This policy explains what Blueplane Inc. (“Blueplane,” “we,” “us”) collects, how we use it, and the choices you have. It covers the blueplane website, the blueplane web app, API, and MCP server, and the capture agent that runs on your device (together, the “Service”).
Two situations, two roles
You use blueplane through your employer’s or team’s workspace. Your organization decides to capture sessions, which devices and directories are included, who can see them, and how long they are kept. Your organization is responsible for telling you about that and for any consent your local law requires. We process your session data on your organization’s behalf and under our agreement with it. Requests to see, change, or delete that data go to your workspace admin, and we act on their instructions. The rest of this policy still describes what we collect and how we protect it.
You use blueplane on your own account, or you visit our website. We decide how your data is handled, and this policy is the full description.
What we collect
Account information. When you sign in with Google or Microsoft, we receive your name, email address, and profile picture from that provider. We do not receive your password. We also store your workspace membership and role.
Session content. The capture agent records your AI sessions on supported platforms. By default that includes prompts, model responses, tool calls, file contents, diffs, file paths, the repository and branch you are working in (including the git remote URL and working directory), the platform and model used, timestamps, and token counts. You or your workspace admin can exclude devices, directories, and repositories. Session content can include anything you put into a session, including source code and, if you do not exclude them, secrets and personal information in your files.
Device and agent information. The capture agent reports the operating system and agent version, and each device is registered under an identifier we issue, so we can show which device a session came from and keep the agent working. We also record the IP address your device or browser connects from in our security and audit logs.
Billing information. If you pay for a plan, our payment processor, Stripe, collects your card details. We do not see or store full card numbers. We keep your billing contact, plan, and invoice history.
Website and product usage. Our hosting provider, Amazon Web Services, records server logs for the website and web app: pages requested, browser type, and the IP address you connect from. We do not use a third-party analytics service.
Communications. If you email us or use support, we keep the conversation.
How we use it
- To provide the Service: store your sessions, build your library, and show dashboards, analysis, and recommendations.
- To generate session titles, summaries, and answers to your questions inside the Service. This processing is done by AI providers acting on our behalf (see below).
- To improve the Service using de-identified, aggregated data derived from sessions across customers. This data does not identify you or your organization and does not contain source code, prompts, or model responses; it is limited to metrics, patterns, and statistics.
- To bill you, send receipts, and handle failed payments.
- To send you service messages (security notices, changes to terms, billing) while you have an account.
- To keep the Service secure, investigate incidents, and comply with law.
We do not sell your data and do not use it for advertising.
AI providers
Two providers process session content on our behalf. Anthropic generates session titles and summaries, and receives the session text needed to produce them. OPA powers the answers you get when you ask questions inside the app, and receives your question along with short excerpts of session text and session metadata. Each is bound by contract to process this data only to provide these features. We tell you before we add or change a subprocessor.
Who we share it with
We share data only with providers that help us run the Service, each bound by contract to protect it:
| Provider | What they do | What they receive |
|---|---|---|
| Amazon Web Services | Cloud hosting, backups, and server logs | All Service data |
| Anthropic | Session titles and summaries | Session content |
| OPA | In-app answers | Your question, short session excerpts, and session metadata |
| WorkOS | Sign-in and workspace identity management | Your sign-in identity and workspace membership |
| Google and Microsoft | Sign-in; Google Workspace also delivers the email we send you | Your sign-in identity, name, and email address |
| Stripe | Payments | Billing details |
We also share data:
- With your workspace admins and members, according to the visibility settings your workspace uses.
- With a training or coaching partner, where your organization has authorized that in its Order Form with us.
- When the law requires it, after telling you if we are allowed to.
- With a buyer or successor if Blueplane is acquired or merges, under this policy.
How long we keep it
- Session content: while your account or workspace is active, subject to your plan’s storage window. Some plans keep session history for a limited period shown on the pricing page; older sessions are deleted.
- After an account or workspace closes: you have 30 days to export. We delete session content from production systems within 60 days, and from backups as they expire, currently within 30 days.
- Account and billing records: 12 months after closure, or longer where tax or accounting law requires.
How we protect it
We encrypt data in transit and at rest, limit access to the people who need it to run the Service or respond to an incident, log that access, and do not use customer data in development or test environments. We are pursuing a SOC 2 Type 2 (Security) report, targeting early 2027. No system is perfectly secure. If we confirm unauthorized access to your data, we will notify you or your organization without undue delay.
Your choices and rights
- See and export: your sessions are available in the app and through the API at any time.
- Delete: delete individual sessions in the app, or close your account. Workspace members: ask your admin.
- Exclude: configure exclusions in the capture agent so specific directories or repositories are never recorded, or uninstall the agent to stop capture on a device.
- Cookies: the website and app use one cookie, to keep you signed in. We do not use advertising or analytics cookies. You can block cookies in your browser, but the app needs the sign-in cookie to work.
If you are in a jurisdiction that gives you additional rights over your personal data, such as the right to access, correct, delete, or restrict processing, or to complain to a regulator, email legal@blueplane.ai and we will respond within 30 days. If your data is held under your organization’s workspace, we will refer your request to your organization.
Where data is stored
We host the Service in the United States (Amazon Web Services, us-west-1). If you use the Service from outside the United States, your data is transferred to and processed there.
Children
The Service is for people at least 18 years old using it for work. We do not knowingly collect data from anyone under 18.
Changes
We will post changes here and update the effective date. For material changes we will email account holders at least 30 days before they take effect.
Contact
Blueplane Inc., a Delaware public benefit corporation
legal@blueplane.ai