Privacy Policy

Effective Date: 8/3/2026

Last Updated: 8/3/2026

1. Who We Are

This Privacy Policy explains how tyne.io / proflowtech.io ("Tyne", "we", "us", or "our") collects, uses, and discloses information about you when you access or use our website (tyne.proflowtech.io), VS Code extension, authentication flow, paid plans, integrations, and related services (collectively, the "Services").

If you have any questions, you can contact us at support@proflowtech.io.

2. Scope

This policy applies to all users of our Services, including developers utilizing our VS Code extension, team members accessing our web dashboard, and administrators configuring integrations (such as Jira or GitHub) and billing.

3. Data We Collect

  • Account Data: Email address, GitHub username, profile data, avatar, user ID, and session metadata.
  • Authentication Data: Supabase Auth session data and OAuth provider identifiers.
  • Billing/Subscription Data: Plan tier, subscription status, customer IDs, payment status, and renewal/cancellation metadata. Payment card processing is handled by our configured payment processor (e.g., Dodo Payments); we do not store raw card numbers.
  • Product Usage Data: Commit generation events, PR generation events, usage counters, timestamps, token usage, feature usage, and diagnostics.
  • Repository/Project Configuration: Repository name, custom guardrail rules, allowed commit types, Jira-ticket requirement settings, and custom prompt instructions.
  • Jira/Atlassian Integration Data: Jira cloud/site ID, Atlassian account email/name, access token, refresh token, expiration time, and issue/ticket metadata needed to map code changes to sprint work (collected only when you connect Jira).
  • Git/Code Data: To generate commits and PR descriptions, Tyne may read local Git staged diffs, commit history, branch names, repository metadata, and pull request context. These may be processed by the configured AI service.
  • BYOK (Bring Your Own Key) Data: If you connect your own AI provider key, it is used to authenticate requests to your chosen provider. If stored server-side, it is handled securely.

4. How We Use Data

We use the collected data for the following purposes:

  • Providing authentication and account management.
  • Enforcing subscription and billing requirements.
  • Generating AI-assisted commits and PR descriptions.
  • Performing guardrail and compliance checks on code changes.
  • Syncing issue metadata with Jira/Atlassian.
  • Preventing abuse, rate limiting, debugging, securing the Services, and improving our products.
  • Complying with legal obligations.

5. AI Processing

Tyne's review and generation features operate on your code diffs, repository metadata, commit history, linked project management tickets, and any instructions you provide. AI output may be inaccurate or incomplete; you remain responsible for reviewing all findings and generated content before acting on them.

For BYOK plans, your chosen AI provider’s terms and privacy rules apply to data sent using your key.

6. Data Sharing & Subprocessors

We may share data with the following categories of subprocessors to operate the Services:

  • Supabase (for authentication and database hosting).
  • GitHub (for OAuth sign-in).
  • Atlassian/Jira (for issue tracker integration).
  • Our configured payment processor (e.g., Dodo Payments) for billing.
  • AI model providers used by Tyne or configured by you (BYOK).
  • Hosting, analytics, and error-monitoring providers.

7. Data Retention

We retain account data while your account is active. Billing records are retained as legally required. Jira tokens are retained while the integration remains connected. Usage logs are retained for rate limiting, abuse prevention, analytics, and billing enforcement.

You may disconnect integrations, delete your account, or request data deletion by contacting support.

8. Security

We implement reasonable technical and organizational safeguards to protect your data, including utilizing Supabase Row Level Security where applicable and secure secret storage mechanisms in our VS Code extension.

9. User Rights

Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of your personal data. To exercise these rights, please contact us at the email provided in Section 1.

10. International Transfers

Your information may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ. By using the Services, you consent to such transfers.

11. Children

Our Services are not intended for children under the age of 16. We do not knowingly collect personal data from children.

12. Changes to this Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the "Effective Date" at the top of this policy or by providing other appropriate notice.