PRIVACY
What we store, where it comes from, and what we never touch.
This policy covers everything Astryke: Astryke Hub, the paid product, and this site with its free browser tools. Astryke is operated by Selfdefiant Studios. Where a section applies to only one of them, it says so.
The short version: the free tools store nothing about you at all, and the Hub stores your working notes, which is unusually personal for software and is why the rest of this page is specific.
ASTRYKE HUB
The Hub holds what you are building, where each project stands, and what you decided.
What the Hub stores
- Your account: email address and the name you sign up with.
- Your board: project names, status, what you are working on next, decisions you settled, questions waiting on you, and notes you or your agents write.
- Working context your agent reports, which can include folder paths on your computer and the names of repositories you have open.
- A record of agent sessions: when one started, how long it ran, and the summary it wrote at the end.
- Technical data: a session cookie to keep you signed in, and ordinary server logs such as IP address and browser type, kept for security and reliability.
Where it comes from, and this part matters
Most of what lands on your board is not typed by you. It is written by an AI coding agent you connected, running on your own machine, which reports what it worked on. That is the point of the product, and it is also the thing worth understanding before you connect one.
An agent sends the Hub what it was asked to record: project names, progress, next steps, decisions, and the folder it was working in. It is not a backup of your computer. The Hub never scans or uploads your repository, has no access to your machine, and cannot go looking for anything. It only ever receives what an agent you connected chooses to send.
Being exact about the limit of that: agents write those summaries, questions and notes themselves, in their own words, from whatever they had in context. Nothing here inspects that text or rejects it for looking like code, so an agent could quote a line of your work in a summary if it judged it relevant. We do not go and get your code; we also cannot promise an agent never includes a piece of it. That is worth knowing when you choose which tool to connect.
The agents you connect
You choose which AI tools to connect, such as Claude Code, Codex, Cursor, or anything else that speaks the same protocol. When one of those reads your board, that content goes to whichever company runs that agent, under their terms and their privacy policy, not ours. We do not control what they do with it, and connecting one is your decision to make with that in mind.
Each connection uses its own token. You can see every token, with when it was created and last used, on the Connect an agent page in the app, and revoke any of them at any time, which stops that agent reading or writing immediately.
How it is protected
What you and your agents write is encrypted before it is stored, using a key belonging only to your workspace. That key is itself protected by a key held outside the database and outside the web server’s document root, so a copy of the database alone does not reveal anyone’s notes. Traffic is HTTPS end to end. Passwords are stored only as an Argon2id hash, which cannot be reversed.
Three things are deliberately not encrypted, and it is only fair to name them: your project names, the one-line next action on each project, and the working-directory paths your agents report. The Hub has to match a project by name every time an agent mentions one, and that cannot be done against encrypted text. Treat the paths the way you would a folder name: they say where you work, not what is in the files. Everything else, meaning session summaries, decisions, questions and their answers, pinned thoughts and replies, and session records, is encrypted at rest.
To be plain about the limits: this is not zero-knowledge encryption. The Hub decrypts your board in order to show it to you and to answer your agents, so the operator can technically reach it. Access is limited to what is needed to run the service and to answer a support request you have made.
What we do not do
- We do not sell your information, and there is nobody to sell it to.
- There is no advertising on Astryke Hub, and no third-party tracking or analytics scripts. The pages inside the app load nothing from anyone else.
- We do not use your projects, notes, or board content to train AI models, and we do not hand them to anyone else to train on.
- We do not read your board for any purpose other than running the service or answering support you asked for.
Your address is used to sign you in, to reset your password, and to send service notices that matter, such as a change to this policy or a problem with your account. Reset messages are sent from our own mail server, not through a third-party sending service. There is no marketing list and nothing on this site collects an address for one.
Payment
Subscriptions are processed by Stripe. Card details go to Stripe directly and never touch our servers, so we could not store a card number even if we wanted to. What we keep is the Stripe customer and subscription identifiers needed to know whether your plan is active. Deleting your account cancels any live subscription with Stripe first.
Cookies
Inside the app, one cookie, and it exists to keep you signed in. It is marked secure, HTTP-only, and same-site. There are no advertising or cross-site tracking cookies there. Clearing it signs you out.
How long it is kept, and how to get rid of it
Your board and its history are kept for as long as your account is open. Session and event history is deliberately not pruned, because the record of what happened is the product; expired password reset links and unused sign-in codes are pruned nightly.
You can export the whole workspace as JSON or Markdown at any time, whether or not you are paying. You can edit or clear any project yourself, and you can delete your account and everything in it from the account page without asking anyone. Deleted data can persist for a short time in routine backups before those rotate out.
THIS SITE AND THE FREE TOOLS
Different rules apply here, because there is nothing to store. The free tools need no account and never ask for an email address.
What runs on this site
Google Analytics 4 for traffic shape (which tools get used, where visitors come from, how long sessions run). GA sets a _ga cookie. Standard, well-documented, opt-out via any cookie or analytics blocker.
Cloudflare Web Analytics for bot-filtered visit counts. Cookieless. No personal identifiers. Loaded from cloudflareinsights.com.
That is the full third-party list on astryke.com. Nothing else fires. Note that these run on the marketing site and the tool pages, not inside the Hub, which carries no third-party scripts at all.
Tool data
Every tool runs entirely in your browser. Files you import, palettes you build, sprite sheets you slice, sounds you generate. None of it is uploaded, logged, or stored anywhere we control. Close the tab and it is gone unless you exported.
Usage counter
The tools index shows a small usage bar under each tool. It counts how often that tool was opened: anonymized, no fingerprinting, and no IP storage beyond a hashed bucket for short-term de-duplication. It exists only to show which tools people actually use.
EVERYTHING ELSE
Where it lives
Astryke runs on servers in the United States and is operated from the United States. If you use it from elsewhere, your information is transferred to and handled in the United States, where data protection law may differ from your own.
Age
You must be at least 13 years old to create an Astryke Hub account.
Changes
If this policy changes in a way that matters, the date below changes and we tell account holders by email. We do not quietly widen what we collect.
Contact
Questions, or a request to see or delete your data: [email protected]. The Terms of Service sit alongside this policy.
Astryke is operated by Selfdefiant Studios. Last updated 1 August 2026.