Privacy Policy
Last updated 4 August 2026
This policy explains what information BiRoot (“BiRoot”, “we”, “us”) collects, why we collect it, and how it is used, stored, shared, and deleted. It covers the biroot.ai website, the BiRoot AI Studio desktop application, and the BiRoot account service.
The product is in private beta. We collect little, and this policy is written to match what the software actually does rather than to reserve broad rights.
Information we collect
Waitlist. If you join the waitlist on this website, we store the email address you submit.
Account. If you create a BiRoot account, we store the information needed to identify and authenticate you: your email address, your display name, and, if you sign in with a third-party identity provider such as Google, your basic profile information (name, email address, and profile picture). We do not receive or store your password for third-party providers.
Optional cloud features. The desktop application works locally by default. If you sign in and enable cloud-connected features (such as syncing workspace state or remote access from another device), we process the data those features need to function: workspace metadata such as project names, task titles and status, session state, and device identifiers; and, for remote-control features you actively use, the content of the commands and messages being relayed. Each cloud-connected feature is opt-in and described in the product when you enable it.
Diagnostics. Crash reports and usage diagnostics, if enabled, are opt-in. We do not run hidden telemetry.
Payments. We currently sell nothing and collect no payment information.
What stays on your machine
BiRoot AI Studio runs on your computer. Your source code, your repositories, your files, your AI provider credentials and API keys, and your conversation history are stored locally on your machine by default. Installing or using the application does not upload your code to us, and agent execution happens on your machine, not on our servers.
BiRoot coordinates AI tools that you connect under your own accounts (for example Claude Code, Codex, or OpenCode). Your use of those tools is governed by their providers’ terms and privacy policies, and your credentials for them are not transmitted to BiRoot.
Google user data
If you choose to sign in with Google, we request only basic profile scopes: your name, email address, and profile picture. We use this information solely to create and authenticate your BiRoot account and to display your identity inside the product.
We do not request access to Gmail, Google Drive, Calendar, Contacts, or any other Google service data. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with your explicit consent, for security purposes, to comply with law, or as necessary to operate the service.
BiRoot’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we use information
We use the information described above to:
- create, authenticate, and secure your account;
- provide the features you enable, including sync and remote access;
- contact you about beta access, product research, and launch updates, if you joined the waitlist;
- fix defects and keep the service reliable and secure;
- comply with legal obligations.
We do not sell personal information, do not share it with data brokers, and do not use it for third-party advertising.
How we share information
We share information only with the service providers that host and operate our infrastructure, and only to the extent needed to run the service:
- Supabase — authentication and application data hosting for accounts and cloud features;
- Cloudflare — website hosting, DNS, and network security.
We may also disclose information if required by law, or to protect the rights, safety, and security of BiRoot, our users, or others. If BiRoot is involved in a merger, acquisition, or asset sale, we will notify you before your information becomes subject to a different policy.
Data retention and deletion
We keep account data for as long as your account exists, and waitlist entries until you ask to be removed or the beta programme ends.
You can request deletion of your account and associated data, or removal from the waitlist, at any time by emailing hello@biroot.com. We will delete the data we hold about you within 30 days, except where we are legally required to retain it. Data stored locally on your machine is under your control and can be deleted by removing the application and its data directory.
Security
Account authentication uses industry-standard protocols (OAuth 2.0 and encrypted transport). Data in transit to our services is encrypted with TLS. Access to production systems is limited to the people who operate them. No method of transmission or storage is perfectly secure, and remote features in beta are opened gradually and documented as they ship.
Children
Our services are not directed to children under 13 (or the higher minimum age in your jurisdiction), and we do not knowingly collect personal information from them.
International users
Our infrastructure providers may process data in data centres in multiple regions. Where data is transferred across borders, we rely on our providers’ standard contractual safeguards.
Changes to this policy
When this policy changes materially, we will update the date at the top of this page and notify account holders and waitlist members by email before the change takes effect.
Contact
Questions about this policy or your data go to hello@biroot.com.