Skip to main content
Nightgauge
  • Pipeline
  • Guardrails
  • Intelligence
  • Enterprise
  • Screenshots
  • Roadmap
  • FAQ
  • GitHub
  • Get Early Access
Privacy

Privacy Policy

Effective August 29, 2026 · Entity: Edibu, LLC · Privacy · Terms

This Privacy Policy explains what information Edibu, LLC (“Edibu”, “we”, “us”) collects when you use Nightgauge, why we collect it, and the choices you have. It covers:

  • the website at nightgauge.dev, including the early-access and support forms;
  • the Nightgauge VS Code extension, CLI and SDK (the “local core”), which are open source under the Apache 2.0 license;
  • the optional Nightgauge hosted platform at api.nightgauge.dev, and the web dashboard and mobile app that connect to it (together, the “Platform”).

The short version: the local core runs on your machines and sends us nothing unless you sign in or add a license key. Your source code, prompts and credentials never leave your machine through Nightgauge. What we do collect is listed below, field by field, and you can turn all of it off.

1. Information the local core handles

The extension, CLI and SDK read your repository, your issue tracker and your AI provider accounts on your behalf, on your machine. That data is processed locally and sent directly from your machine to the providers you configure (your git forge, your model provider, your chat workspace). Edibu does not sit in the middle of those connections and does not receive that data.

Credentials you enter into Nightgauge (forge tokens, model API keys, chat bot tokens, license keys) are stored in your operating system’s secure credential store via VS Code’s secret storage. They are redacted from logs, from the settings view and from every notification the pipeline sends.

2. Product telemetry

The extension can send pipeline telemetry to the Platform. Telemetry is on by default and you are asked on first activation whether to keep it on; you can turn it off at any time in Settings (nightgauge.telemetry.enabled), and VS Code’s global telemetry-off setting is honored as a hard stop. No telemetry is uploaded unless you have signed in or added a license key — a plain community install sends nothing.

When enabled, telemetry contains:

  • stage outcomes, duration buckets and token/cost counters for each pipeline run;
  • the pipeline outcome category, issue size and issue type;
  • the repository slug (owner/name) and issue number, used as correlation keys so that runs can be listed in the dashboard and mobile app;
  • pipeline health snapshots, recommendation outcomes and anonymized workflow traces (agent tree and judge verdicts, without content).

Telemetry never contains source code, file contents, diffs, prompts, model responses, secrets, branch names or commit SHAs. The complete field list, the schema and deletion instructions are published in TELEMETRY_PRIVACY.md in the open-source repository, and the code that builds each payload is public.

Telemetry is retained for 90 days and then deleted. You can request earlier deletion at any time (see § 9).

3. Platform accounts

If you create a Platform account or use a license key, we collect:

  • your name, email address and authentication identifiers (for example a GitHub account identifier when you sign in with GitHub, or a device code grant when you sign in from the mobile app);
  • team and organization membership, roles and audit-log entries of actions taken in the dashboard;
  • license state and, for paid plans, the billing records our payment processor returns to us (we never see or store full card numbers);
  • the telemetry described in § 2, associated with your account or team.

4. The website

Early-access and support forms. When you join the waitlist we store your email address (and name, if given) and add it to our launch mailing list; you can unsubscribe from any message. When you contact support we store the message and reply by email; support requests are not added to any marketing list. Both forms are protected by Cloudflare Turnstile, which may process your IP address and browser signals to distinguish people from bots.

Analytics and logs. nightgauge.dev is served by Cloudflare, which keeps standard edge request logs (IP address, user agent, requested URL) for security and abuse prevention. We may use Cloudflare Web Analytics, which is cookie-less and does not track you across sites. We do not use advertising trackers, and the site sets no cookies of its own.

5. How we use information

We use the information above to provide and operate Nightgauge; to show you your own runs, costs and history in the dashboard and mobile app; to detect and fix failures; to secure accounts and prevent abuse; to respond to support requests; to send launch and product announcements you signed up for; and to comply with law. We do not sell personal information and we do not use your telemetry or code to train AI models.

6. Sub-processors

We share data only with the service providers below, only as needed to run the product, and under contracts that restrict their use of it.

ProviderPurposeData
Cloudflare, Inc.CDN, DNS, tunnel and bot protection for the site and PlatformRequest metadata, IP address; Turnstile challenge signals
Resend, Inc.Transactional and waitlist emailEmail address, name, message content you submit
GitHub, Inc.Sign-in with GitHub; the open-source repository and discussionsAccount identifier, email; anything you post publicly on GitHub
Stripe, Inc.Payment processing for paid plansBilling name, email, payment method (held by Stripe, not by us)
Anthropic, PBC and other model providersOnly when you configure them. The local core calls the model provider you choose, from your machine, with your own key.Your prompts and repository context, sent by your machine directly to the provider under your agreement with them — never through Edibu
LiveKit, Deepgram, CartesiaVoice features, only if you enable them (preview)Audio streams and transcripts of voice sessions

Model providers and chat workspaces (Slack, Discord, Mattermost) are services you connect Nightgauge to with your own credentials. Their handling of that data is governed by their own terms and privacy policies.

We will update this table before adding a sub-processor that handles personal information.

7. Security

Credentials are held in your operating system’s secure store, never in plain files or YAML. Transport is TLS everywhere. The Platform runs behind Cloudflare with no publicly exposed origin ports. We run secret scanning, dependency scanning and static analysis on every change, and publish a security policy and a disclosure channel at github.com/nightgauge/nightgauge/security/policy (security@nightgauge.dev). No system is perfectly secure; if we learn of a breach affecting your personal information we will notify you as required by law.

8. Retention

  • Telemetry: 90 days, then deleted.
  • Platform account, team and audit data: for as long as your account exists, and up to 30 days after you delete it.
  • Waitlist and support email: until you unsubscribe or ask us to delete it.
  • Edge request logs: per Cloudflare’s retention, typically days.

9. Your choices and rights

You can turn telemetry off in Settings, disable individual streams, delete your Platform account from the dashboard, unsubscribe from any email, and uninstall the extension — which removes its local state with it.

Depending on where you live you may have the right to access, correct, export or delete personal information we hold about you, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. To exercise any right, email privacy@nightgauge.dev. We answer within 30 days and never charge for a reasonable request. We do not discriminate against you for exercising your rights.

To request deletion of your Platform account and its data specifically, see Delete Your Account & Data for what gets removed and the retention window that applies.

International visitors. Edibu is located in the United States and the Platform is hosted there. If you use Nightgauge from outside the United States your information is transferred to and processed in the United States.

10. Children

Nightgauge is a developer tool and is not directed to children under 16. We do not knowingly collect personal information from children.

11. Changes

We will post any change to this policy on this page with a new effective date and, for material changes, notify Platform account holders by email before the change takes effect.

12. Contact

Edibu, LLC · privacy@nightgauge.dev · nightgauge.dev/support

Nightgauge
Privacy Terms Sub-processors Security Changelog
© 2026 Edibu, LLC. All rights reserved. Created by Mark McCorkle.