (§6) |
| Conversations in transit | Your messages, the agents' answers, files and images you attach, while they travel between your devices and your machines | That is the service | (b) | Not stored by us. Held in memory only while it is passing, compressed on the wire |
| Linked Digital One products | If you link DispatChai: its sign-in for you, encrypted with our server's key. If FrontierScore's card is on: your own FrontierScore key, encrypted the same way | To show and manage your DispatChai residences, and FrontierScore's model scores | (b) | Until you unlink, or delete your account |
| Usage and limits | Per conversation and per day: provider, model, tokens, and cost where money is involved; for DispatChai desks, tokens per day and model, and how each desk is signed in | Your Usage page, and the spending caps (plan use is shown as tokens, money as money) | (b); (f) keeping spending within the caps | Detail for 35 days, then one total per day, kept 24 months. All of it is deleted with your account. DispatChai desk figures: dropped 45 days after a desk was last heard from |
| Status history | Every 5 minutes, whether each of your machines and accounts was up, and the machines' load (two hours of it) | The status sheet in the app | (b) | One day |
| Invitations | If someone invites you: your email address, who invited you, their note, what was offered (the size and length of a free DispatChai residence), the state of the invitation, and who accepted it and when. The link itself is stored only as a one-way hash plus an encrypted copy for the sender | To send the invitation, let you accept it, and set up the free residence. Your address came from the person who invited you; the invitation email links to this policy | (b); for the invited person before they accept: (f) delivering an invitation someone chose to send them | 12 months after the invitation ends (accepted, expired or ended), and each line of the invitation log 12 months after it was written. If you delete your account: invitations you sent that nobody took up are deleted; one that was taken up stays for the person who took it, without your account id or address; on one you took up, the address you accepted with is removed, and the sender keeps the address they sent it to as their record |
| Organisations | Your memberships and roles (the Digital One suite holds them; we keep a copy); a log of organisation events (machine linked, space made or removed, key or cap changed — and who did it) | To run organisations (§9) | (b); for the log: (f) letting the organisation's owners see who changed what | The copy is refreshed every few minutes. Each line of the log is kept 12 months after the event, also after you delete your account: it is the organisation's record, and it names you by account id, not by email |
| Crash reports and usage counts | See §5 | To find crashes and see which screens are used | (a) your consent | For the period PostHog's paid plan, which we use, keeps events: 7 years (PostHog: "Events data retention") |
| Security and abuse | Pairing attempts by network address (to lock out guessing), server request logs (address, time, page, browser) | To keep the service and your machines safe | (f) security | Pairing locks: in memory, gone at a restart. Request logs: 14 days (the web server's logs; the server's system log, at most 7 days). What the server program itself prints is kept until the program is next updated |
| Support and messages | What you write to us | To answer you | (b); (f) | 2 years after your last message |
| Backups | A copy of everything in this table that is on app.builds.one | To recover from a failure | (f) not losing your setup | Daily, encrypted, on the server; each backup is kept 7 days |
What we do not have. Your code, your files, your conversation history, your AI credentials or API keys, your payment details. Builds itself has no payment: a DispatChai residence is paid through DispatChai, under DispatChai's own terms and privacy policy.
Do you have to give us this? Your Digital One account id and email are needed to use Builds: we cannot tell your machines apart from anyone else's without them. Everything else is created by using the product. Crash reports and usage counts are optional: we ask first, and saying no changes nothing else.
Automated decisions. We make none that have legal or similarly significant effects on you. Some checks are automatic: a pairing code typed wrong too often locks for 15 minutes; a spending cap stops a turn; an invitation is refused over a daily limit. Write to us and a person looks.
5 · Crash reports and usage counts
The app (iPhone, iPad, Android preview, web) can send crash reports and usage counts to PostHog, in PostHog's EU region (Frankfurt, Germany). It asks you first, on each device. Until you say yes, it sends nothing to PostHog and keeps no PostHog id on your device. Saying no changes nothing else in the app.
What goes, if you said yes: a random id made on your device (not your account), the app's version and platform, the screens you open by their shape (/s/:id, never the conversation's id or name), the app's start and stop, errors and crash reports with the program's own stack (component and file names of our code). On the web it goes through app.builds.one, which passes on your network address as a direct call would; PostHog discards it (our project's "Discard client IP data" setting is on).
What never goes: a message's words, a file's name, a path, a machine's or desk's name, your email, your account id. We do not create a profile of you in PostHog and we do not link its events to your account.
Changing your mind: Settings → This device → Share crash reports and usage counts. It is off until you say yes, and you can switch it off, or on again, at any time. Switching it off stops anything more being sent and removes PostHog's id from the device.
6 · Who else receives data
We keep the list short, and every recipient is named on the sub-processor list with what it gets and where.
| Recipient | What | Where | Role |
|---|---|---|---|
| Hostinger International Ltd (Cyprus) | Runs the server app.builds.one is on, so everything in §4 that is on the server | Frankfurt, Germany | Our processor |
Digital One ID (our own sign-in, at ai.digital1.one, api.digital1.one and id.digital1.one), behind Cloudflare, Inc. | Your sign-in: with a code sent to your email, or with Google, GitHub, Microsoft or Apple, and if you choose one of those, that company also takes part, under its own terms. The sign-in page counts its own use with PostHog (EU) only if you say yes to its own question (Analytics settings on that page changes the answer), and then links it to your Digital One account once you are signed in. It serves its fonts from its own server | EU; Cloudflare is a US company | Ours; Cloudflare is our processor |
| PostHog Inc. | Crash reports and usage counts (§5), only if you said yes | Frankfurt, Germany (EU region) | Our processor |
| Resend, Inc. | Invitation emails: the invited address, the sender's name and address, the note and the link | United States (Resend stores sent mail and logs for 30 days) | Our processor |
| Apple (Apple Push Notification service) | Your iPhone's or iPad's push token and the notification's words | Apple's systems | Delivers notifications |
| Google (Firebase Cloud Messaging, Android preview only) | Your Android device's push token and the notification's words | Google's systems | Delivers notifications |
| Your browser's push service (Apple, Google, Mozilla or Microsoft, depending on the browser) | A web push subscription and an encrypted notification it cannot read | Their systems | Delivers notifications |
| DispatChai (also Digital One) | If you link it, or accept a free residence: your account id, email and whether it is verified, the invitation and the residence's size and end date | EU | Same company; DispatChai's own privacy policy covers the residence |
| FrontierScore, Gateward, SkilledMind (also Digital One) | Only if you use them: FrontierScore's card (your FrontierScore key); a team's Gateward key and SkilledMind knowledge (§9) | EU | Same company |
| The AI vendors you use | Not from us: from your machine, directly (§7) | Mostly the United States | Your choice, your agreement |
We disclose personal data to anyone else only when the law requires it (a valid order from a court or authority), or to establish or defend a legal claim.
Transfers outside the EEA. Two of our processors are US companies that handle data outside the EU: Resend (stores invitation mail in the US) and Cloudflare (in front of the sign-in). Both are certified under the EU–US Data Privacy Framework, which the European Commission found adequate on 10 July 2023 (Decision (EU) 2023/1795); their contracts with us also include the Commission's Standard Contractual Clauses. PostHog's EU region keeps the data in the EU, and PostHog's contract with us includes the Standard Contractual Clauses for any access from the US. Write to us for a copy of the safeguards.
7 · The AI vendors: what leaves your machine
When an agent works, your machine sends your prompt and the code it reads to the vendor that runs the model: Anthropic (Claude), OpenAI (Codex), xAI (Grok), Google, Mistral, or whoever you pick. That is what a coding agent is.
- You sign in on your machine with the vendor's own tool (
claude,codex,grok) or add your own API key. Builds uses a subscription only through the vendor's official tool. - The vendor is not our processor. It processes your data under your agreement with it, as a controller in its own right (or as your processor, on a business or API plan). Its terms decide retention and whether your data trains its models. Read them; some let you switch training off.
- We are not affiliated with those vendors, and we do not see what passes between your machine and them.
- If your code contains other people's personal data, sending it to a vendor is your processing decision.
Where each vendor says what it keeps and whether it trains on it (as read on 2026-10-04; check them, they change):
| Vendor | Plans (signed in with the vendor's tool) | API keys |
|---|---|---|
| Anthropic (Claude) | Free, Pro and Max: used for training if your "help improve Claude" setting is on (kept up to 5 years), not if it is off (30 days). anthropic.com/legal/consumer-terms · code.claude.com/docs/en/data-usage | Not used for training; 30 days. anthropic.com/legal/commercial-terms |
| OpenAI (Codex) | ChatGPT Plus and Pro: may be used to improve models unless you turn it off in ChatGPT's data controls; Business: not by default. help.openai.com | Not used to improve the services unless you agree. openai.com/policies |
| xAI (Grok) | You choose in your xAI account whether your content trains its models. x.ai/legal/terms-of-service | Not used to train foundation models. x.ai/legal/terms-of-service-enterprise |
| Google (Gemini) | — | In the EEA, the paid-service terms apply to all use. ai.google.dev/gemini-api/terms |
8 · How long, in one place
The "How long" column of §4 is the rule. In short: most of it while you have an account, plus at most 7 days in our backups after you delete it. A few things follow their own clock, and §4 says which: usage totals (24 months, and gone with your account), the records of removed machines, invitations and organisation events (12 months after the event, with your address removed when you delete your account), invitation emails at Resend (30 days), and your messages to us (2 years after the last one). What we must keep by law (for example a record of a legal request) is kept as long as that law says.
9 · Teams (organisations)
- An organisation is created in Builds and kept in Digital One's suite, which Gateward and SkilledMind share.
- On an organisation's machine, each member gets a separate space (a separate Unix user). Other members cannot read it. The machine's administrator can: whoever runs a machine can read everything on it. The app says so, with the administrator's address, before you make your space.
- An organisation's key (through Gateward, a Digital One product): a desk you put on it sends its prompts through Gateward to the model vendor under the organisation's account, and Gateward records the use and cost for the organisation's caps.
- An organisation's knowledge (SkilledMind, a Digital One product): if the organisation turned it on, a desk can read the organisation's shared knowledge, and, where its "learn" switch is on, send a summary of a finished conversation into it, where the organisation's members can find it.
- For these, the organisation decides and we act on its behalf, under a data processing agreement we offer every organisation (Terms §12). Its own policies apply to you as a member; ask its administrator.
- The organisation's owners and admins see the members, their roles, the seats (whose, state, number of desks) and the log of organisation events. They do not see your conversations.
10 · Your rights
You have the right to:
- access your data and get a copy;
- correct it;
- delete it (§11 says how, from the app);
- restrict our processing while a question is settled;
- portability: the data you gave us, in a machine-readable file;
- object to processing based on our legitimate interests, and to any direct marketing (we send none);
- withdraw consent at any time where we rely on it (crash reports and usage counts: Settings → This device → Share crash reports and usage counts; the sign-in page's own analytics: Analytics settings on that page), without affecting what was done before.
How: write to info@digital1.one from your account's address, or use the app (Settings → Delete account). We answer within one month (two more for a complex request, and we tell you why). It is free. We may ask you to confirm it is you; signing in is usually enough.
Complaints. Tell us first, please. You can also complain to a data protection authority:
- Ireland (our lead authority): Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, Ireland · +353 1 765 0100 · complaints in writing at forms.dataprotection.ie/contact · www.dataprotection.ie
- Hungary: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9-11 (post: 1363 Budapest, Pf. 9.) · +36 1 391 1400 · ugyfelszolgalat@naih.hu · cases are started at naih.hu/online-ugyinditas, not by email · www.naih.hu
- or the authority where you live or work, or where you think the breach happened (Art. 77 GDPR).
You may also go to court (Art. 79 GDPR): in Ireland, or in the country where you live (in Hungary, the regional court — törvényszék — for where you live).
11 · Deleting your account
From the app: Settings → Delete account. The full description of what is removed and what stays is on the account deletion page. In short:
- your Builds account, and what §4 lists about you, goes from app.builds.one at once, and every device is signed out; the records other people keep stay as theirs (an invitation someone sent you keeps the address they sent it to; an organisation's log names your account id, not your email) until each is deleted 12 months after the event;
- backups age out within 7 days;
- your machines keep their own data, which only you can remove;
- a free DispatChai residence you got by invitation ends: it is stopped, kept 7 days, then removed; a paid one is closed in DispatChai;
- if you are the only owner of an organisation, or you linked an organisation's machine that other people work on, the app asks you to hand it over first;
- your Digital One account stays. It is the sign-in Digital One's other products share. Delete it at digital1.one, or write to info@digital1.one.
12 · Security
The server holds no AI credential. Secrets it must hold (a linked DispatChai sign-in, a FrontierScore key) are encrypted with a key kept outside the data. Device tokens and machine credentials are kept only as hashes. Risky actions ask for Face ID or a second press. Everything travels over TLS. More on the security page, and how to report a weakness.
If a breach puts your rights at risk, we tell the Data Protection Commission within 72 hours and you without undue delay where the risk to you is high.
13 · Children
Builds is not for children. You must be at least 18 to use it. We do not knowingly collect data from anyone younger; if you think we have, tell us and we delete it.
14 · Changes
When we change this policy, we update this page and its date. If a change matters to how your data is used, we tell you in the app or by email before it takes effect. Earlier versions are available on request.
15 · Contact
info@digital1.one · Digital One Technology Consulting Limited, 6-9 Trinity Street, Dublin 2, D02 EY47, Ireland.
Last updated