Legal
Privacy Policy
Last updated: September 25, 2026
Draft — to be reviewed before launch. This text is a working draft, not a final policy and not legal advice.
The short version: Technically Not is a desktop app. Your projects, prompts and agent conversations stay on your PC, apart from what the agents you run send to their own providers. If you create an account, our accounts server at api.technicallynot.ai keeps only what the account needs: your email, how you sign in, your plan and your sign-in sessions. The app sends no telemetry or analytics. This website sets no cookies and runs no trackers.
1. Who we are
Technically Not is made by [legal entity name], [registered address] (“we”, “us”). We are the data controller for the limited personal data described here that reaches us.
2. What the app does with data
Your projects stay on your PC
Technically Not reads and writes your project folder locally. It doesn’t upload your files, code, prompts or terminal output to us, and our servers never receive them.
What the app stores on your PC
The app keeps its own data in %AppData%\TechnicallyNot.ai on your computer. This includes:
- Settings, the last project folder, and agent setup (limits, custom agents, rules).
- Terminal session records and scrollback, so work survives a crash or restart.
- Files you attach in the composer. These are deleted automatically after 30 days.
- Per-project agent context notes and Git worktrees made for agents.
- If you sign in to Technically Not, your account profile, with its sign-in tokens encrypted by Windows secure storage.
None of this is sent to us. Uninstalling the app and deleting that folder removes it.
Your Technically Not account
If you create an account, our accounts server at api.technicallynot.ai stores:
- Your account email.
- How you sign in (Google, or email and password).
- If you use a password, a hash of it. We never store the password itself.
- Your plan and subscription status.
- Records of your sign-in sessions, so you can stay signed in and sign out.
Stripe holds your payment details; we don’t. Your AI provider keys and your project files are never sent to us.
Agent sign-ins
Technically Not never asks for or stores passwords or API keys for AI agents. Each agent CLI (for example Claude Code, Codex or Cursor Agent) signs in by itself. To show which account and plan a panel uses, the app reads the account email and plan name (for example Pro or Max) from the CLI’s own sign-in file on your PC. The token in that file is never copied, shown or sent anywhere.
When the app goes online
- Agents you run. An agent sends your prompts and the files it works on to its own provider, under that provider’s terms and privacy policy. Technically Not doesn’t send that data anywhere else.
- App updates. The app checks for updates at api.technicallynot.ai over HTTPS at start and every 4 hours, and installs them automatically. You can change this in Settings › Updates. Our update server sees your IP address and app version, as with any download.
- Agent CLI version checks. For agent CLIs published on npm, the app asks the public npm registry for the latest version number, shortly after start and every 6 hours. Only the package name is sent.
- Optional Technically Not sign-in. You can choose “Continue with Google”, which signs you in through Google in your browser, or sign in with an email and password. New email accounts are confirmed with a verification email, and you can turn on two-step sign-in codes. Sign-in goes through our accounts server at api.technicallynot.ai (see Your Technically Not account). Signing out revokes the tokens.
- Git. Fetch, Pull and Push contact your repository’s remote only when you click them, using your own Git credentials.
The app also runs small servers bound to 127.0.0.1 (your own PC only) so agents can report live status and so browser sign-in can return to the app. They can’t be reached from the internet.
No telemetry
The app sends no analytics, usage data or crash reports to us or anyone else.
3. What this website collects
This website is a set of static pages. It sets no cookies, runs no analytics or advertising trackers, and loads no third-party scripts or fonts. That’s why there is no cookie banner. The one exception: if you sign in on this website (when that’s available), our accounts server sets a single sign-in session cookie.
Our web host, [hosting provider], keeps standard server logs (such as IP address, browser and pages requested) for security and to keep the site running. We don’t use them to identify you.
4. Payments
Purchases are processed by Stripe (Stripe Managed Payments), acting as Merchant of Record. Pro is a monthly or yearly subscription. Stripe collects your name, email, billing address and payment details, and handles tax. We never see your full card details. Stripe shares with us what we need to run and support your subscription: your name, email, country, your plan and its status. Stripe’s privacy policy also applies.
5. Support email
If you email us, we use your message and address only to answer you and to keep a record of the conversation.
6. Third parties
- AI agent providers you choose to run (for example Anthropic, OpenAI, Cursor). You have your own relationship with them.
- GitHub stores app releases, which our update server delivers.
- npm registry answers CLI version checks.
- Google, only if you use it to sign in to Technically Not.
- Stripe for purchases and subscriptions.
- [Hosting provider] for this website.
We don’t sell or rent personal data, and we don’t share it for advertising.
7. How long data is kept
- Data in the app stays on your PC until you delete it. Attachments are removed after 30 days.
- Purchase and subscription records: as long as your subscription is active, and then as long as tax and accounting law requires.
- Support emails: up to [2 years] after the conversation ends.
8. Your rights
Depending on where you live, you can ask us to access, correct, delete or export the personal data we hold about you, or to object to or limit how we use it. Email us and we’ll answer within one month.
- EU and UK (GDPR). We use purchase data to perform our contract with you and to meet legal duties, and support emails based on our legitimate interest in helping you. You can complain to your local data protection authority.
- California (CCPA/CPRA). You have the right to know, delete and correct your data, and not to be discriminated against for using these rights. We don’t sell or share personal information as those laws define it.
Most app data never reaches us, so you control it directly on your PC.
9. Children
Technically Not is a developer tool and isn’t directed at children under 16. We don’t knowingly collect their data. If you think a child has sent us data, contact us and we’ll delete it.
10. Changes to this policy
If we change how data is handled, we’ll update this page and the “Last updated” date. For important changes we’ll also tell you in the app or by email.
11. Contact
Privacy questions or requests: support@technicallynot.ai.

