Skip to content

PRIVACY

Privacy Policy

Last updated · 2026-09-19

Koestler is a decision partner and an agent action gate. To run the service we process a small, deliberate set of data. This page lists what we collect, how long we keep it, and the controls you have over it.

What we collect

We collect only what the service needs to operate:

  • Account — your email address, handled by Supabase Auth, our authentication provider. We never see or store your password.
  • Agent activity — the action ledger and gate verdicts recorded when your agents pass through the Koestler gate.
  • Decision sessions — the messages and analyses inside your decision sessions.
  • Board images — images you add to a space board. They are re-encoded in your browser before upload (which drops embedded metadata such as location) and stored in a private Supabase Storage bucket.
  • Billing — payments are processed by Lemon Squeezy as Merchant of Record. Card details never touch our servers.

How long we keep it

Retention defaults are deliberately short:

  • Raw action payloads — 30 days.
  • Shadow-mode ledger entries — 90 days.
  • Deleted sessions — permanently erased 30 days after deletion.
  • Session summary reports — 180 days.
  • Board images — kept while a board uses them; deleted 7 days after no board refers to them, and removed with your account. Images on a deleted space stay until the space is permanently erased (30 days after deletion) and are deleted 7 days after that. Copies cached by the storage delivery network can stay reachable through links issued earlier for up to 1 hour after deletion.
  • Resolved escalation tickets — 90 days. The override decision and its reason remain permanently in the audit ledger.

Your controls

You can delete your account and export your data yourself, at any time, from the profile page — no support ticket required. Deleting your account removes your data on the schedule above.

Account data (email, plan) is kept only for as long as your account exists.

AI processing — what leaves our servers

Adversarial judging is the core of the service, and it runs on external large-language-model providers. When your agent's action goes through the gate or you run a decision session, the following is sent to OpenAI and/or Anthropic via their APIs for judging, debate, and evidence embedding:

  • Agent action context — file paths, change summaries, shell commands, and the agent's stated justification.
  • Debate text — the defenses and critical questions exchanged during a gate debate.
  • Decision session text — the messages and analyses inside your decision sessions.

This data is processed to produce verdicts and analyses, and is handled under each provider's API data policy. We do not use your data to train models, and we only use provider API tiers that are excluded from model training by default. If this data flow is not acceptable for your codebase or organization, do not connect your agents to Koestler.

Third parties

We rely on a small set of processors: Supabase (authentication, database, and board image storage), OpenAI and Anthropic (LLM judging, debate, and embeddings — see the section above), Lemon Squeezy (payments, as Merchant of Record), and Cloudflare (hosting). We do not sell your data, and we do not share it for advertising.

Where your data lives

Your account and application data are stored with Supabase in the ap-southeast-2 region (Sydney, Australia). LLM processing by OpenAI and Anthropic takes place on their infrastructure, primarily in the United States. Hosting and delivery run on Cloudflare's global network. By using the service you consent to these cross-border transfers, which are required to provide it.

Who operates Koestler

Koestler is operated by RTFM, an independent solo developer based in the Republic of Korea. Privacy inquiries and data-subject requests are handled at the contact address below and answered without undue delay.

Contact

Questions about privacy or your data? Write to support@koestler.ai