This Privacy Policy explains how Trylle, Inc. ("Trylle", "we", "us", or "our") collects, uses, shares, and protects personal data when you use the Trylle platform, websites, and related services (the "Service"). Trylle, Inc. is the controller of the personal data described here. We process data only as needed to provide the Service, keep your account secure, and comply with our legal obligations.
1. Information we collect
We collect the following categories of information:
- Account data: your email address, display name, username, password or authentication credentials, and profile details you provide.
- Content data: repositories, source code, commits, issues, pull requests, comments, reviews, and other materials you create or upload to the Service.
- Usage and technical data: log data, IP address, device and browser information, pages viewed, actions taken, and timestamps, collected to operate and secure the Service.
- Billing data: for paid plans, billing contact details and subscription records. Payments are handled by our payment processor; we do not store full payment card numbers.
- Communications: messages you send us for support or other inquiries.
- Cookies and similar technologies: identifiers used to keep you signed in and to understand and improve usage (see the Cookies section below).
2. Sources of data
We collect data directly from you (for example, when you register or use the Service), automatically as you interact with the Service, and from connected git hosts and third-party integrations that you choose to authorize.
3. How we use data and our legal bases
We use personal data for the purposes below. Where the GDPR or similar laws apply, we rely on the legal bases noted:
- To provide the Service, including authentication, sessions, hosting repositories, and syncing the information you choose to access (legal basis: performance of a contract).
- To secure the Service, prevent fraud and abuse, and maintain reliability through limited logging and monitoring (legal basis: legitimate interests).
- To process payments and manage subscriptions (legal basis: performance of a contract).
- To respond to your requests and provide support (legal basis: legitimate interests or contract).
- To improve and develop the Service and understand how it is used (legal basis: legitimate interests).
- To send service-related and, where permitted, product communications (legal basis: legitimate interests or consent, which you can withdraw).
- To comply with legal obligations and enforce our terms (legal basis: legal obligation and legitimate interests).
4. Cookies and tracking
We use strictly necessary cookies to operate the Service (for example, to keep you signed in) and, where applicable, functional and analytics cookies to remember preferences and understand usage. Where required by law, we ask for your consent before setting non-essential cookies, and you can manage your preferences through your browser settings or any consent controls we provide.
5. How we share data
We do not sell your personal information. We share data only as described here:
- Service providers (sub-processors) that process data on our behalf, such as cloud hosting, database, email delivery, payment processing, and analytics providers, under contracts that require appropriate safeguards.
- Collaborators and organizations you choose to share repositories, issues, or other content with.
- Legal and safety: when required by law, legal process, or to protect the rights, property, or safety of our users, the public, or us.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Privacy Policy.
6. AI features and code processing
Some Trylle features use artificial intelligence and machine learning, and several of them rely on third-party AI providers (acting as our sub-processors) to operate. When you or a member of your organization invokes one of these features, the relevant context — which may include your source code, diffs, file contents, issues, pull requests, commit messages, and related repository content and metadata — may be sent to and processed by these third-party providers in order to generate a response. This processing happens at your direction: it occurs only when you or your organization triggers the feature, and it is scoped to the repositories and resources that feature is authorized to access.
AI-assisted features that may process your or your organization's code in this way include:
- Automations that call models to run on repository events.
- Zen PRs and guided pull request review.
- The command palette and other in-product assistants.
- Bots and agents that you or your organization configure.
We and our AI sub-processors use this content only to provide the feature you requested. We do not sell your code, and we do not use your private repository content to train third-party foundation models; we contractually require our AI providers to process your data only to deliver the feature and not to train their models on it, except where you expressly opt in. You can control whether these features are enabled through your organization and repository settings (for example, Settings → AI), and disabling a feature stops the associated processing going forward.
7. International data transfers
We may process and store data in countries other than where you live, including the United States. Where we transfer personal data internationally, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK addendum where applicable) to protect your data.
8. Data retention
We retain personal data for as long as your account is active and as needed to provide the Service. After your account is closed, we delete or anonymize personal data within a reasonable period, except where we must retain it to comply with legal obligations, resolve disputes, enforce our agreements, or maintain security logs.
9. Security
We use technical and organizational measures designed to protect personal data, including encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, and you are responsible for keeping your credentials safe.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to our processing of your personal data, to data portability, and to withdraw consent. If you are in California, you may have rights to know what personal information we collect, to delete it, to correct it, and to opt out of its sale or sharing; we do not sell or share personal information as those terms are defined under California law. We will not discriminate against you for exercising your rights.
11. How to exercise your rights
To exercise your rights or make a privacy request, contact us at hello@trylle.com. We will respond in accordance with applicable law and may need to verify your identity. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
12. Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify you, and the "Last updated" date below will change when we do.
14. Contact us
If you have questions about this Privacy Policy or how we handle your data, contact Trylle, Inc. at hello@trylle.com.