Octarin · NACE AI, Inc.

Privacy Policy

Last updated: June 7, 2026 · Effective: June 7, 2026

This Privacy Policy describes how NACE AI, Inc. collects, uses, shares, and protects information in connection with Octarin, our AI-coding-agent usage and spend analytics platform.

Octarin captures development telemetry from AI coding agents. For most of that telemetry, your organization decides what is collected and acts as the controller, while NACE AI processes it on your organization's behalf.

1.Scope and Acceptance

This Privacy Policy explains how NACE AI, Inc. ("NACE AI," "we," "us," or "our") collects, uses, discloses, and otherwise processes information in connection with Octarin and its websites, applications, dashboards, capture agents, command-line tools, and APIs (the "Services"). It supplements and is incorporated into our Terms of Service.

By using the Services or sending data to them, you acknowledge this Privacy Policy. For much of the development telemetry processed through Octarin, our customer (your organization) is the controller and determines what is collected; we act as a processor on the customer's instructions. Where we determine the purposes and means of processing (for example, our websites and account administration), we act as a controller.

2.Information We Collect

Information you provide

  • Account and organization details: name, work email, organization name, role, and profile information;
  • Authentication data via providers such as Google (OAuth) — we receive your email, name, and profile identifiers;
  • Billing details processed by our third-party payment processor (we do not store full card numbers);
  • Communications you send us, including support requests and feedback; and
  • Settings and configuration, including invitations you create and capture/redaction choices.

Development telemetry (Customer Data) captured by the Services

  • Prompts and assistant responses; tool, file, and command activity (including names of tools, MCP servers, and skills);
  • Model identifiers, token counts, and computed cost; repository and environment names; session metadata, timestamps, and durations;
  • Pseudonymous user references that may include email addresses or usernames; and
  • Where you enable it, attached files or images associated with a session.

Information collected automatically

  • Device and connection data: IP address, browser and operating system, and approximate location derived from IP;
  • Usage and log data: pages viewed, actions taken, timestamps, and diagnostic information; and
  • Cookies and similar technologies used for authentication, security, and analytics.

Information from third parties

We may receive information from identity providers, payment processors, infrastructure and analytics providers, and your organization's administrators.

3.How We Use Information

We use information to:

  • provide, operate, maintain, secure, and support the Services and your account;
  • generate the analytics, summaries, labels, scores, statistics, and answers that are the core of the Services;
  • monitor, detect, prevent, and address fraud, abuse, security incidents, and technical issues;
  • analyze usage and trends, and to develop, improve, and create new features, products, and services;
  • create de-identified and aggregated data and to train, evaluate, and improve our models, algorithms, and benchmarks (see below);
  • communicate with you, including service, security, billing, and (where permitted) product messages; and
  • comply with law, enforce our Terms, and protect our rights, our customers, and others.

We rely on the following legal bases where applicable: performance of a contract, our legitimate interests in operating and improving the Services, your consent (where required), and compliance with legal obligations.

4.AI Processing, De-Identified Data, and Model Improvement

To deliver the Services, we send certain Customer Data to AI providers (for example, to generate session summaries, scores, embeddings, and chat answers). These providers process data on our behalf as sub-processors and are contractually restricted from using it to train their own general models except as permitted under their terms.

We may use Customer Data, and information derived from it, to operate and improve the Services and to develop new offerings. We may create de-identified and aggregated data and may use such data for any lawful purpose, including analytics, benchmarking, and training and improving our own models. We do not use Customer Data that directly identifies you or your individual users to train models made generally available to other customers without consent, except in de-identified or aggregated form.

Where you enable redaction or other privacy controls we make available, we apply commercially reasonable efforts to filter designated categories of personal data before storage or AI processing; however, no filtering is perfect, and you remain responsible for what you choose to transmit.

5.How We Disclose Information

We disclose information to:

  • Service providers and sub-processors that perform services on our behalf under appropriate confidentiality and data-protection obligations;
  • Your organization and its administrators — telemetry is made available within your organization's workspace to authorized members;
  • Affiliates within our corporate group for the purposes described in this Policy;
  • Authorities and others when we believe disclosure is reasonably necessary to comply with law, legal process, or governmental request, or to protect the rights, property, or safety of NACE AI, our customers, or the public; and
  • Acquirers and their advisors in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, in which information may be transferred as a business asset.

We do not sell personal information for money. To the extent certain data sharing for analytics constitutes a "sale" or "sharing" under applicable law, you may exercise the choices described below.

6.Sub-Processors and Service Providers

We use the following categories of sub-processors to provide the Services. We may update this list as our providers change.

  • Anthropic — large language models (session summarization, scoring, and chat);
  • Voyage AI — text embeddings for semantic search;
  • ClickHouse Cloud — analytics data storage;
  • Supabase — authentication and application database;
  • DigitalOcean — cloud hosting and object storage (Spaces) for attachments;
  • Resend — transactional and invitation email; and
  • Google — authentication (OAuth) and, where enabled, website analytics.

7.Cookies and Analytics

We use cookies and similar technologies for authentication, security, preferences, and to understand how the Services are used. You can control cookies through your browser settings; disabling some cookies may affect functionality. Where required, we obtain consent for non-essential cookies.

8.International Data Transfers

We operate in the United States and may process and store information in the United States and other countries where we or our sub-processors operate. These countries may have data-protection laws different from those in your jurisdiction. Where required, we implement appropriate safeguards (such as standard contractual clauses) for cross-border transfers.

9.Data Security

We implement administrative, technical, and organizational measures designed to protect information, including encryption in transit, access controls, and scoped credentials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and API keys and for configuring the capture and redaction controls appropriate to your data.

10.Data Retention

We retain information for as long as reasonably necessary to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements, after which we delete or de-identify it. Customer Data is retained according to your plan and configuration and your organization's instructions. We may retain de-identified data, aggregated data, derived data, and backups for longer, including after termination.

11.Your Rights and Choices

Depending on your location, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, to object to certain processing, and to withdraw consent. Because much of the telemetry processed through Octarin belongs to our customers as controllers, we will generally direct requests concerning that data to the relevant customer, or assist that customer in responding.

EEA / UK (GDPR)

If you are in the EEA or UK, you may exercise the rights above and may lodge a complaint with your supervisory authority. Our legal bases are described in "How We Use Information."

California (CCPA/CPRA)

California residents may request disclosure of the categories and specific pieces of personal information we collect, the purposes of collection, and the categories of recipients; may request deletion or correction; and may opt out of any "sale" or "sharing" as defined by law. We do not knowingly sell personal information for money. You may also designate an authorized agent. We will not discriminate against you for exercising your rights.

How to exercise rights

To make a request, contact privacy@nace.ai. We will verify your request as required by law. If you are an individual whose employer uses Octarin, please also contact your organization's administrator, who controls that data.

12.Children's Privacy

The Services are intended for business use and are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact privacy@nace.ai and we will take appropriate steps to delete it.

14.Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the revised version with a new "Last updated" date, and material changes take effect upon posting unless we indicate otherwise. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.

15.How to Contact Us

For privacy questions or to exercise your rights, contact our privacy team at privacy@nace.ai. For other matters, contact support@nace.ai. You may also reach NACE AI, Inc. (a Delaware C corporation), Attn: Privacy, at dos@nace.ai.