Privacy Policy
Effective 10 August 2026. Version 1.0.
This Privacy Policy describes how DELG Software, S.A.S DE C.V. (“DELG Software”, “we”, “us”, the “controller”) collects, uses, discloses and retains personal data in connection with the DELG Code web application, desktop IDE and command-line interface (together, the “Service”). It applies to all users of the Service. Capitalised terms have the meanings given in clause 3.
1.Identity and domicile of the controller
1.1The controller responsible for the processing of personal data described in this Policy is DELG Software, S.A.S DE C.V., a company incorporated under the laws of the United Mexican States, having its principal place of business in the State of Nuevo León, United Mexican States.
1.2The domicile of the controller for the purposes of this Policy is Nuevo León, México.
1.3Communications concerning this Policy, and requests made under clause 11, may be addressed to [email protected].
1.4This Policy applies to the DELG Code web application, the DELG Code desktop IDE and the DELG Code command-line interface. It does not apply to third-party services that a user elects to connect to the Service, which are governed by their own privacy notices.
2.Applicable law
2.1The controller is established in Mexico and processes personal data in accordance with the Ley Federal de Protección de Datos Personales en Posesión de los Particulares and its implementing regulations (together, the "Federal Law"). The authority competent to supervise compliance with the Federal Law is the Secretaría Anticorrupción y Buen Gobierno (SABG).
2.2The Service is offered internationally. Where the controller offers the Service to data subjects in the European Economic Area or the United Kingdom, the General Data Protection Regulation and the United Kingdom General Data Protection Regulation respectively apply to that processing by virtue of their extraterritorial scope.
2.3This Policy is intended to satisfy the requirements of each of the instruments referred to in clauses 2.1 and 2.2. Where those instruments confer different or additional rights, the provision most favourable to the data subject applies.
3.Definitions
In this Policy:
- "Account Data": means the identifiers and attributes associated with a user account, including email address, authentication subject identifier, plan and credit balance.
- "Diagnostics": means the optional error and usage information described in clause 6.
- "Repository Content": means source code and related files obtained from a repository a user connects to the Service.
- "Session Data": means the instructions submitted by a user to an agent session and the responses generated in that session.
- "Sub-processor": means a third party engaged by us to process personal data on our behalf.
4.Categories of personal data processed
We process the following categories of personal data:
- Account Data: collected when a user registers for or signs in to the Service.
- Session Data: submitted by the user and generated by the Service during an agent session.
- Repository Content: obtained, at the user's direction, from repositories the user has authorised the Service to access.
- Transaction data: records of credit consumption and plan entitlement.
- Technical data: internet protocol address, request metadata and server logs generated when the Service is accessed.
- Diagnostics: processed only where the user has given consent in accordance with clause 6.
5.Purposes and legal bases
We process personal data for the following purposes and on the following legal bases under Article 6(1) of the General Data Protection Regulation and equivalent provisions of applicable law:
- Provision of the Service: to authenticate users, execute agent sessions, access authorised repositories and create pull requests. Legal basis: performance of a contract, Article 6(1)(b).
- Billing and account administration: to apply plan entitlements, meter credit consumption and maintain accounting records. Legal basis: performance of a contract, Article 6(1)(b), and compliance with a legal obligation, Article 6(1)(c).
- Security and abuse prevention: to detect, investigate and prevent unauthorised access, abuse and interference with the Service. Legal basis: legitimate interests, Article 6(1)(f), being our interest in maintaining the security and availability of the Service.
- Diagnostics: to identify and correct defects and to assess how features of the Service are used. Legal basis: consent, Article 6(1)(a).
5.2Where processing is based on consent, that consent may be withdrawn at any time in accordance with clause 6.5. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5.3We do not sell personal data, and we do not disclose personal data to third parties for advertising or profiling purposes.
6.Optional diagnostics from the desktop IDE
6.1The desktop IDE is capable of transmitting Diagnostics to us. This function is disabled by default and transmits nothing unless the user enables it under Settings → Privacy. It remains disabled for users who are not signed in to an account.
Where enabled, Diagnostics comprise:
- Error information: the type, message and stack trace of an error occurring in the application. File paths within stack traces are reduced to a file name before transmission.
- Usage information: counts and fixed labels recording which features are invoked, including panels opened, commands executed, and whether an agent session completed or was interrupted.
- Environment information: the application version, operating system and processor architecture.
Diagnostics are designed to exclude, and the application removes before transmission, the following:
- File contents: source code, diffs, clipboard contents and terminal output.
- Session Data: instructions submitted to an agent and the responses generated.
- Identifying names: file paths, directory names, repository names, branch names and operating system user names.
- Credentials: access tokens, application programming interface keys and passwords.
6.4The exclusions in clause 6.3 are applied by the application before transmission and applied again by our servers on receipt. We do not rely on the application alone to enforce them.
6.5Consent may be withdrawn at any time by disabling the function under Settings → Privacy. Diagnostics already received may be erased by the user at any time using the deletion function provided in the same location, or by request under clause 11.
7.Disclosure and sub-processors
We disclose personal data to the following categories of recipient, in each case only to the extent necessary for the purposes set out in clause 5:
- Infrastructure providers: which host our application, database and sandbox environments.
- Model providers: which receive the instructions and file contents necessary to generate a response to a request initiated by the user. Data transmitted for this purpose is not used by those providers to train models.
- Source control providers: accessed on the user's behalf and within the permissions the user has granted, in order to read repositories and open pull requests.
- Payment and identity providers: which administer authentication and billing.
7.2We may disclose personal data where required to do so by law, or where necessary to establish, exercise or defend legal claims.
7.3Sub-processors are engaged under written terms imposing obligations of confidentiality and data protection no less protective than those set out in this Policy.
8.International transfers
8.1The Service is offered internationally. Personal data may be processed in, or transferred to, jurisdictions other than the jurisdiction in which the user is located.
8.2Where personal data is transferred out of the European Economic Area or the United Kingdom, we engage providers that offer appropriate contractual and technical safeguards in respect of that transfer.
9.Retention
We retain personal data for no longer than is necessary for the purposes for which it was collected, as follows:
- Diagnostics: erased automatically 90 days after receipt.
- Session Data: retained until the user deletes the session or the associated account.
- Repository Content: held in an isolated sandbox for the duration of a session and destroyed when that session ends.
- Account Data: retained for the duration of the account and deleted following its closure, subject to clause 9.2.
- Transaction data: retained for the period required by applicable accounting and tax law.
9.2We may retain personal data beyond the periods stated in clause 9.1 where retention is required by law or is necessary to establish, exercise or defend legal claims.
10.Security
10.1We implement technical and organisational measures appropriate to the risk, including encryption of data in transit, isolation of session workspaces, access controls over production systems and the credential-removal measures described in clause 6.4.
10.2No method of transmission or storage is entirely secure, and we do not warrant absolute security. Users are responsible for maintaining the confidentiality of their account credentials and any access tokens they supply to the Service.
11.Rights of data subjects
Under the Federal Law, a data subject may exercise the rights known collectively as ARCO rights:
- Acceso (Access): to know what personal data the controller holds concerning them and the terms on which it is processed.
- Rectificación (Rectification): to obtain the correction of personal data that is inaccurate or incomplete.
- Cancelación (Cancellation): to obtain the deletion of personal data where it is no longer required for the purposes for which it was collected.
- Oposición (Objection): to object to the processing of personal data for a particular purpose where there are legitimate grounds to do so.
Where the General Data Protection Regulation or the United Kingdom General Data Protection Regulation applies to the processing, the data subject may in addition exercise the following rights:
- Restriction of processing: to obtain the restriction of processing in the circumstances specified by those instruments.
- Portability: to receive personal data provided to the controller in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
- Withdrawal of consent: to withdraw consent to processing carried out on that basis at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Automated decision-making: not to be subject to a decision producing legal or similarly significant effects based solely on automated processing. The controller does not carry out such processing.
11.3Certain rights may be exercised directly within the Service without the need for a request: Diagnostics may be erased under Settings → Privacy in the desktop IDE, and closure of an account removes the associated sessions and repository connections.
11.4Requests may otherwise be submitted to [email protected]. A request should identify the data subject, state the right being exercised and describe the personal data concerned. The controller may request information reasonably necessary to verify the identity of the requester, and will respond within the period prescribed by the applicable instrument.
11.5A data subject who considers that the processing of their personal data infringes the Federal Law may lodge a complaint with the Secretaría Anticorrupción y Buen Gobierno (SABG). Where the General Data Protection Regulation or the United Kingdom General Data Protection Regulation applies to the processing, a data subject may instead lodge a complaint with the supervisory authority of their habitual residence, place of work or place of the alleged infringement.
12.Cookies and similar technologies
12.1We use cookies and equivalent browser storage solely to maintain authenticated sessions and to record interface preferences such as language and theme.
12.2We do not use cookies for advertising, cross-site tracking or third-party analytics.
13.Children
13.1The Service is not directed to, and may not be used by, individuals under the age of 16. We do not knowingly process personal data of such individuals. Where we become aware that we have done so, we will delete that data without undue delay.
14.Amendments
14.1We may amend this Policy from time to time. The version and effective date recorded at the head of this document indicate when it was last amended.
14.2Where an amendment materially affects the processing of personal data, we will provide notice by an appropriate means before the amendment takes effect. Where the amendment concerns processing carried out on the basis of consent, we will obtain fresh consent.
This Policy is published in English. Where a translation is provided and its meaning differs from the English text, the English text governs. See also our Terms of Service.