Privacy Policy

How GDSense handles your data across the plugin, API, and web app.

GDSense is operated by JuneauLabs LLC in Ohio, USA. Our Services are available globally. If you do not agree with this Policy, please do not use the Services.

Don't send secrets. Do not include API keys, passwords, or private tokens in prompts or uploads.

1) Information We Collect

We collect only what's needed to run GDSense:

  • Account info: email, hashed password (password accounts only — see Sign-in with Google or Apple below), email-verification status, and basic account status/permissions metadata.
  • Sign-in with Google or Apple: if you choose to sign in with Google or Apple, we receive your name, your email address, and a stable account identifier from that provider, and we store that identifier to link your GDSense account to your provider sign-in. We never receive or store your Google or Apple password, and accounts created this way have no GDSense password. If you use Apple's "Hide My Email," we receive and use the private relay address Apple provides, and email we send you is forwarded through Apple's relay service.
  • Name: a single display/contact name you provide at registration. We use it to personalize the product and our communications with you. (Your legal/billing name, if any, is held separately by Stripe.)
  • Date of birth: collected at registration to verify that you meet our 18+ age requirement (age-gating) and to comply with applicable law. We store the date of birth you provide and a record that your eligibility was checked.
  • Consent records: when you accept our Terms and Privacy Policy, we record which version you accepted, when, and a hashed (non-identifying) record of the IP address and browser used, as proof of consent.
  • Credentials: API keys (stored as non-reversible hashes with a minimal masked preview) and session tokens.
  • Usage & device data: request timestamps, sizes, IP address, user agent, locale/timezone, and security events.
  • Request Content: We process prompts, code, and outputs to provide AI features as described in Section 3.
  • Automatically supplied project context: In Agent Mode, the plugin automatically sends a shallow tree of file and folder path names to GDSense and third-party AI service providers so the Agent can navigate your project; the tree contains no file contents. On fresh Chat, Quick Edit, and Agent-start requests, if res://AGENTS.md exists, the plugin may automatically read and send its project-rule content as part of the request. Retry preserves the original rules and context instead of rereading the file, and autocomplete does not use AGENTS.md.
  • Optional feedback transcripts: if you rate a response poorly, you may choose to send us that conversation transcript to help us debug. This is opt-in and off by default — see "Optional Feedback Transcripts" below.
  • Cookies/local storage: essential auth/security cookies and preferences; opt-in analytics cookies (PostHog) set only with your consent. If you decline or make no choice, no analytics cookies or identifiers are placed on your device and your visit is counted anonymously instead — see Section 7.
  • Support: emails and in-product feedback you send us.
  • Payments: processed by Stripe, Inc., our U.S.-based payment processor. We store subscription status, tier, billing cycle dates, and invoice metadata. Stripe stores your payment method securely; we never see or store full card numbers. See Stripe's privacy policy: stripe.com/privacy

1a) Optional Feedback Transcripts

  • Opt-in only: If you give a response a negative ("thumbs-down") rating, you may optionally choose to send us the transcript of that specific conversation so we can investigate. The option is unchecked by default — nothing is sent unless you check it.
  • Review before sending: Please review the transcript for secrets (API keys, passwords, private code) before submitting. As a defense-in-depth measure we automatically scrub patterns that look like secrets before storage, but scrubbing does not guarantee removal — do not rely on it.
  • Short retention: Submitted transcripts are encrypted at rest, used only to debug and improve service quality, and retained for no more than 90 days.
  • Never used for training: Transcripts you submit are never used to train or fine-tune AI models.

2) How We Use Information

  • Provide, secure, and improve the Services (authentication, plugin/API features, request history, abuse prevention).
  • Communicate with you (account notices, security alerts, and plugin update notifications). You can manage your notification preferences in your account settings.
  • Process subscription payments through Stripe, our payment processor. We do not collect or store full card numbers — Stripe handles your payment method.
  • Comply with law, enforce terms, and protect rights.

We do not sell personal information and we do not use third-party advertising networks.

If you sign in with Google or Apple, that provider processes your sign-in under its own privacy policy; we receive only the sign-in details described in Section 1, and your prompts and project content are never shared with them.

3) AI Processing & Data Training Protection

Content submitted to GDSense’s AI features may be processed and temporarily retained by third-party AI service providers for up to 30 days to provide and secure the service.

Depending on the feature, submitted content may include prompts, code or scene content you explicitly attach, the Agent Mode shallow tree of file and folder path names described in Section 1 (which contains no file contents), and project-rule content from res://AGENTS.md that may be supplied on fresh Chat, Quick Edit, and Agent-start requests. Retry preserves the original rules and context instead of rereading AGENTS.md, and autocomplete does not use it.

JuneauLabs does not use your prompts, code, or outputs to train AI models.

4) Sharing & Disclosures

We share information only with: (a) service providers that help us run the Services (infrastructure, email, monitoring, payments, AI inference), (b) legal/safety recipients, and (c) parties to a business transfer. We do not share personal information for cross-context behavioral advertising.

5) Data Location & Retention

Data may be stored and processed in the United States and other countries. We retain information only as long as needed for the purposes above or as required by law. Typical ranges:

  • Request metadata: timestamps, sizes, token counts, and status are retained for up to 18 months.
  • AI request content & project context: prompts, explicitly attached content, res://AGENTS.md project-rule content, the Agent Mode shallow path-name tree, and outputs may be processed and temporarily retained by third-party AI service providers for up to 30 days as described in Section 3.
  • User-submitted feedback transcripts: retained for no more than 90 days (see "Optional Feedback Transcripts"). The associated feedback metadata (rating/category) is retained for up to 18 months.
  • Consent records: retained for the life of the account as proof of consent and as required by law.
  • Security/audit logs & short-cycle backups: administrative audit logs up to 18 months; database backups up to 30 days.

Account deletion & right to erasure. You can request deletion of your account and personal data at any time from your account settings or by contacting us. Where applicable, your request may include AI request content and project context that we hold and can associate with your account. We delete or anonymize personal data associated with your account, subject to limited retention where required by law. Third-party AI providers may continue to retain submitted content for their applicable temporary retention period, subject to legal requirements and any applicable deletion rights.

6) Security

We use industry-standard safeguards (TLS, encryption at rest, hashed passwords/keys, least-privilege access, logging, rate-limiting, incident response).

If a security incident affects your personal information, we will notify you and authorities as required by applicable law.

7) Cookies & Analytics

Cookies and analytics. We use essential cookies to keep you signed in and operate core features of the Services, and analytics cookies (provided by PostHog) to understand usage and improve the product. The first time you visit, a cookie banner lets you choose "Accept All" (essential + analytics) or "Essential Only." Analytics cookies are set only if you opt in. If you choose Essential Only we store nothing but that preference itself, and if you make no choice we store nothing at all — in both cases no analytics cookies or identifiers are placed on your device, and we simply count the visit anonymously with a privacy-preserving, irreversible hash that PostHog generates on its servers from a salt that rotates daily and is then deleted, so those visits cannot be linked to you or joined together across days. If your browser signals Do Not Track, we do not count the visit at all. You can change your analytics-cookie choice any time in your account’s Cookie Preferences. Essential cookies are required for the Services to function and are not used for analytics or advertising. We do not sell your personal information or use it for cross-context behavioral advertising.

8) Your Rights

United States:

Depending on your state (e.g., California, Colorado, Virginia), you may have rights to access, correct, delete, or obtain a copy of your information and to opt out of certain processing. We are headquartered in Ohio and comply with applicable U.S. federal and state laws (e.g., CCPA/CPRA).

California residents (CCPA/CPRA):

In the prior 12 months we have collected:

  • Identifiers — name and email address; consent records (including a hashed IP for proof of consent).
  • Sensitive personal information — your date of birth, collected and used solely to verify our 18+ age requirement and to comply with law. We do not use it to infer characteristics about you. Because we use your date of birth only for age verification (an enumerated, permitted purpose) and never to infer characteristics, the CPRA "right to limit the use of Sensitive PI" results in no additional limitation — your date of birth is already restricted to age verification and legal compliance.
  • Commercial information — subscription tier, billing cycle, and invoice metadata (your payment card is handled by Stripe).
  • Internet/usage and device information — request timestamps, sizes, token counts, IP address, user agent, and locale/timezone.
  • Customer records / communications — prompts; code or scene content you explicitly attach; res://AGENTS.md project-rule content that may be supplied on fresh Chat, Quick Edit, and Agent-start requests; the shallow tree of file and folder path names Agent Mode automatically sends (which contains no file contents); AI outputs; support emails and in-product feedback you send us; and optional feedback transcripts you choose to submit (see Section 1a).
  • Inferences — none. We do not create profiles or infer characteristics about you.

We collect each category for the business purposes described in Section 2 and retain each category for the periods described in Section 5.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA, and we have not done so in the prior 12 months. Because we do not sell or share, we do not provide a "Do Not Sell or Share My Personal Information" link; if this changes, we will update this Policy and provide the required opt-out.

Subject to verification, California residents may exercise the rights to know/access, correct, and delete. Where legally applicable, these rights include AI request content and project context that we hold and can associate with your account. We will not discriminate against you for exercising these rights. To make a request, contact support@gdsense.com.

International Users — EEA & UK (GDPR/UK GDPR):

The data controller for your personal data is JuneauLabs LLC; you can reach us at support@gdsense.com. If you are located in the EEA, UK, or Switzerland, you have additional rights under the GDPR and UK GDPR including:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure: Request deletion of your personal data ("right to be forgotten").
  • Portability: Receive your data in a structured, machine-readable format.
  • Restriction: Limit how we process your data in certain circumstances.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw Consent: Where processing is based on consent, withdraw it at any time.

Where legally applicable, these rights include AI request content and project context that we hold and can associate with you.

You may also lodge a complaint with your local data protection authority.

Legal Basis for Processing (EEA/UK):

  • Contract: Processing necessary to provide the Services you requested.
  • Legitimate Interests: Security, fraud prevention, and service improvement (balanced against your rights).
  • Consent: Where you've opted in to optional communications, features, or analytics cookies.
  • Legal Obligation: Where required by applicable law.

Our lawful bases are the performance of our contract with you, our legitimate interests in securing and improving the Services, and your consent where required (for example, analytics cookies, which you may accept or decline via our cookie banner and change at any time).

International Data Transfers:

Your data may be processed in the United States and other countries. For users in the EEA/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and/or the UK Information Commissioner's Office as the legal mechanism for such transfers. We also apply supplementary technical and organizational safeguards as appropriate.

To exercise any rights, contact support@gdsense.com. We'll verify your identity as required and respond within legally required timeframes. We will not discriminate against you for exercising your rights.

9) Children

The Services are for individuals 18 and older. We verify age at registration using the date of birth you provide, and we do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from a person under 18, we will delete it.

10) Changes & Contact

We may update this Policy. We'll post updates with a new effective date and notify you of material changes via the web app or email.

Contact: support@gdsense.com
Operator: JuneauLabs LLC (Ohio, USA)