Privacy Policy
Last updated: July 2026
1. The CLI — Zero Telemetry
When you install and run epi-recorder locally, nothing is sent to EPI Labs. The CLI generates .epi files entirely on your machine. Your prompts, responses, API keys, environment variables, and workflow data never leave your computer unless you explicitly upload them to a hosted service.
2. Hosted Verification & SCITT
When you use hosted verification or SCITT remote anchoring, the .epi file is transmitted to our servers for processing. We process it ephemerally — verification results are returned immediately and the file is not retained after the operation completes unless you have explicitly opted into case storage (Pro/Team/Enterprise plans).
3. Account Information
When you sign in with GitHub, we receive your public profile information (username, avatar, email if public). This is used to identify your account and associate it with your subscription tier. We do not sell, share, or monetize this data.
4. Payment Information
All payments are processed by Paddle, our payment partner. EPI Labs never receives or stores your credit card details. Paddle's privacy policy applies to your payment data.
5. Analytics (Website Only)
Our website uses Plausible Analytics, a privacy-focused analytics service that does not use cookies and does not track individuals. No personal data is collected. The CLI has no analytics or telemetry of any kind.
6. Cookies
We do not use tracking cookies. Authentication tokens are stored in your browser's localStorage when you sign in, and are sent only to our API for session verification.
7. Data Retention
Account data is retained as long as your account is active. You may request deletion at any time by emailing us. Shared cases expire automatically based on the expiry period set at upload time (default 30 days). Verification requests are processed in memory and not retained.
8. Your Rights
You have the right to access, correct, or delete your account data. You may export your data or close your account at any time. Since we collect minimal data, most requests are straightforward — email us and we'll handle it.
9. Security
All hosted services communicate over HTTPS. API keys are hashed at rest. Our infrastructure is hosted on Render with encrypted volumes. We do not have access to your locally generated .epi files unless you explicitly share them.
10. Changes to This Policy
We may update this policy. Material changes will be communicated via email to active subscribers and posted on this page.
11. Contact
Privacy questions: mohdibrahim@epilabs.org