Privacy Policy

What changed: Sub-processors are now maintained in one place at /legal/subprocessors, retention states the periods we have actually committed to, and the newsletter and consent disclosures were corrected.

Kosuke is a B2B AI coding platform. Organizations connect GitHub repositories, collaborate through chat, and use AI-assisted workflows to generate, review, and ship code changes. This Privacy Policy explains how Kosuke, Inc. ("Kosuke", "we", "our", or "us") collects, uses, stores, and shares personal data when you use kosuke.ai, app.kosuke.ai, preview environments we create for you, and related services.

1. Who We Are

Kosuke, Inc.
1111B S Governors Ave # 54640, Dover, DE 19904
privacy@kosuke.ai

2. Scope

This policy covers both our public website and the Kosuke product. Because Kosuke is a repository-connected AI coding platform, the data we process can include account data, organization data, repository information, prompts, generated output, previews, attachments, and operational telemetry.

3. Our Role

When we process customer workspace content such as repositories, prompts, code, attachments, and project data in order to provide the service, we act as a service provider or processor on behalf of the customer organization.

When we process website usage data, account and authentication data, security and fraud-prevention data, support communications, and our own operational or business records, we act as a controller.

4. Data We Process

We may process the following categories of personal data and customer content:

  • Account and authentication data, such as name, email address, profile details, authentication identifiers, and session information.
  • Workspace and organization data, such as organization name, membership, roles, invitations, and administrative settings.
  • GitHub and project data, such as connected repository details, repository metadata, webhook events, branch and pull request information, and related project configuration.
  • Repository contents and code processed in the service, including source code and related files processed in sandbox or preview environments in order to provide the service.
  • Chat and generated-output data, such as prompts, instructions, assistant responses, generated code, diffs, and conversation history.
  • Uploaded files and attachments, including files, images, and documents submitted through the product.
  • Preview, sandbox, and deployment data, such as preview environment identifiers, runtime state, logs, and deployment-related metadata.
  • AI-provider configuration and credentials, such as selected provider settings and encrypted API credentials where an organization chooses to store them with Kosuke.
  • Usage, diagnostics, and analytics data, such as IP address, browser and device information, feature usage, crash data, logs, telemetry, and error-monitoring data.
  • Website and communications data, such as demo requests, waitlist submissions, and support communications.
  • Investor deck analytics, collected when you open the password-protected investor deck. We record the email address you enter to request access, a hashed version of your IP address, your browser user agent, the referring page, and which slides you viewed and for how long.
  • Newsletter and signup data, such as email address, name, company website, role, the page or campaign the signup came from, a record of your acceptance of our Terms, and the timestamps of your confirmation and any later unsubscribe. When you submit a signup form we also store a hashed version of your IP address in order to rate limit the form, and we send a notification of the signup to our internal Slack workspace.

5. How We Use Data

We use personal data to:

  • authenticate users and manage accounts, workspaces, and permissions;
  • connect repositories and operate repository, sandbox, preview, and AI-assisted product workflows;
  • store chat history, attachments, generated output, and related project state so users can continue working across sessions;
  • process prompts, repository context, and attachments with AI providers and related systems used to operate the service;
  • monitor performance, investigate incidents, prevent abuse, troubleshoot issues, and improve the service;
  • communicate with users about the service, onboarding, demos, support, and updates; and
  • comply with legal obligations, enforce our terms, and protect our users, systems, and rights.

6. AI Processing and Model Providers

We do not train on your code or on agent transcripts. Customer workspace content, including repository contents, prompts, attachments, chat history, agent transcripts, and generated output, is not used to train Kosuke models and is not supplied to any third party to train theirs.

Agent transcripts are also not used for internal evaluation, benchmarking, or model tuning.

When we send prompts, repository context, attachments, or related output to third-party AI providers in order to provide AI features, those providers process that data under their own terms and technical controls. Where Kosuke controls the provider relationship, we use business or API offerings and enable zero data retention where the provider makes it available. Provider-specific data use practices, retention periods, and available opt-out or zero-retention controls vary by provider and by configuration.

If your organization configures its own AI provider credentials, your organization is responsible for reviewing the provider's terms, retention practices, and any available data-use controls. Kosuke does not currently offer a single in-product switch that overrides every provider's own retention or model-training policy.

7. Legal Bases for Processing

We rely on one or more of the following legal bases:

  • Contract: when processing is necessary to provide the service or respond to requests.
  • Legitimate interests: when we secure the platform, prevent abuse, investigate incidents, maintain logs, and improve reliability and product quality.
  • Consent: when we rely on cookie consent for optional analytics, diagnostics, or marketing technologies, or where you opt into certain communications.
  • Legal obligation: when we must retain or disclose data to comply with applicable law.

8. Service Providers and Sub-processors

We rely on third-party providers to run the service. There is one authoritative list rather than two: /legal/subprocessors names every Sub-processor that may process customer Personal Data, with its purpose, its location, and the transfer mechanism that applies to it. That page is maintained as the single source of truth, and this policy deliberately does not repeat the names, so the two can never drift apart. We provide at least 30 days advance notice before engaging a new Sub-processor, as set out in our Data Processing Agreement.

The categories of provider we use for the product are:

  • Authentication and workspace management, handling account identifiers, authentication data, session data, and workspace membership.
  • Repository integration, handling connected repository metadata, webhook events, and branch and pull request information.
  • Sandbox, preview, and hosting infrastructure, which builds and runs your code and therefore processes repository contents and anything present in them.
  • Storage and databases, holding attachments, project records, and the operational data needed to run the platform.
  • AI inference providers, processing prompts, repository context, attachments, and generated output in order to provide AI features.
  • Error monitoring and observability, processing crash diagnostics, logs, traces, and operational telemetry.
  • Email delivery, processing recipient addresses and delivery records.

The public marketing site at kosuke.ai uses a separate and smaller set of providers, none of which receive customer workspace content: Cookiebot for consent management, Amazon SES for newsletter delivery, Slack for internal notification of signups, and Reddit, X, and Meta for conversion measurement. These are described in our Cookies Policy.

9. Cookies and Analytics

Cookiebot is the consent manager used on Kosuke properties where cookie consent is enabled. Optional analytics, diagnostics, and marketing technologies do not run until the matching consent category is granted.

  • On kosuke.ai, the site runs no analytics of its own. The only optional technologies are the Reddit, X, and Meta marketing pixels, and they stay blocked until you grant marketing consent.
  • On app.kosuke.ai, client-side analytics and diagnostics are enabled only after the relevant consent is available through Cookiebot.
  • On kosuke.ai, you can reopen the banner and change or withdraw consent at any time using the Cookie settings link in the site footer.
  • On app.kosuke.ai, signed-in users can manage, change, or withdraw consent through Cookiebot in the product, including from Settings > Security.

See our Cookies Policy for the full list and the categories each tool falls under.

10. Retention

We retain data for as long as reasonably necessary to provide the service, secure the platform, comply with legal obligations, resolve disputes, and enforce our agreements.

One period is already committed and binding: on termination, or on deletion of an account or workspace, Personal Data is returned or securely destroyed within 30 days, under Section 7 of the Data Processing Agreement.

The per-category periods below are being finalised. Until each one is confirmed, this policy states that it is outstanding rather than giving a figure we cannot stand behind.

Category Retention period
Repository contents processed in the service To be confirmed
Sandbox and preview contents To be confirmed
Agent transcripts and chat history To be confirmed
Application and security logs To be confirmed
Backups To be confirmed
Newsletter subscribers To be confirmed, see below

Two related periods are already fixed by how the systems work:

  • Newsletter suppression records. An address submitted but never confirmed is kept as an unconfirmed record and is never sent a campaign. An address that unsubscribes, hard bounces, or reports spam is kept as a suppression record for as long as we operate the list, because that record is precisely what stops us from mailing it again.
  • Signup rate-limiting records. A hashed IP address, kept for a 10 minute window and cleared automatically once the window has passed.

Source repositories remain in your own GitHub account throughout and are never subject to our retention periods, because they are never ours.

Limited copies of certain data may remain in backups, logs, or security records for a limited period after deletion.

11. Deletion Requests, Termination, and Privacy Rights

Depending on your location, you may have rights to access, correct, delete, port, restrict, or object to certain processing, and to withdraw consent for optional processing.

Kosuke currently supports deletion and privacy requests through product workflows and support processes, including:

  • account deletion requests;
  • workspace or organization deletion by authorized administrators;
  • removal of stored AI-provider credentials and related configuration; and
  • cleanup of related application and infrastructure resources where applicable.

When an account or workspace is deleted or a customer relationship ends, the following general lifecycle applies:

  • source repositories remain in the customer's GitHub account or other external systems under the customer's control;
  • branches, pull requests, commits, or other artifacts already created in customer-controlled repositories remain in those repositories until the customer deletes them;
  • chat history, attachments, generated output, project metadata, and other records stored in Kosuke production systems are deleted or destroyed within the 30 day window committed in Section 7 of the Data Processing Agreement, subject to any retention required by law;
  • sandbox, preview, and related temporary resources are removed under our normal cleanup processes; and
  • limited copies may remain in backups, audit trails, and security logs for a limited period where needed for resilience, fraud prevention, legal compliance, or dispute resolution.

Customers should export or retain any data they need before requesting workspace deletion or termination. Export and retrieval options may vary by data type and workflow.

We may retain limited data after deletion where necessary for backups, security, fraud prevention, legal compliance, or dispute resolution.

To exercise privacy rights or request deletion assistance, email privacy@kosuke.ai.

12. Security

We use technical and organizational safeguards designed to protect personal data and customer content, including access controls, transport encryption, encrypted storage of supported credentials, and secured file storage.

In the event of a personal data breach affecting your data, we will notify affected customers without undue delay and in any event within 72 hours of becoming aware, in accordance with GDPR Article 33 and Section 6.2 of the Data Processing Agreement.

For details on our security posture — encryption, access controls, sub-processors, certifications status, and how to report a vulnerability — see our Security page.

13. International Transfers

Kosuke and our providers may process data in the United States, the European Union, and other jurisdictions where our providers operate. Where Personal Data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, the transfer is governed by the Standard Contractual Clauses, the UK International Data Transfer Addendum, or the equivalent Swiss mechanism, as set out in Section 5 of our Data Processing Agreement. The mechanism that applies to each Sub-processor is listed at /legal/subprocessors.

14. Changes to This Policy

We may update this Privacy Policy to reflect changes to the product, our providers, our legal obligations, or our operational practices. When we do, we will update the date associated with this policy.

15. Contact

For privacy questions, support, or deletion requests, contact privacy@kosuke.ai. You can also review our Terms and Conditions and Cookies Policy.