Privacy Policy

What data Semantix collects, what it does not, and what stays on your machine.

Version 1.1Last updated

Effective 4 August 2026 · Version 1.1

The short version#

Your code lives on your computer. The editor, the code index, and the graph work fully offline and never upload it.

When you run an agent, work is sent. That request carries your prompt, the file context for it, the results of tools the agent runs, and your provider key — to our service, which passes it to the model provider you chose. We do not store it, log it, train on it, or use it for anything but answering that request.

If you create an account on this website, we hold your name, your email address, and a hashed password.

The rest of this page is the detail behind those three paragraphs. It says the same things as section 3 of our Terms of Use, in the same words, on purpose.

Three different things#

It matters which one you are asking about, because the answers are different.

Where it runs What we receive
The editor, index and graph Your computer Nothing. It works offline.
Agent requests Our service, then your model provider Your prompt, file context, tool results, your provider key — for that request only
This website + your account Our servers Your name, email, hashed password

1. What never leaves your computer#

  • Your source code and project files. The Studio reads and indexes the files you point it at. That index is written to a directory on your own computer. It is not uploaded and we have no access to it.
  • The code graph. Built locally, from the local index.
  • Your settings, themes, and local configuration.
  • Your API keys at rest. They are written to a configuration file in your own home directory with owner-only permissions.

The editor and the graph require nothing from us. If our servers vanished tomorrow, they would keep working.

2. What is sent when you run an agent#

Running an agent is a request to send work to a model. That is what it is for, and it cannot be done without sending something. Here is exactly what.

Sent with each agent request:

  • Your prompt.
  • The file context assembled for it, which may include the contents of your files.
  • The results of tools the agent runs — file contents, search results, command output.
  • The API key for the model provider you configured.

Where it goes: to our service, which calls the model provider you chose and returns their answer to you.

What we do with it: we serve the request. Nothing else.

  • We do not store your prompts, your code, or your tool results.
  • We do not log them.
  • We do not store your API key. It is used to make your call and it is not retained.
  • We do not train any model on any of it.
  • We do not sell it or share it with anyone other than the provider you chose.
  • Transmission is encrypted.

What the provider does is between you and them. OpenAI, Anthropic, Groq, OpenRouter, whoever you configured — their handling of your data is governed by their privacy policy, not this one, and it is worth reading.

3. This website and your Semantix account#

If you create an account here, we collect:

  • Your name and username — so the product can address you.
  • Your email address — to identify your account, to let you sign in, and to reach you about your account or important changes to the service.
  • Your password — stored as a cryptographic hash. We cannot read it, and neither can anyone who obtains the database.

We keep a session cookie so you stay signed in between visits. It is strictly necessary for the site to work; it is not an advertising or tracking cookie, and we do not sell or share it.

Our servers keep standard technical logs — IP address, timestamp, requested page — as any web server does, for security and debugging. These are kept for a limited period and are not used to build a profile of you.

4. What we do not do#

  • We do not sell your personal data. Not to anyone, at any price.
  • We do not share it with advertisers or data brokers.
  • We do not use third-party advertising or cross-site tracking on this site.
  • We do not read your source code for our own purposes, and we do not keep it.
  • We do not train any model on your data.

5. Who else is involved#

We keep this list short on purpose, and we will keep this page honest as it grows.

  • Hosting. This site and our services run on servers we rent. Our hosting provider processes data on our behalf, under contract, and does not use it for their own purposes.
  • Model providers. Whoever you chose. You have a direct relationship with them, and your request reaches them because you asked us to send it.

If we ever add a service that processes your personal data, we will name it here before it goes live.

6. Your rights#

Wherever you live, you may ask us to:

  • See what personal data we hold about you.
  • Correct anything that is wrong.
  • Delete your account and the data attached to it.
  • Export your data in a portable form.
  • Object to a particular use of it.

Write to privacy@semantix.dev and we will act on it within 30 days. We will not make you justify the request, and we will not make deletion difficult.

If you are in the European Economic Area or the United Kingdom, the GDPR gives you these rights as a matter of law, and you also have the right to complain to your national data protection authority. Our legal basis for processing your account data is the performance of our contract with you — we cannot give you an account without it.

7. How long we keep things#

  • Agent requests — not retained. Prompts, code context, tool results and keys are used to serve the request and are not written to storage.
  • Account data — for as long as your account exists, and deleted when you delete it.
  • Server logs — a limited retention period, then discarded.
  • Backups — deleted data may persist in encrypted backups for a short window before those backups rotate out.

8. Children#

Semantix is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has given us data, write to us and we will remove it.

9. Security#

We take reasonable technical measures to protect your data: passwords are hashed, connections are encrypted in transit, and access to production systems is limited.

No system is perfectly secure, and we will not pretend otherwise. If we ever suffer a breach affecting your personal data, we will tell you, and we will tell you what actually happened.

10. Changes to this policy#

The Studio is early software and our infrastructure is growing. When what we collect changes, this page changes with it — with a new version number and date at the top, before the change takes effect, not after.

We will not quietly widen what we collect and leave the old promise on the page.

11. Contact#

privacy@semantix.dev

Semantix, Israel.