Privacy Policy
Effective date: September 1, 2026 Version: v1.3
1. Who We Are and What This Covers
This Privacy Policy explains how Colorful Aura Inc. ("Poly," "we," "us") collects, uses, and shares information through the Poly web application at usepoly.co (the "Service"). It applies to account holders and to anyone invited into a Poly room.
2. Information We Collect
Account information (from you, when you sign up or edit your profile): email address, password hash, unique handle, optional bio, optional GitHub username, optional avatar image, timezone, email-verification status, and optional 2FA settings.
Repo tokens (from you, if you connect a GitHub repository): any GitHub personal access token you supply. These are encrypted at rest using AES-256-GCM and are only decrypted at the moment we need to sync one of your repos. We're being direct about this: because decryption happens on our servers, our service — and by extension, people who operate it — can technically access these credentials at the point of use. We recommend a fine-grained token scoped to just the repositories you connect.
You do not give us an Anthropic or OpenAI API key — AI turns run on Poly's own provider accounts. (Under the earlier bring-your-own-key model, accounts created before August 3, 2026 could store an Anthropic API key with us; all such stored keys were deleted from our systems on August 3, 2026.)
Room content (from you and your invitees, as you use the Service): chat timelines, AI agent replies, tool/command activity, group chat and threads, polls, reactions, read receipts, uploaded files (both workspace files and files shared in chat), and git history of your hosted workspace, including per-user commit attribution.
Usage and operations data (collected automatically): session cookies (we store session tokens hashed, not in plain text), IP addresses (used for rate limiting and kept in server logs), turn receipts and per-turn usage records (duration, model used, and the underlying AI cost of each turn you run — we record this per account to operate the Service and enforce beta usage limits), sandbox/network egress failure logs, and, if you opt in, web-push notification subscriptions.
How you found us (collected automatically, once, when you create an account): the site that referred you (we keep only the site and page — for example www.reddit.com/r/SideProject — and deliberately discard that site's query string, which can contain search terms or identifiers) and any utm_source / utm_campaign tags on the link you followed. We record this once at signup to understand which places people hear about Poly from. It is never updated afterwards and is visible only to Poly's administrators.
Billing information (from you, if you subscribe or buy credits): your purchases are processed by Stripe — your card number never touches our servers. Stripe sends us, and we store, your Stripe customer reference, which plan you're on, your purchase history (what you bought, when, for how much), and your current credit balance. Payment details, invoices, and receipts live with Stripe.
Landing-page analytics (collected automatically, signed-out visitors only): our public landing page loads Cloudflare Web Analytics, which reports aggregate page views and referrers (for example, "N visitors arrived from Product Hunt"). It is cookieless, sets no identifier, and does not track you across sites. It runs only on the signed-out marketing page — once you're signed in, no page view or in-app activity is sent to it, and everything we measure about product usage stays in our own database.
Beyond that, we run no advertising trackers and no other third-party analytics.
3. Why We Collect It, and Our Legal Basis
| We use it to... | Which data | Legal basis (GDPR) | |---|---|---| | Run the Service and your account | Account info, session/usage data | Contract (necessary to provide the Service) | | Run the AI turns you request, on our provider accounts (Anthropic or OpenAI, depending on the model) | Prompts, workspace contents, conversation history | Contract; performed at your direction | | Meter usage and maintain your credit balance | Per-turn usage/cost records, purchases, credit balance | Contract (billing is part of providing the Service) | | Understand which channels bring people to Poly | Referring site and campaign tags, recorded once at signup | Legitimate interest in knowing how our own service is found | | Enable multiplayer rooms | Room content shared with invited members | Contract; legitimate interest in enabling the core product | | Secure the Service and prevent abuse | IP addresses, session data, logs | Legitimate interest | | Communicate with you (verification, resets, invites) | Email address | Contract; legitimate interest | | Send optional push notifications | Push subscription | Consent (opt-in) |
If you're in the EU or UK, you also have rights described in Section 6.
4. How We Share Information
Other room members. Poly is a multiplayer product by design. Anything you post or upload into a room — prompts, AI replies, code, chat, files, polls, approval decisions — is visible to everyone in that room. This includes group chat and threads: those are hidden from the AI agent, but they are not private from the Service — they're stored, unencrypted, in our database, and visible to room members.
Service providers (subprocessors). We share data with vendors who help us run Poly, limited to what each needs to do its job:
- Anthropic — receives your prompts, relevant workspace contents, and conversation history to run AI turns on Claude models, under Poly's own Anthropic account (you don't need one).
- OpenAI — receives your prompts, relevant workspace contents, and conversation history to run AI turns on GPT models, under Poly's own OpenAI account (you don't need one). Which provider a chat turn's data goes to depends on the model chosen for that turn. Image generation is the exception: images are always generated by an OpenAI model, so when the agent generates an image — in any turn, including one running on a Claude model — the image prompt goes to OpenAI.
- DigitalOcean — our hosting provider; servers located in the United States.
- Stripe — processes subscription and credit-pack payments. Card details go directly to Stripe; we receive a customer reference and purchase records, never card numbers.
- Cloudflare — runs Turnstile bot-detection on signup and password-reset (processes some visitor/browser data for that purpose), provides cookieless Web Analytics on our public landing page (aggregate page views and referrers from signed-out visits only), and hosts our encrypted offsite backups (R2).
- Resend — sends transactional email: verification codes, 2FA codes, invites, and password resets.
- Google — if you choose to sign in with Google, handles that OAuth sign-in flow.
- GitHub — only if you connect a repo or list a GitHub username on your profile; commit attribution uses GitHub's public no-reply email addresses.
- Apple, Google, and Mozilla push services — only if you opt into browser push notifications.
Legal compulsion. We may disclose information if required by law, subpoena, or other legal process, or to protect the rights, safety, or property of Poly, our users, or others.
Business transfers. If Poly is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction; we'd notify you of any resulting change to this policy.
We do not sell personal data, and we do not share it for targeted advertising.
5. Where Data Is Processed and How Long We Keep It
Location. Our servers are located in the United States. If you're using Poly from outside the US, your information will be transferred to and processed in the US.
Retention:
- Account data: kept while your account is active.
- Room content: kept until the room or account is deleted.
- Offsite backups: retained on a rolling basis, roughly 30 days, then aged out.
- Logs: kept for a brief operational window, then deleted.
Deleting content removes it from the live system immediately. Because of how backups work, it may still exist in an offsite backup until that backup rotates out — typically within about 30 days.
6. Your Rights
You can access, correct, delete, or export your data by contacting us at support@usepoly.co. You can also sync your code out to your own GitHub at any time — you're never locked into Poly for your own content.
If you're in the EU/UK: you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. You also have the right to lodge a complaint with your local data protection supervisory authority.
If you're a California resident: you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of the sale or sharing of personal information — which, as noted above, we don't do.
7. Security
We take reasonable steps to protect your information, including: TLS encryption in transit, AES-256-GCM encryption at rest for repo tokens, hashed (not plaintext) session tokens, sandboxed AI execution with network egress allowlists (AI turns never see Poly's platform credentials), optional two-factor authentication, and encrypted offsite backups.
No system is perfectly secure, and we can't guarantee absolute protection against all threats. Internally, access to your data is limited to what's needed to operate, maintain, and debug the Service.
8. Cookies and Local Storage
We use only strictly necessary cookies — for session authentication — plus a browser localStorage entry for your theme preference. We don't use advertising or analytics cookies: our landing-page analytics (Section 2) is cookieless and stores nothing on your device. That's why we don't show a cookie consent banner.
9. Children
Poly is not directed to, and is not intended for, anyone under 18. If we learn an account belongs to someone under 18, we'll delete it.
10. Breach Notification and Policy Changes
If we experience a data breach affecting your information, we'll notify you as required by applicable law. We'll announce changes to this policy by email and/or in-app notice; material changes will require you to re-accept the policy to continue using the Service.
11. Contact Us
Colorful Aura Inc. 2388 Ocean Ave Ste MO Brooklyn, NY 11229 support@usepoly.co (754) 703-8553
For data access, correction, deletion, or export requests, or any privacy questions, reach us at the email above.