Privacy Policy

Last updated: May 14, 2026

1. Introduction

Methodic Ventures LLC ("Company," "we," "us," or "our") operates the Chief platform ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Service.

2. Information We Collect

2.1 Information You Provide

  • Account information (name, email address, authentication credentials).
  • Project configuration (repository paths, project names, goals, and settings).
  • Communications you send to us (support requests, feedback).

2.2 Information Processed Through the Service

  • Source code is transmitted by agents on your machine directly to AI providers via the Chief relay. Chief's servers do not store or proxy source code files.
  • Agent interaction logs, task results, and task planning data (which may contain code snippets included in conversation).
  • Token usage and compute metrics associated with your projects.

2.3 Automatically Collected Information

  • Device and browser information, IP address, and access timestamps.
  • Usage patterns and feature interaction data.

2.4 Cookies and Local Storage

We use a small number of cookies and browser local storage entries to operate the Service. The table below lists each one, its purpose, and the lawful basis under which it is set.

Cookies

  • sessionid — server-side session identifier used for authentication. HttpOnly; expires after 2 weeks. Lawful basis: contractual necessity.
  • csrftoken — cross-site request forgery protection token read by the browser to secure form submissions. Lawful basis: contractual necessity and legitimate interest (security).

Local Storage

  • chief_auth_token — API authentication token. Lawful basis: contractual necessity.
  • chief_consent — records your cookie and analytics consent choice (granted, denied, or pending). Lawful basis: legal obligation.
  • chief-draft:{projectId} — preserves unsaved message drafts per project. Lawful basis: contractual necessity.
  • chief.lastProjectId — last visited project for navigation restoration. Lawful basis: legitimate interest (user experience).
  • chief-chat-scroll-{projectId} — chat scroll position per project. Lawful basis: legitimate interest (user experience).
  • chief_referral_prompt_dismissed — whether the referral prompt has been dismissed. Lawful basis: legitimate interest (user experience).

3. How We Use Your Information

We process your information for the purposes listed below. Where required by applicable law (including the GDPR for EU/EEA users), we rely on one of the following lawful bases for each activity.

Contractual Necessity

Processing that is necessary to deliver the Service you signed up for:

  • Providing, operating, and maintaining the Service, including authentication and session management.
  • Routing your tasks and project data to AI agent providers for execution.
  • Processing payments and managing billing through Stripe.
  • Communicating with you about the Service, updates, and support.

Consent

Processing that occurs only after you grant consent (EU/EEA users are prompted via the consent banner; see Section 8):

  • Analytics and usage-pattern tracking, including Google Analytics page views.
  • Funnel and onboarding event telemetry used to improve the product experience.

Legitimate Interest

Processing where we have a legitimate operational need that does not override your rights:

  • Error monitoring and frontend error reporting to maintain Service stability.
  • Latency and performance beacons (sampled, anonymized) to detect service degradation.
  • Detecting, preventing, and addressing security threats.
  • Improving and developing new features for the Service.

4. Data Sharing and Sub-Processors

We share data with the following categories of third-party sub-processors in order to operate the Service. We do not sell your data to third parties.

AI Providers

The core functionality of the Service requires transmitting your project data (including source code) to third-party AI providers such as Anthropic and OpenAI for agent task execution. Each AI provider processes your data according to their own terms of service and privacy policies. We recommend reviewing the privacy policies of the AI providers used by your configured agents.

Google Analytics (consent-gated)

We use Google Analytics for aggregated usage analytics. For EU/EEA visitors, Google Analytics scripts are loaded only after you grant consent via the consent banner. Non-EU visitors may be tracked by default. Google processes this data under its own privacy policy.

Stripe (payment processor)

We use Stripe to process payments and manage subscriptions. Stripe receives your payment method details, billing address, and transaction information as necessary to fulfill its role as our payment processor. Stripe acts as an independent data controller for payment-fraud prevention.

Amazon Web Services (infrastructure)

We host the Service on Amazon Web Services (AWS). All application data, including databases and file storage, resides on AWS infrastructure. AWS processes this data under its Data Processing Addendum.

5. Data Retention

We retain different categories of data for different periods:

  • Account data (name, email, authentication credentials, project settings) — retained while your account is active. After account deletion, we remove or anonymize this data within 30 days, except where retention is required by law.
  • Telemetry and analytics events — retained for 12 months from collection, then deleted.
  • Billing and payment records — retained as required by applicable tax and accounting laws (typically 7 years).
  • Agent interaction logs and task data — retained while your account is active to support ongoing project context.

You may request deletion of your account and associated data by contacting us. Data already transmitted to third-party AI providers or payment processors is subject to their respective retention policies.

6. Data Security

We implement reasonable technical and organizational measures to protect your information. However, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data, particularly given that the Service involves transmitting code to external AI providers over the internet.

For details on our encryption standards, data flow architecture, and agent isolation model, see our Security page.

7. Your Rights and Choices

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of your personal information.
  • Object to or restrict certain processing of your data.
  • Request portability of your data.
  • Withdraw consent at any time for consent-based processing.

EU/EEA Residents

If you are located in the European Union or European Economic Area, you have specific rights under the General Data Protection Regulation (GDPR), Articles 15–22, including the right of access (Art. 15), right to rectification (Art. 16), right to erasure (Art. 17), right to restriction of processing (Art. 18), right to data portability (Art. 20), right to object (Art. 21), and the right not to be subject to automated individual decision-making (Art. 22). You also have the right to lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, contact us at legal@chiefisnext.com. We will respond within 30 days as required by the GDPR.

8. Consent Management

If you visit the Service from the EU or EEA, a consent banner appears at the bottom of the page before any non-essential tracking occurs. The banner gives you two choices:

  • Accept — enables analytics and usage-tracking features, including Google Analytics.
  • Reject — all non-essential analytics remain disabled; the Google Analytics script is never loaded.

Your choice is stored in your browser's local storage (chief_consent) and persists across sessions. To change your preference, clear your browser's local storage for this site and reload the page; the consent banner will reappear.

What Is Consent-Gated

  • Google Analytics page-view and event tracking.
  • Internal telemetry events for product analytics (signup funnels, onboarding timing, feature usage).
  • Analytics-related session storage entries used for funnel measurement.

What Is Exempt from Consent

  • Strictly necessary cookies (sessionid, csrftoken) required for authentication and security.
  • Frontend error reporting (legitimate interest in operational stability — no marketing or profiling purpose).
  • Anonymized latency beacons used for infrastructure monitoring (sampled at 10%, no user identifiers).

9. Children's Privacy

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will take steps to delete it.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your own, including the United States and any country where our AI providers operate. By using the Service, you consent to such transfers.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. Your continued use of the Service after changes constitutes acceptance.

12. Contact Us

If you have questions about this Privacy Policy, contact us at legal@chiefisnext.com.

Methodic Ventures LLC