Privacy Policy
Last updated 15 August 2026
Draft pending legal review. Written to match how Eigon actually works; not a substitute for advice from a qualified lawyer.
This policy describes what Eigon collects and why. It is written to match what the product actually does — if you find something here that does not match our behaviour, that is a bug and we want to hear about it at info@eigon.io.
1. What we collect
| Data | Why |
|---|---|
| Email address and name | To create your account, sign you in, and send deployment and billing notices. |
| Organisation and project names | To structure your workspace. |
| Your source code and build output | To build and run your application. Retrieved from your connected Git provider or uploaded by you. |
| Environment variables and secrets you provide | To supply them to your running containers. Stored encrypted and never shown back in full once saved. |
| Deployment, build and application logs | To show you what happened and diagnose failures. |
| Infrastructure and cost metrics | To display usage, enforce spending caps, and bill accurately. |
| Billing details | Handled by our payment processor. We store the plan, invoices and whether a payment method exists — we never receive or store full card numbers. |
| Approximate location from your IP | To suggest a nearby deployment region. Derived from request headers; we do not build a location history. |
2. What we do not do
- We do not sell personal data.
- We do not use your source code or data to train machine-learning models.
- We do not run advertising or third-party ad trackers on the product.
3. Automated analysis of failures
When a deployment fails, Eigon analyses the build output and relevant configuration to explain the failure and suggest a fix. Some of that analysis uses a third-party AI provider, which means the excerpt being analysed — which can include fragments of your code or logs — is sent to that provider for processing. It is not used to train their models. If you would rather this never happen for your account, contact us and we will disable it.
4. Who we share it with
We use these processors, and only for the purpose listed:
- Amazon Web Services — hosting, storage, email delivery, and the infrastructure your applications run on.
- Our payment processor — subscriptions and payments.
- Anthropic — failure analysis and fix suggestions, as described above.
- Your connected Git provider — only to read the repositories you authorise and, if you ask, to open a pull request.
We may also disclose data where legally required, or to protect the Service and its users from harm.
5. Where it is stored
Our control plane runs in AWS in the United States. Your applications run in the region you choose, which may be elsewhere. Transfers out of the UK/EEA rely on the appropriate safeguards, including standard contractual clauses where applicable.
6. How long we keep it
- Account data: while your account exists, and for a short period afterwards.
- Build and deployment logs: retained on a rolling window (3 days for dev environments, 30 for production) and then deleted.
- Invoices and billing records: as long as tax and accounting law requires.
- Your code and deployed data: deleted with the environment, subject to any snapshot retention shown in the dashboard.
7. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. Email info@eigon.io and we will respond within the period the applicable law requires. Deleting your account deletes the environments and data attached to it.
8. Security
Secrets are encrypted, tenant environments are isolated at the network layer, and access to production is restricted. Details are on our Security page. No system is perfectly secure; if we discover a breach affecting your personal data we will notify you and any regulator as the law requires.
9. Cookies
We use only what the product needs to function: a session token so you stay signed in, and a short-lived state cookie during sign-in with a Git provider to prevent request forgery. We do not set advertising or cross-site tracking cookies.
10. Children
The Service is not directed at children and we do not knowingly collect their data.
11. Changes
We will post updates here and, for material changes, notify you by email or in the dashboard.
12. Contact
Privacy questions and data requests: info@eigon.io.
