Privacy Policy
Last updated: 30 June 2026
1. Who we are
Drifterr ("we", "us") provides the Drifterr application and website at drifterr.app. For any privacy question, contact support@drifterr.app.
2. What stays on your device (and never reaches us)
Detection runs entirely locally. The following never leave your machine and we never receive them — on any plan, including Team:
- Your conversations, prompts and the assistant's replies;
- Your goal, constraints and decisions (the "baseline");
- Drift signals, drift scores and re-anchor snapshots.
These live in a local SQLite database on your computer. If you enable the optional "judge" feature, a short excerpt of the relevant turn is sent to your own AI provider (e.g. OpenAI, Anthropic, OpenRouter) using your own API key — it goes directly from your machine to that provider, never through Drifterr.
3. What we do collect (accounts, billing, and opt-in Team sharing)
- Account: your email address, and your name if you provide it.
- Subscription: your plan, subscription status and renewal date.
- Billing: a Stripe customer/subscription identifier. Payment card details are handled by Stripe — we never see or store them.
- Auth metadata: standard sign-in data (e.g. timestamps), and, if you use Google/GitHub sign-in, the basic profile your provider returns.
- Team sharing (Team plans only, and only when you act):
the rule packs you choose to share — configuration text you wrote,
such as "Never use
anytypes" — and counts of how often each shared rule fired, such as ("tight-scope:no-new-deps", 7), bucketed by day. That is the complete list.
Team sharing never includes offending spans or excerpts, your goal, prompts or replies, session identifiers, file, repository or branch names, model names, or timestamps finer than a day. Rules you stated in conversation are excluded as well, because their identifiers were derived from your own messages. Before anything is sent, the app can print the exact payload — Settings → Team sharing → "Show exactly what would be shared" — together with a note of what was withheld and why.
4. Processors we use
- Supabase — authentication and the accounts/subscriptions database.
- Stripe — payment processing and subscription management.
- Resend — transactional emails (e.g. confirm your email).
- Vercel — hosting of this website.
Each processes the limited data above on our behalf. Your AI model provider (when you use the judge) acts under your own account, not ours.
5. Cookies & local storage
The website uses local storage and cookies only to keep you signed in and remember preferences (e.g. your selected provider and whether you've seen onboarding). We do not run third-party advertising or cross-site tracking.
6. How we use the data
To create and secure your account, provide the plan you chose, process payments and renewals, send essential service emails, and comply with legal obligations. We do not sell your data.
7. Retention
We keep account and billing data while your account is active and as required for legal/accounting purposes. Delete your account by contacting us and we will remove your personal data, subject to those obligations.
8. Your rights
Depending on where you live (e.g. the EU/EEA under GDPR), you may access, correct, export or delete your personal data, and object to or restrict certain processing. Email support@drifterr.app to exercise these rights.
9. Security
Access to account data is protected by row-level security and is limited to your own records. We never transmit conversation content.
10. Children
Drifterr is not directed to children under 16, and we do not knowingly collect their data.
11. Changes
We may update this policy; we'll revise the date above and, for material changes, notify you. Continued use means acceptance of the update.
Questions? support@drifterr.app · See also our Terms of Service.