Legal

Privacy Policy

Last updated — July 2026

Overview

Aiva is a local-first product. Your source code, worktrees, and agent runtime run on your own hardware. This policy describes what the Aiva cloud stores in order to provide the control plane, and the choices you have over that data.

Data the cloud stores

  • Account and workspace data — your name, email address, workspace membership, and settings.
  • Session orchestration state — session records, transcripts, queued prompts, approvals, unread and dirty state, and related metadata needed to render the control plane. Transcripts include what appeared in the session: prompts, agent messages, diffs, file excerpts, and command output.
  • Instance registrations — bridge identities and hashed API keys for machines you connect.
  • Integration configuration — source-control and project-management provider settings you add to a workspace.

Data the cloud does not store

  • Your repositories, worktrees, and git history — the cloud never mirrors or indexes your source tree. File contents are fetched on demand through the bridge when you open them, and code otherwise reaches the cloud only inside session transcripts.
  • Model and agent-runtime credentials, which remain in your local agent home.

How data is used

Stored data is used to operate the service: rendering the control plane, synchronizing state across your devices, and connecting your machines to your workspace. Aiva does not sell your data or use your session content to train models.

Retention and deletion

You can delete sessions and workspace data from the app. Deleting a session removes its stored transcript; deleting a workspace removes its stored orchestration state. Local session stores on your machines are under your control and can be removed at any time.

Contact

Questions about this policy can be raised with the operator of your Aiva deployment, or with Moltenmouse for the hosted service.