Privacy Policy
How Tecsteps GmbH processes personal data for daemons.run.
Version of 26 September 2026.
1. Who is responsible
We are Tecsteps GmbH, Breitscheidstr. 42, 16321 Bernau bei Berlin, Germany, represented by Managing Director Fabian Wesner, registered at Amtsgericht Frankfurt (Oder), HRB 18540, VAT ID DE341723281. Privacy contact: fabian.wesner@tecsteps.com. No data protection officer is appointed; the managing director is the privacy contact.
2. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| PurposeCreating and keeping your account, signing you in | DataName, verified email, provider and provider account identifier, provider handle, time of last sign-in, time of joining | Legal basisArt. 6(1)(b) GDPR, steps taken at your request before a contract |
| PurposeTelling you about your own account and your own workspaces, for example that a workspace you created is ready to use | DataEmail address, name, the content of that message and its delivery result | Legal basisArt. 6(1)(b) GDPR, performance of the contract you asked for. There is no newsletter, no marketing list and no tracking pixel |
| PurposeDelivering this website, keeping it available and investigating faults or abuse | DataConnection data and request metadata as described in section 4 | Legal basisArt. 6(1)(f) GDPR, our legitimate interest in a working and protected website |
Accepting this Policy is not consent, and nothing here relies on consent. You may object to the processing based on our legitimate interest for reasons relating to your situation; see section 9.
3. Signing in with GitHub, Google or Microsoft
The provider you choose receives the sign-in request and handles its own account and connection data under its own privacy notice. For people in the European Economic Area those providers are GitHub B.V., Prins Bernhardplein 200, 1097JB Amsterdam, Netherlands, together with GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, California, United States; Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; and Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
We ask each provider only for what the sign-in needs: GitHub for your account and verified email address, Google for your OpenID identifier, basic profile and email address, Microsoft for your OpenID identifier, basic profile and email address.
From that answer we keep, for every provider, the provider name, the provider account identifier, the verified email address and the time when it was verified, your handle where the provider supplies one, and the time of your last sign-in with that provider. For GitHub the account identifier is your numeric GitHub account number, for Google it is your OpenID subject identifier, and for Microsoft it is your Microsoft tenant identifier together with your account object identifier, plus a marker showing whether you signed in as a member of that tenant. A Microsoft identity without a verified email address can only be linked while you are authenticated through another provider.
We do not store the access token the provider issues at sign-in, and we ask for no refresh token, so none is issued. The access token exists only in the memory of the request that signs you in and is gone when that request ends.
From the provider we receive an account identifier, your name, your email address as verified by that provider, your handle where the provider has one and, where the provider offers one, the address of your avatar image. We do not keep the avatar address. We never receive your provider password.
You do not have to give us any of this; without a sign-in there is simply no account. We store your name, your verified email address, the provider you used and its account identifier, your handle at that provider where it supplied one, the time of your last sign-in, the time you joined.
We do not enrich your data from other sources, we build no profile and we do not pass your data to advertisers.
Sign-in is the only thing we use these providers for.
4. Website delivery and server logs
Delivering this website processes your IP address, the time of the request, the requested host and route, the response status and connection data; request headers may include a user agent and a referrer. We use these records to deliver the site, to keep it available and to investigate faults and abuse. Stored diagnostics exclude credentials and free-text payloads. We run no analytics, no advertising and no tracking of any kind. The pages, the stylesheet, the fonts and the one script this site uses are all served from daemons.run itself, so reading a page makes no request to any other company.
The certificate that secures this site is issued by Let's Encrypt (Internet Security Research Group). Certificate authorities publish the host names they certify in public Certificate Transparency logs, so the name daemons.run appears there. Nothing about you is in that record.
5. Where the data is, and who else sees it
Tecsteps operates from Germany. The website and its database run on Scaleway SAS infrastructure in Paris, France, as our processor.
| Recipient | Purpose and data | Location |
|---|---|---|
| RecipientScaleway SAS | Purpose and dataHosting of the website, the database and its encrypted backups | LocationParis, France |
| RecipientBrevo SAS, 106 boulevard Haussmann, 75008 Paris | Purpose and dataSending the email we owe you about your own account and workspaces: your address, the content of that message and the delivery result. It sends from a verified daemons.run sender. | LocationFrance, EU |
| RecipientStripe Managed Payments | Purpose and dataMerchant of record for paid subscriptions. Stripe handles checkout, payment processing, invoicing and applicable taxes. | LocationSee Stripe's privacy notice for information about processing locations. |
| RecipientCloudflare | Purpose and dataDNS for our domains only; no traffic is proxied | LocationDNS query metadata; Cloudflare, Inc., United States, under its standard contractual clauses |
| RecipientGitHub B.V. and GitHub, Inc.; Google Ireland Limited; Microsoft Ireland Operations Limited | Purpose and dataThe sign-in you choose: the fields listed in section 3 | LocationNetherlands and United States; Ireland; Ireland. Onward transfer to the United States under the providers' Data Privacy Framework certifications or standard contractual clauses, see section 3 |
Beyond these, we disclose data only to authorities where the law requires it and to professional advisers bound by confidentiality. We remain responsible for the providers we engage.
6. Pricing and payments
Paid workspace subscriptions are available through our pricing page. Stripe Managed Payments is the merchant of record and handles checkout, payment processing, invoicing and applicable taxes.
Payment details are submitted to Stripe during checkout. daemons.run does not receive full card numbers. Stripe's privacy notice explains how it processes personal data.
7. Retention and deletion
If you have not signed in for twelve months, we send a reminder and delete the account 30 days later unless you sign in. Application log files rotate every day and we keep at most the last 14 days, after which they are deleted. The system's own service logs are kept only as long as needed for the purposes in section 4.
8. Cookies and browser storage
This site sets no cookies for analytics, advertising or tracking, and loads no third-party scripts. It sets exactly two cookies, both by the application itself on daemons.run, both expiring two hours after your last request, both restricted to encrypted connections and to requests that start on this site.
| Cookie | What it does |
|---|---|
| Cookiedaemonsrun-session | What it doesHolds the session that keeps you signed in and carries messages between two page loads. Your browser cannot read it. |
| CookieXSRF-TOKEN | What it doesLets the page prove that a form you submit came from this site and not from another one. |
Local storage holds whether the sidebar is collapsed and whether the Pusher connection uses TLS, so each browser keeps those settings. It also keeps per-browser conveniences: recently opened workspaces, open terminal and chat tabs, the terminal font size, renderer and screen reader mode, the chat theme and model choice, editor line wrapping, expanded folders in the file tree, the CLI platform you picked and when you dismissed the Install app prompt. Session storage keeps an unfinished workspace checkout until you close the tab. These entries stay in your browser and are not sent with requests.
Strictly necessary access and security cookies rely on section 25(2) no. 2 TDDDG; the related processing relies on Art. 6(1)(b) or Art. 6(1)(f) as set out in section 2.
9. Your rights and complaints
Subject to the conditions in the GDPR you may request access, rectification, erasure, restriction and portability, and you may object to processing based on our legitimate interest for reasons relating to your situation. Write to fabian.wesner@tecsteps.com; we may ask for proportionate proof of identity. Deleting your account is the fastest route and needs no request from us.
Right to object. Where we process your data on the basis of our legitimate interest (Art. 6(1)(f) GDPR, see section 2), you may object at any time for reasons relating to your particular situation, under Art. 21 GDPR. We then stop that processing unless we can show compelling legitimate grounds that override your interests, rights and freedoms. We do no direct marketing, so there is no marketing processing to object to.
You may complain to a supervisory authority, in particular where you live or work or where you believe an infringement occurred. Our authority is the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow, Poststelle@LDA.Brandenburg.de. Contact details are available from the Brandenburg authority.
10. Workspaces and workspace content
We process workspace details, configuration, environment variables and content to provide the workspace service. Workspaces run on Scaleway infrastructure. Access to a workspace is controlled by its organization and workspace permissions.
11. Payment and invoicing records
Stripe Managed Payments handles checkout, payment processing, invoicing and applicable taxes. We receive subscription and invoice information needed to manage billing. daemons.run does not receive full card numbers.
12. Workspace health and activity reporting
We record health observations for each workspace, such as processor, memory and disk use and whether it is reachable, to run the service and to show them to its organization. Raw observations are kept for 24 hours and resolved incidents for 30 days.
Where an organization uses the Intelligence package, each workspace reports allow-listed usage metadata from its coding agents: counts and durations per agent and model, token counts, session starts and observed process duration. Prompts, results, tool names, file paths and repository content stay in the workspace. Each developer sees their own records. Admins see aggregates a day later, and activity across people only when at least five people are included. These records expire after 30 days.
13. Data processing agreement and subprocessors
For personal data in an organization's workspaces and reporting, we process on behalf of that organization under Art. 28 GDPR. Organizations can request a data processing agreement from the privacy contact in section 1. The subprocessors we use are the recipients listed in section 5.
14. Financial and billing retention
We retain financial and billing records for as long as required by applicable accounting and tax obligations. Deleting an account does not delete records we are required to retain.
15. Changes to this Policy
We update this Policy when our processing changes. Where a change materially affects you, we tell you.