Legal
Privacy
Understand what stays local, what is sent to the cloud and the choices available to you.
Updated
Who is responsible
Asondy is a software project operated by João Marques, an independent developer responsible for the project’s handling of personal data described in this notice.
Contact: joaoagm90@gmail.com. This notice covers this website and the Asondy features described below. Where a workspace owner determines how other people’s data is used, that owner may have separate responsibilities for the content they submit.
Information handled by each feature
- Website
- These informational pages do not include advertising pixels, analytics scripts or embedded third-party fonts. A hosting service may receive normal request information such as IP address, requested URL and browser headers.
- Local integration
- The installed software reads project state and supported coding-tool session data on your machine. The local dashboard uses loopback. Installing hooks and connecting a cloud session are separate operations.
- Accounts
- Hosted authentication uses account identifiers, email and authentication records. Authentication providers receive the information required for the sign-in method you choose.
- Cloud relay
- Connected sessions can send project identity, goal text, activity, usage measurements and conversation turns. Conversation text can contain code or personal data.
- Verification
- Requests identify a repository and revision, or submit a diff and selected files in SDK mode. The service handles that content to run checks and records the result.
- Optional model routing
- When enabled, model requests pass through Asondy to the configured provider. Prompts, code and responses are subject to that provider’s data handling as well.
Purposes and legal bases
Account and feature data are used to provide the functions you request. Where GDPR applies, processing necessary to provide a service under an agreement relies on that contractual necessity. Security and abuse prevention may rely on legitimate interests, subject to your rights and the required balancing of interests. Processing required by law relies on the relevant legal obligation.
Support correspondence includes the email address, message and attachments you send. It is used to answer your request and maintain a record of its resolution. Messages sent to the contact address are handled through Gmail. Send only the information needed to explain the issue.
Consent is required where applicable for an optional processing purpose; it can be withdrawn without changing the lawfulness of earlier processing. Choosing a feature does not create blanket permission to use its content for unrelated purposes.
Automated checks and session scoring
Guards evaluate configured conditions and may block supported coding actions. The cloud implementation also computes session-risk estimates from activity and outcome measurements, and stores associated scores for calibration. These estimates are distinct from deterministic verification results.
Risk-based intervention is disabled by default in the reviewed implementation. If a deployment enables it, a high score can pause a worker, prompt additional review or suggest a retry. Treat these as signals about a coding session, not assessments of a person’s ability or suitability. Review the recorded session activity when challenging an outcome.
Uses that make legally or similarly significant decisions about people require a separate assessment of the applicable automated-decision rules and safeguards.
Recipients and international transfers
- Hosting
- The hosted website and relay run on Hetzner infrastructure in Falkenstein, Germany. Cloudflare provides the domain’s DNS service. Hetzner privacy information; Cloudflare privacy information.
- Authentication
- Asondy connects to the Asqav authentication service at api.asqav.com. Its application and account database run on the same host in Germany. A sign-in provider you choose also handles the information needed for that method.
- Correspondence
- Messages to João Marques at the contact address are handled through Google’s Gmail service. Google privacy information.
- Model providers
- Optional routing sends requests to the configured model providers. A retry after an upstream failure can send the same request to another configured provider. Their processing locations and policies depend on the provider used.
A workspace owner may control who can view a shared session. Content may also be disclosed where a valid legal obligation requires it. Hosting in Germany does not mean every recipient processes data only in the EU. Where GDPR transfer rules apply, international transfers require an applicable legal mechanism, such as an adequacy decision or appropriate safeguards. Contact João Marques for information about recipients and safeguards relevant to your use. Read the EDPB guidance on international transfers.
Retention and deletion
- Verification files
- Temporary job files are removed when the verification queue completes or handles a failure. An abrupt host or process failure can interrupt cleanup. Verification results are stored separately.
- Dashboard measurements
- The hosted relay runs hourly cleanup for time-series points older than 24 hours, and usage rows and saved relay-session metadata older than seven days. Saved session metadata can include the goal text you send. These are periodic deletion thresholds, not exact expiry times.
- Remote commands
- Pending remote-command payloads expire after five minutes. They are removed from the active queue after the connector confirms local storage, rejects the command, or a legacy connector attempts delivery. Body-free delivery acknowledgements and a command fingerprint are retained for about 24 hours after delivery ends for retries. Status events do not include instruction text. An acknowledgement confirms local storage, not execution by the coding agent. Instructions stored on your computer remain there until consumed or removed locally.
- Session content and other records
- Live relay buffers have size limits and inactive sessions are removed. Check and review records, account and workspace records, saved workflow state, savings measurements and risk-calibration records have separate storage and no shared automatic expiry. They are reviewed when handling a deletion request, considering the service still in use, unresolved security incidents and any legal retention requirement. Ending a session does not erase these records.
- Backups
- The authentication database is backed up daily on the same host. Successful backup runs rotate copies once they are at least eight days old. A failed backup run can delay rotation. Removing a record from the active database does not immediately remove it from an existing backup. This schedule describes database backups, not a guarantee covering every infrastructure snapshot.
- Correspondence and local files
- Support messages are kept while the request remains unresolved and as needed to document its resolution or meet a legal obligation. Local project files and coding-tool transcripts remain under their local owner’s control.
For account closure or deletion, email joaoagm90@gmail.com. The hosted self-service deletion endpoint is not enabled. Requests are handled individually after identity verification and cover the relevant active records, separately retained check records and backup restrictions. Any records that must be retained, the reason and applicable deletion timing will be explained in the response.
Cookies and similar technologies
This informational website does not set analytics or advertising cookies through its page scripts. Hosted sign-in is a separate application and uses authentication and security cookies. Strictly necessary cookies can have different consent requirements from optional tracking; adding analytics would require a fresh assessment and, where required, prior consent. Read the EU guidance on cookies.
Your choices and rights
You can use the local integration without enabling optional model routing. Stop a cloud connection to stop its live stream. For access, correction or deletion of hosted personal data, contact joaoagm90@gmail.com and identify the account or workspace concerned. Do not include API keys or passwords.
Where GDPR applies, you may have rights of access, correction, erasure, restriction, portability and objection, depending on the processing. You can also complain to the competent data protection authority. Requests generally require a response within one month. Complex requests may qualify for up to two additional months, with notice in the first month. Reasonable identity verification and other lawful exceptions can apply. Read the EDPB guide to your rights.
Shared workspaces and sensitive information
If you connect a workplace repository, confirm your authority and inform the people whose data may appear in transcripts. Where Asondy processes personal data on an organization’s instructions, an appropriate data-processing agreement and verified provider arrangements are required. This notice does not replace that agreement.
Asondy is intended for coding workflows. Keep passwords, API keys and unnecessary sensitive personal information out of prompts and support messages. Redaction of credential fields does not reliably remove secrets embedded in ordinary text.
Changes to this notice
Changes to features or data handling may require an updated notice. Material new processing must be explained before it begins where applicable law requires that notice.