Privacy Policy
Last updated 27 July 2026
Who we are, and the two roles we play
GodviewAI is operated by ParakeetAI d.o.o., Slovenska cesta 55b, 1000 Ljubljana, Slovenia, VAT SI96761202. For anything in this policy you can write to jure@parakeet-ai.com. We are not required to appoint a data protection officer and have not appointed one; that address reaches the person responsible.
We are the controller of the data we need in order to run the service: accounts, authentication, organization membership, billing, support correspondence, and the technical logs that keep the service up and secure. Sections 2 to 11 describe that processing, and are the information notice required by Articles 13 and 14 of the GDPR.
We are a processor for the activity data collected from a customer connected tools. The customer organization decides to collect it, decides who is recorded, and is the controller of it. We process it on their documented instructions under the data processing terms in our Terms of Service. If your employer records your work activity in GodviewAI, they — not we — decide why, and they are who your privacy rights are exercised against. Section 12 explains what we will do if you write to us anyway.
Data we hold as controller
Account and identity
Your name, email address, and profile picture where a sign-in provider supplies one. If you sign in with a password we store a bcrypt hash of it, never the password itself. If you sign in with Google we store the identifier Google gives us and the tokens needed for that sign-in. If you use a one-time email link we store the single-use token and its expiry.
Sessions and security
Sessions are stored in our database and identified by a cookie. We record session creation and expiry, password reset and email verification tokens, and rate-limiting counters keyed to an email address or address prefix, which exist to make credential stuffing expensive.
Organizations
Which organizations you belong to and with what role, invitations you have sent or received (including the invited email address), and the setup state of an organization.
Billing
Subscription and invoice records live with Stripe, our payment processor, keyed to your organization identifier. We read them live and store none of them, and we never see or store your card number. The billing name, address and VAT identification number you give to Stripe are held by Stripe on our behalf.
Technical logs
Our hosting provider records standard request logs — IP address, user agent, URL, status and timestamp — and we record application logs about synchronisation and backfill runs, including error messages returned by connected providers. These exist to operate, debug and secure the service.
Correspondence
If you email us, we keep the message and our reply for as long as needed to deal with it and to keep a record of what was agreed.
Data we process as processor, for a customer
When an organization connects a provider, we collect records of work activity from it and store them under that organization. What we hold depends on which providers are connected, and typically includes:
- Activity records: what happened, who did it, when, and where — the provider, the type of event, the actor identifier, a timestamp, a title, a link, a repository or workspace name, an optional detail line, a duration, and a count of lines changed. Titles and details often contain content: a commit message, an issue or document name, an email subject line, or a short excerpt of a chat message.
- Work intervals: derived spans of work, such as the period a pull request or issue was open and who owned it.
- Presence and status: where Slack is connected, periodic records of whether a user was shown as active or away, and their status text and emoji, each with the time it was observed.
- Coding-assistant metrics: where Claude Code telemetry is connected, session identifiers, model names, repository names and numeric measurements over time.
- Directories: the member lists of connected workspaces — names, handles, email addresses, avatars and identifiers — so that accounts can be recognised and linked.
- People and links: the people the customer has created and the provider accounts attached to each of them. This mapping is what turns scattered handles into a named individual, and it is created by the customer.
- Custom events: anything the customer pushes to their own ingest endpoint. Its content is entirely their choice, and our Terms forbid sending special categories of personal data.
We collect only what the granted permission scopes allow, on the schedule the customer configures, and only for the providers they connect. We do not sell any of it, we do not use it for advertising, we do not use it to build profiles of our own, and we do not use it to train artificial intelligence models. We do not currently send it to any third-party model provider; if that ever changes, this page and the sub-processor list below will say so before it does.
Where the data comes from
Directly from you, when you create an account, name an organization, invite someone, or write to us. From your sign-in provider, when you choose to use one. From Stripe, for the state of a subscription. And, for the activity described above, from the provider APIs that the customer organization has authorised: GitHub, Slack, Linear, Google Workspace (Gmail, Calendar and Drive), Figma, Notion, Discord, Claude Code, and any custom source the customer pushes to.
This means we may hold personal data about people who never created an account with us — colleagues who appear in a connected workspace. We hold it for the customer, who is responsible for informing them.
Why we use it, and on what legal basis
- To provide the service you asked for — accounts, authentication, organizations, collecting and displaying activity, support. Legal basis: performance of a contract, or steps taken at your request before entering one.
- To take payment and keep the records tax law requires. Legal basis: contract, and legal obligation.
- To keep the service secure and working — logging, rate limiting, abuse prevention, debugging, backups. Legal basis: our legitimate interest in the security and integrity of the service, which we consider not to be overridden by the interests of the people concerned because the data used is limited and technical.
- To improve the service, using aggregated and de-identified usage statistics. Legal basis: legitimate interest in developing our product.
- To send service messages — verification, password resets, invitations, billing and material changes to this policy or our Terms. Legal basis: contract. These are not marketing and cannot be unsubscribed from while you have an account.
- To defend legal claims and comply with the law. Legal basis: legal obligation, and legitimate interest in establishing or defending claims.
For activity data processed for a customer, the legal basis is the customer to determine and document, not ours.
Cookies
We use cookies that are strictly necessary and nothing else. There is no advertising cookie, no tracking pixel, no third-party analytics script, and consequently no consent banner to click away.
- Session cookie — set when you sign in, so that the next request knows who you are. It is httpOnly, marked secure over https, and expires when the session does or when you sign out.
- Short-lived flow cookies — used during sign-in and when connecting a provider, to carry state safely between the two halves of an OAuth redirect and to return you to the page you started from.
Who we share it with
We do not sell personal data and we do not share it for anyone else marketing. We use the following sub-processors, each under a contract that binds them to protections no less protective than ours:
- Vercel Inc. — United States
- Application hosting, the network in front of it, and the background jobs that run backfills. Processes all data passing through the service.
- Neon Inc. — United States
- The managed PostgreSQL database where everything described above is stored, and its backups. Our database currently resides in a United States region.
- Stripe, Inc. and Stripe Payments Europe, Ltd. — United States and Ireland
- Payment processing, subscriptions and invoices. Stripe acts as an independent controller for payment data and holds card details; we never receive them.
- ActiveCampaign, LLC (Postmark) — United States
- Delivery of transactional email: verification links, one-time sign-in links, password resets and invitations. Receives the recipient address and message content.
- Google Ireland Limited — Ireland
- Only where you choose to sign in with Google, or where an organization connects Google Workspace. Google is an independent controller of your Google account.
We also disclose data to professional advisers under a duty of confidence, to authorities where the law requires it, and to an acquirer in the event of a merger, acquisition or sale of assets — in which case we will say so on this page before it changes anything about how the data is handled.
Customers are told about new sub-processors through this page, and may object as described in the data processing terms of our Terms of Service.
International transfers
Our hosting, database and email providers are established in the United States, so personal data is transferred outside the European Economic Area. Those transfers are made under the European Commission standard contractual clauses, supplemented where appropriate by the EU-US Data Privacy Framework where the recipient is certified under it, together with technical measures including encryption in transit and at rest. Write to us at jure@parakeet-ai.com for a copy of the relevant safeguards.
How long we keep it
- Activity data — for as long as the customer organization keeps it. An administrator can delete everything stored for a provider at any time from that provider page in the app, and that deletion is immediate and permanent.
- Organization data — until the organization is deleted. Deleting an organization removes every record belonging to it, permanently, and cancels its subscription. Nothing is archived.
- Account data — while you have an account, and for a short period afterwards to handle any dispute about it.
- Sessions and tokens — until they expire or are used; verification and reset tokens are single-use and short-lived.
- Billing records — for the period required by Slovenian tax and accounting law, generally ten years.
- Logs and backups — logs for a rolling operational window; backups for a short retention period, after which copies age out. A record deleted from the live system is deleted from backups as those backups expire.
Nothing is deleted because a subscription lapsed: non-payment pauses collection, it does not erase what has already been collected.
How we protect it
- Encryption in transit (TLS) and at rest at our hosting and database providers.
- Every read is scoped to one organization. Data never crosses that boundary, and there is no view in the product that reads across customers other than a staff dashboard restricted to a flag that has no way of being set from inside the application.
- Passwords stored only as bcrypt hashes, sessions stored server-side and revocable, rate limiting on authentication endpoints.
- Provider access uses per-organization credentials with the narrowest scopes that make the integration work, visible to the customer, and revocable by them at any time.
- Secrets held in the hosting platform, never in the codebase.
- Access to production data limited to those who need it to run the service.
No system is perfectly secure. We do not guarantee that the measures above will prevent every incident, and our liability if one occurs is governed by our Terms of Service.
Automated decision-making
We do not make decisions about anyone by automated means, and the service produces no scores, ratings, risk assessments or recommendations about individuals. Leaderboards and charts count and arrange records; they do not evaluate people. Any decision a customer takes about a person after looking at the data is theirs, taken by a human, and our Terms prohibit using the service as the sole basis for one.
Your rights
Where the GDPR applies you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to processing, to portability, and to withdraw consent where processing rests on consent. You also have the right to object at any time, on grounds relating to your particular situation, to processing we carry out on the basis of legitimate interests.
If you have an account with us
Write to jure@parakeet-ai.com. We answer within one month, extendable by two further months for complex requests, and we may ask for information to confirm your identity. Exercising these rights is free unless a request is manifestly unfounded or excessive.
If your work activity appears in a customer workspace
The organization that connected the tools is the controller, and your rights are exercised against them: they decide what is collected, they can delete it, and only they can tell you why it is being collected. If you write to us instead, we will pass your request to that organization and support them in answering it, but we cannot disclose or erase their data on our own initiative. We will not ignore you — we will tell you what we have done with your request.
Complaints
You can complain to a supervisory authority. Ours is the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si. You may also complain to the authority where you live or work. We would rather you told us first, at jure@parakeet-ai.com.
Children
The service is for organizations and their staff. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe we have, write to us and we will delete it.
Changes to this policy
We may update this policy. The date at the top says when it last changed. If a change materially affects how we handle personal data, we will tell account holders by email or in the service before it takes effect, and customers may object to a new sub-processor as described in our Terms of Service.
Contact
ParakeetAI d.o.o.
Slovenska cesta 55b, 1000 Ljubljana, Slovenia
VAT SI96761202
jure@parakeet-ai.com