Privacy Policy
Last updated: January 29, 2026
Introduction
Handoff Kit ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service, including our website and application (collectively, the "Service").
Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the Service.
Information We Collect
Personal Information
We collect information that you provide directly to us, including:
- Account information (name, email address, password)
- Organization details (company name, organization settings)
- Payment information (processed securely through Stripe)
- Communication data (support messages, feedback)
Repository Data
When you connect GitHub or Azure DevOps repositories, we collect:
- Repository metadata (name, description, language, file structure)
- Code files and content for analysis (temporarily stored during processing)
- OAuth tokens (encrypted and stored securely)
- Repository activity data (commits, branches)
AI Processing Data
Your repository data is processed by Claude AI (Anthropic) to generate documentation. This processing:
- Occurs in real-time during documentation generation
- Is subject to Anthropic's data handling policies
- Does not result in your code being used for AI model training
- Is deleted from processing systems after generation completes
Automatically Collected Information
When you access the Service, we automatically collect:
- Usage data (features accessed, pages viewed, time spent)
- Device information (browser type, operating system, IP address)
- Log data (error logs, performance metrics)
How We Use Your Information
We use the collected information for:
- Providing and maintaining the Service
- Analyzing repositories and generating documentation
- Processing payments and managing subscriptions
- Sending service-related notifications and updates
- Improving and optimizing the Service
- Detecting and preventing fraud or abuse
- Complying with legal obligations
Data Sharing and Disclosure
We do not sell your personal information. We may share your information with:
Service Providers
- Anthropic (Claude AI): For AI-powered code analysis and documentation generation
- Stripe: For payment processing
- Vercel: For hosting and infrastructure
- Neon: For database services
- Cloudflare R2: For file storage
Legal Requirements
We may disclose your information if required by law, court order, or government request, or to protect our rights and the safety of others.
Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure OAuth token storage with encryption
- Regular security audits and updates
- Access controls and authentication requirements
- Automated backups and disaster recovery procedures
However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this policy:
- Account data: Until account deletion
- Repository analysis data: Duration of project storage
- Generated documentation: Until manually deleted
- Temporary processing data: Deleted within 24 hours
- Log data: Retained for 90 days
Your Rights
Depending on your location, you may have the following rights:
- Access: Request access to your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data
- Portability: Request a copy of your data in a structured format
- Objection: Object to processing of your data
- Restriction: Request restriction of processing
To exercise these rights, contact us at privacy@handoffkit.ai
Cookies and Tracking
We use cookies and similar technologies to:
- Maintain your session and authentication state
- Remember your preferences and settings
- Analyze usage patterns and improve the Service
You can control cookies through your browser settings. Note that disabling cookies may affect Service functionality.
Children's Privacy
Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We ensure appropriate safeguards are in place for such transfers.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: