Legal / afk.watch

Privacy policy

Last updated: August 28, 2026

1. Who we are

afk.watch (“we”, “us”, “our”) operates from Sweden and is the controller for personal data processed through the Service. We process personal data under Swedish and EU law, including the General Data Protection Regulation (GDPR). Contact us at privacy@afk.watch.

2. Data we collect

Account data. When you sign in with GitHub, we receive identifiers and profile information made available by GitHub and Supabase, which may include your GitHub user ID, username, name, avatar, and email address. We store an encrypted GitHub access token so the Service can read issues and manage labels on repositories you choose.

Repository and issue data. We store the repositories you choose to watch and fetch issue metadata needed to display and run your approved queue, such as repository name, issue number, title, body, labels, and URL.

Agent-run data. A run contains an issue identifier, title, repository, agent name, status, one latest progress line, a final Markdown report, and timestamps. We deliberately do not store full agent logs or a copy of your source-code repository.

AFK session data. We store a small session summary needed to coordinate an explicitly started queue: chosen agent, state, current run, outcome counts, and timestamps. The coding client and source checkout run locally on your Mac.

Notifications and communications. We store push tokens, device platform, notification preferences, pending digest records, push-delivery receipts, and whether an onboarding reminder was sent. If you request a setup link or receive a transactional reminder, we use your email address to send it.

Credentials and billing. Reporting API keys are stored as one-way hashes with a short identifying prefix; the raw key is shown when issued and stored locally when you connect the desktop app. If paid plans are offered, Stripe or an app store processes payment details. We receive subscription and transaction status but do not store full card details.

Technical data. Our infrastructure may process IP address, request metadata, device and app information, crash or error details, and security events needed to operate and protect the Service. Operational events are designed not to contain run payloads or credentials.

3. Why we use your data

PurposeGDPR legal basis
Authenticate you and provide the apps, run feed, GitHub queue, local AFK sessions, and notificationsPerformance of our contract (Art. 6(1)(b))
Process subscriptions and send requested or service-related communicationsContract (Art. 6(1)(b)) and legal obligations (Art. 6(1)(c))
Secure, troubleshoot, prevent abuse, and improve reliabilityLegitimate interests (Art. 6(1)(f))
Maintain tax, accounting, and other required recordsLegal obligation (Art. 6(1)(c))

We do not sell personal data, use it for third-party advertising, or use private run reports to train AI models.

4. Retention

When you request account deletion, we delete or anonymise account-linked personal data within 30 days unless law requires retention. Data may remain briefly in encrypted backups until those backups rotate.

5. Service providers and disclosures

We share data only as needed with processors and platforms that operate the Service:

ProviderPurpose
SupabaseGitHub-backed authentication and database hosting
CloudflareAPI hosting, edge networking, security, and operational logs
GitHubAuthentication and repository, issue, label, branch, and draft pull-request operations you authorise
Expo, Apple, and GoogleMobile app delivery and push notifications
ResendTransactional email
Stripe and app storesSubscription and payment processing, when applicable
Your chosen coding-agent providerRuns code locally under the provider account and terms you configure; afk.watch does not receive that provider’s credentials

We may also disclose information when required by law, to protect rights and safety, or as part of a business transaction subject to appropriate safeguards. Providers may process data outside the EU/EEA. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses, or another lawful safeguard.

6. Local processing and device permissions

The desktop companion stores repository-to-folder mappings and the effective reporting key on your Mac. It starts supported coding clients against local checkouts only after you confirm an AFK session. The mobile app requests notification permission and stores its session using platform-appropriate local storage. Your operating system and coding clients govern access to local files and device data.

7. Cookies and similar storage

The public legal and download pages do not use advertising or analytics cookies. The advanced setup page and applications use necessary local storage or secure device storage to maintain authentication and settings. Infrastructure providers may set strictly necessary security cookies.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a portable copy of your personal data; object to processing based on legitimate interests; and withdraw consent where processing relies on consent. You may also complain to a data-protection authority.

To exercise a right, email privacy@afk.watch. We may need to verify your identity and will normally respond within one month.

9. Security

We use reasonable technical and organisational safeguards, including TLS in transit, access controls, row-level database security, one-way hashing for reporting keys, and encryption at rest for GitHub tokens. No system is completely secure, so keep your devices, GitHub account, coding-client credentials, and reporting key protected.

10. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data. Contact us if you believe a child has provided personal data.

11. Changes to this policy

We may update this policy as the Service or law changes. We will revise the date above and provide reasonable advance notice of material changes through the Service or by email when available.

12. Complaints and contact

Contact privacy@afk.watch with privacy questions or requests. You may lodge a complaint with your local authority or with Sweden’s supervisory authority, Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden.

See also our Terms of use.