Legal
Privacy Policy
Last updated August 31, 2026
01Overview
This Privacy Policy explains what information Astrea ("Astrea," "we," "us") collects when you use our website, desktop application, and gateway (together, the "Service"), how we use it, and the choices you have.
Privacy by design is core to how Astrea works: your code stays on your machine. We built the Service so that the parts of your project that matter most (your source files, credentials, and project history) never have to leave your computer.
02Information we collect
- Account information. Email address, a salted hash of your password (never the password itself), and your account creation date.
- Authentication and device records. API keys, the list of IDE devices linked to your account, and session metadata used to keep you signed in.
- Usage and billing records. Model requests, token counts, charges, top-ups, and balance history, kept so we can meter usage and bill you accurately.
- Support and security communications. Anything you send us through the contact form, by email, or through a support ticket.
- Website interaction data. Your session, theme preference, and language preference, stored locally in your browser (see "Cookies and Local Storage" below).
03Information we do not collect
We do not receive copies of your source code, project files, credentials, or project history. These are processed locally by the desktop application on your machine and are never transmitted to us.
We do not scan, store, or train on your code. We do not sell your personal information, and we never will.
04How model requests are handled
When you send a request through the gateway, the content of that request (for example, your prompt and any code you have chosen to include in it) is forwarded to the third-party model provider that serves the model you selected, so the request can be completed.
- Providers process and may retain request content under their own privacy policies. We encourage you to review the terms of any provider you use.
- Where possible, we route through providers that commit not to use submitted content to train their models, but this varies by provider and model, and you should confirm the current terms for the specific model you choose.
- We ourselves use request content only to complete the request, meter your usage, and bill you correctly. We do not use it to train models, and we do not retain it any longer than necessary for these purposes.
05Payments
Payments are processed by Stripe, a third-party payment processor. We receive confirmation of the payment amount and outcome, but we never store your full card number on our servers. Stripe's handling of your payment details is governed by Stripe's own privacy policy (https://stripe.com/privacy).
06Cookies and local storage
The website stores a small amount of data in your browser, specifically:
- your login session,
- your preferred theme, and
- your preferred language.
07How we use information
We use the information described above to:
- operate, maintain, authenticate, and secure the Service;
- meter usage and process billing;
- provide customer and technical support;
- communicate with you about your account, updates, or changes to our policies; and
- investigate and prevent abuse, fraud, or violations of our Terms of Service (https://getastrea.com/terms).
08Sharing of information
We share information only as needed to run the Service:
- Model providers (for example, OpenRouter, opencode, Groq, and similar) receive request content to fulfill the model request you initiate.
- Stripe receives payment information needed to process transactions.
- Service providers who host our infrastructure or help us operate the Service, bound by confidentiality and data-protection obligations.
- Legal and safety disclosures, where required by law, legal process, or to protect the rights, property, or safety of Astrea, our users, or others.
09Data retention
We retain account and billing records for as long as your account is active, and for a reasonable period afterward to comply with legal, tax, and accounting obligations.
Model request content is retained only as long as necessary to complete the request and produce accurate usage and billing records, and is not kept for any secondary purpose.
You may export your account data or request deletion from the signed-in dashboard. Deletion revokes active sessions, IDE devices, API keys, and Discord links and anonymizes the account identity; payment and usage records that must be retained for legal, tax, fraud-prevention, or accounting reasons remain subject to those obligations.
10Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, or delete the personal information we hold about you.
To exercise any of these rights, contact privacy@getastrea.com. We will respond to verifiable requests within the timeframe required by applicable law.
- EU, EEA, and UK residents have rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with your local data protection authority.
- California residents have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected and to request its deletion.
11International data transfers
Astrea and the providers we work with may process information in countries other than your own. Where we transfer personal information internationally, we rely on appropriate safeguards, such as standard contractual clauses, as required by applicable law.
12Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us at privacy@getastrea.com and we will delete it.
13Security
- Provider API keys and account secrets are stored only on our servers, never in the browser or the desktop application.
- All traffic between the IDE, the website, and our servers is encrypted in transit.
- Access to production systems is limited to authorized personnel and is logged and audited.
14Changes to this policy
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security, but we work to protect your information using industry-standard practices.
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. We will post the updated policy here with a new "Last updated" date, and we will notify you of material changes through the Service (for example, by email or an in-app notice).
15Contact us
For questions about this Privacy Policy or our privacy practices, contact us at:
privacy@getastrea.com
or via our contact page (https://getastrea.com/contact).
