sapling
Home Terms Privacy
Dashboard →

Privacy Policy

Effective September 7, 2026

1. What this covers

This Privacy Policy explains what information Sapling collects when you use Sapling's CLI and hosted services (the "Service"), how we use it, and the choices you have.

2. Information we collect

Account information. Your email address and authentication data, handled through our authentication provider (Supabase). We don't store your password ourselves.

Billing information. If you subscribe to a paid plan, payment card details are collected and processed directly by our payment processor (Stripe) - we never see or store your full card number.

Usage data. Which models you use, token counts, and cost figures, so we can meter your plan and show you your own usage. We do not use this to build a profile of you beyond what's needed to run your account.

Prompts and content you submit. When you send a message through the Service, it's forwarded to the relevant AI model provider to generate a response. We log enough about that request (timing, token counts, which model) to bill and debug it; we do not use the content of your prompts to train our own models, and we don't sell it.

BYOK keys. If you add your own provider API key, it's encrypted at rest and used only to forward your own requests to that provider on your behalf.

Local data. Your research log, session history, and configuration live on your own machine under .sapling/ - we don't have access to these unless you explicitly share them with us (for example, when asking for support).

3. How we use information

  • To provide, maintain, and improve the Service;
  • To process payments and manage your subscription;
  • To meter usage against your plan and enforce quotas;
  • To communicate with you about your account, changes to the Service, or support requests;
  • To detect, prevent, and address abuse, fraud, or security issues.

4. Who we share information with

We share information only as needed to run the Service:

  • AI model providers (Anthropic, OpenAI, and others) receive the content of your prompts in order to generate a response - that's the core function of the Service.
  • Supabase hosts our database and handles authentication.
  • Stripe processes payments and stores your payment method on our behalf.
  • Fly.io hosts our backend infrastructure.

We do not sell your personal information to third parties.

5. Data retention

We keep account and usage data for as long as your account is active, and for a reasonable period afterward as needed for legitimate business or legal purposes (for example, billing records). You can request deletion of your account and associated data - see Section 7.

6. Security

We use industry-standard measures to protect your information, including encryption of BYOK keys at rest and encrypted connections (TLS) for data in transit. No system is perfectly secure, and we can't guarantee absolute security.

7. Your choices

  • You can view and update your account details from the dashboard's Settings page.
  • You can add, remove, or rotate a BYOK key at any time.
  • To request deletion of your account and associated data, contact us at noah95mitchell@gmail.com - we'll process the request within a reasonable time.

8. Children's privacy

The Service isn't directed at anyone under 18, and we don't knowingly collect information from anyone under that age.

9. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we'll make reasonable efforts to notify you before they take effect.

10. Contact

Questions about this policy, or a data request? Reach us at noah95mitchell@gmail.com or on Discord.

Questions about either of these? Reach us on Discord or at noah95mitchell@gmail.com.