← Back to Eigon

Privacy Policy

Last updated 15 August 2026

Draft pending legal review. Written to match how Eigon actually works; not a substitute for advice from a qualified lawyer.

This policy describes what Eigon collects and why. It is written to match what the product actually does — if you find something here that does not match our behaviour, that is a bug and we want to hear about it at info@eigon.io.

1. What we collect

DataWhy
Email address and nameTo create your account, sign you in, and send deployment and billing notices.
Organisation and project namesTo structure your workspace.
Your source code and build outputTo build and run your application. Retrieved from your connected Git provider or uploaded by you.
Environment variables and secrets you provideTo supply them to your running containers. Stored encrypted and never shown back in full once saved.
Deployment, build and application logsTo show you what happened and diagnose failures.
Infrastructure and cost metricsTo display usage, enforce spending caps, and bill accurately.
Billing detailsHandled by our payment processor. We store the plan, invoices and whether a payment method exists — we never receive or store full card numbers.
Approximate location from your IPTo suggest a nearby deployment region. Derived from request headers; we do not build a location history.

2. What we do not do

  • We do not sell personal data.
  • We do not use your source code or data to train machine-learning models.
  • We do not run advertising or third-party ad trackers on the product.

3. Automated analysis of failures

When a deployment fails, Eigon analyses the build output and relevant configuration to explain the failure and suggest a fix. Some of that analysis uses a third-party AI provider, which means the excerpt being analysed — which can include fragments of your code or logs — is sent to that provider for processing. It is not used to train their models. If you would rather this never happen for your account, contact us and we will disable it.

4. Who we share it with

We use these processors, and only for the purpose listed:

  • Amazon Web Services — hosting, storage, email delivery, and the infrastructure your applications run on.
  • Our payment processor — subscriptions and payments.
  • Datafast — website and product analytics, as described in section 10.
  • Anthropic — failure analysis and fix suggestions, as described above.
  • Your connected Git provider — only to read the repositories you authorise and, if you ask, to open a pull request.

We may also disclose data where legally required, or to protect the Service and its users from harm.

5. Where it is stored

Our control plane runs in AWS in the United States. Your applications run in the region you choose, which may be elsewhere. Transfers out of the UK/EEA rely on the appropriate safeguards, including standard contractual clauses where applicable.

6. How long we keep it

  • Account data: while your account exists, and for a short period afterwards.
  • Build and deployment logs: retained on a rolling window (3 days for dev environments, 30 for production) and then deleted.
  • Invoices and billing records: as long as tax and accounting law requires.
  • Your code and deployed data: deleted with the environment, subject to any snapshot retention shown in the dashboard.

7. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. Email info@eigon.io and we will respond within the period the applicable law requires. Deleting your account deletes the environments and data attached to it.

8. Security

Secrets are encrypted, tenant environments are isolated at the network layer, and access to production is restricted. Details are on our Security page. No system is perfectly secure; if we discover a breach affecting your personal data we will notify you and any regulator as the law requires.

9. Cookies

Two are needed for the product to work: a session token so you stay signed in, and a short-lived state cookie during sign-in with a Git provider to prevent request forgery.

One more is set by our analytics, described in section 10. It stores a random identifier so that repeat visits are counted as one person rather than several. It is a first-party cookie, set on our own domain, and it cannot follow you to other sites. It is readable by our analytics provider (section 10), which is what it is for; it is not sold, and it carries no advertising identifier.

We do not set advertising or cross-site tracking cookies.

10. Product analytics

We measure how the site and the dashboard are used, so we can tell which pages are read, which steps people abandon, and where our own product is confusing. For each visit we record the pages viewed, the links and buttons pressed, the page you left from, the site or campaign that referred you, your country, and your browser and device type. Your country is derived from your IP address; we do not store the address itself as part of these records.

Some of this is measured by Datafast, an analytics provider, which means those visit records are sent to a company other than us. It receives the pages you viewed, the referring site, and your country and device type. The rest runs on our own servers, in our own AWS account. We do not sell this data, we do not send it to an advertising network, and it is not used to build a profile of you across other sites.

Three things we deliberately do not collect. We do not record what you type: field contents are never captured, which matters because the dashboard holds environment variables and cloud credentials. We do not record your screen — no session replay or video of your visit. And we remove identifiers from the addresses we store, so a page recorded as /dashboard/org/:orgId/project/:projectId does not carry which organisation or project you were looking at, and one-time links such as invitations have their token stripped before anything is written down.

While you are signed in, these records are linked to your account, which is how we can tell that one person read the pricing page and later deployed something. Signing out unlinks them.

There is no cookie banner because there is nothing here to consent to beyond what is described above: no advertising, no third parties, no cross-site tracking. If you would prefer not to be measured at all, any browser content blocker or a Do Not Track setting will stop it, and you can also ask us to delete your records using the contact details at the end of this page.

11. Children

The Service is not directed at children and we do not knowingly collect their data.

12. Changes

We will post updates here and, for material changes, notify you by email or in the dashboard.

13. Contact

Privacy questions and data requests: info@eigon.io.