Privacy Policy

Last updated: July 2026

1. The CLI — Zero Telemetry

When you install and run epi-recorder locally, nothing is sent to EPI Labs. The CLI generates .epi files entirely on your machine. Your prompts, responses, API keys, environment variables, and workflow data never leave your computer unless you explicitly upload them to a hosted service.

2. Hosted Verification & SCITT

When you use hosted verification or SCITT remote anchoring, the .epi file is transmitted to our servers for processing. We process it ephemerally — verification results are returned immediately and the file is not retained after the operation completes unless you have explicitly opted into case storage (Pro/Team/Enterprise plans).

3. Account Information

When you sign in with GitHub, we receive your public profile information (username, avatar, email if public). This is used to identify your account and associate it with your subscription tier. We do not sell, share, or monetize this data.

4. Payment Information

All payments are processed by Paddle, our payment partner. EPI Labs never receives or stores your credit card details. Paddle's privacy policy applies to your payment data.

5. Analytics (Website Only)

Our website uses Plausible Analytics, a privacy-focused analytics service that does not use cookies and does not track individuals. No personal data is collected. The CLI has no analytics or telemetry of any kind.

6. Cookies

We do not use tracking cookies. Authentication tokens are stored in your browser's localStorage when you sign in, and are sent only to our API for session verification.

7. Data Retention

Account data is retained as long as your account is active. You may request deletion at any time by emailing us. Shared cases expire automatically based on the expiry period set at upload time (default 30 days). Verification requests are processed in memory and not retained.

8. Your Rights

You have the right to access, correct, or delete your account data. You may export your data or close your account at any time. Since we collect minimal data, most requests are straightforward — email us and we'll handle it.

9. Security

All hosted services communicate over HTTPS. API keys are hashed at rest. Our infrastructure is hosted on Render with encrypted volumes. We do not have access to your locally generated .epi files unless you explicitly share them.

10. Changes to This Policy

We may update this policy. Material changes will be communicated via email to active subscribers and posted on this page.

11. Contact

Privacy questions: mohdibrahim@epilabs.org