Privacy Policy
Version 1.0 · Last updated 2026-10-04
1. Overview
This Privacy Policy explains what DarkCoder.ai collects when you use https://darkcoder.ai and how it is used. Contact: hello@ajens.org.
2. What we collect
- Account data: name, email address, a salted hash of your password (if you use one), your role, and sign-in method. If you sign in with Google we receive your name, email address and profile picture URL from Google.
- Consent record: the version of the Terms and Privacy Policy you accepted, when, and the IP address used.
- Provider connections: tokens and API keys you connect are stored encrypted at rest and are used only to make requests you ask for. Account labels and quota information are stored in plain form so the cockpit can show them.
- Gateway keys: we store only a hash and the last four characters of each key, plus its name, scope, caps and usage counters.
- Request logs: for each request the gateway records time, key name, model, provider, status, latency, token counts, cost and fallback path. Prompt and response text is not kept in the logs.
- Security and audit events: sign-ins, failed sign-ins, role changes, settings changes and security reports, with IP address.
- Technical data: a session cookie, IP address and user agent for security and rate limiting.
3. Content sent to providers
When you make a request, your prompt and any attached content are forwarded to the provider that serves it (for example GitHub, Anthropic, Google, OpenAI, xAI, DeepSeek, Groq or Cognition). That provider processes the content under its own terms and privacy policy and may retain it. Choose providers accordingly. Local providers keep data on your own machine.
4. How we use data
To provide and secure the Service, authenticate you, enforce limits, show usage, send verification and invitation emails, respond to security reports, and meet legal obligations. We do not sell personal data.
5. Cookies and analytics
See the Cookie Policy. Analytics and advertising are off unless the operator enables them.
6. Sharing
We share data with: the providers you select (see section 3), our email delivery service when we send you email, our hosting infrastructure, and authorities when required by law. We do not share your data for advertising except through any ad or analytics tools described in the Cookie Policy.
7. Retention
Account data is kept while your account exists. Request logs and audit events are kept for a limited rolling period and may be wiped by the operator. Security reports are kept until resolved and for a reasonable period afterwards. Deleting your account removes your credentials, sessions and invitation tokens.
8. Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a data protection authority. Email hello@ajens.org and we will respond within 30 days.
9. Security
Secrets are encrypted at rest, sessions are signed and revocable, and access is role-based. No system is perfectly secure. If you find a vulnerability please follow our responsible disclosure policy.
10. International transfers
Providers you choose may process data in other countries. Where required we rely on appropriate transfer safeguards.
11. Changes
We will update the version and date on this page when this policy changes materially.
Last updated: 2026-10-04.