Skip to main content
Dispatcher

Legal

Privacy Policy

Last updated: August 8, 2026 · Version 2026.08.08

Dispatcher (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the Dispatcher desktop application, website, and related services (the “Service”).

This Policy is designed around Dispatcher's architecture: agents run locally with your credentials, while optional cloud features sync collaboration data you choose to store with us.

1. Local vs cloud: the data boundary

What stays on your machine by design

For ordinary local desktop use, the following remain on your device and are not uploaded to Dispatcher cloud:

  • Repository source code and working trees
  • Diffs, patches, and local review artifacts
  • Terminal output and agent transcripts
  • Local workspace/agent-run state stored by the desktop app (for example in local SQLite or similar on-device storage)
  • AI provider API keys managed by third-party agent CLIs or your local environment (not sent to Dispatcher cloud as part of ordinary agent execution)

Code is sent to third-party AI providers only when you launch an agent that communicates with those providers, under their terms and with credentials you control.

What may be stored in Dispatcher cloud

When you sign in and use cloud features, we may store:

  • Account identifiers and profile data from our auth provider
  • Collaboration content you create or sync: tasks/issues, projects, cycles, roadmaps, knowledge documents, Sites content, comments, and similar metadata
  • Organization membership, roles, invitations, and workspace data
  • OAuth tokens or similar credentials for integrations you connect (for example GitHub, Linear, Slack)
  • Limited product analytics, diagnostics, or crash data, as described below

Cloud sync is optional for core local agent orchestration. Turning on cloud features is a deliberate choice to store collaboration data with us.

2. Information we collect

Information you provide

  • Account information when you sign in
  • Cloud content you choose to create or sync
  • Support, abuse, privacy, or security communications you send us
  • Integration connection details and tokens you authorize

Information collected automatically

  • Application version, OS/platform, and similar technical details for updates and diagnostics
  • Anonymous or pseudonymous usage analytics if enabled (desktop analytics may be controlled in Settings where available)
  • Error logs and diagnostic data to improve stability
  • Standard web logs for the website and APIs (IP address, user agent, timestamps, request metadata)

Credentials and secrets

We minimize secret handling where possible. AI provider keys used by local agent CLIs generally remain under your local/tooling control. If you connect cloud integrations, we store the tokens needed to operate those features and protect them with industry-standard safeguards appropriate to our hosting environment. You remain responsible for endpoint security on devices where the desktop app runs, including disk encryption and access control for any local databases or config files.

3. How we use information

We use information to:

  • Provide, maintain, secure, and improve the Service
  • Authenticate accounts and operate cloud collaboration features
  • Operate integrations you connect and publish Sites you choose to host
  • Send important service, security, and product notices
  • Respond to support, abuse, privacy, and security requests
  • Analyze aggregated or de-identified usage patterns to improve the product
  • Comply with law and enforce our Terms

We do not sell your personal information. We do not use repository source code from your machine to train our own models.

4. Legal bases (GDPR / UK GDPR)

If you are in the EEA, UK, or a similar jurisdiction, we process personal data under one or more of these bases:

  • Contract: to provide the Service you request (account, sync, integrations)
  • Legitimate interests: to secure, debug, and improve the Service, and prevent abuse, balanced against your rights
  • Consent: where required (for example optional analytics), which you may withdraw
  • Legal obligation: when we must retain or disclose data to comply with law

5. CCPA / CPRA notice (California)

If the California Consumer Privacy Act (as amended by the CPRA) applies, this Policy describes the categories of personal information we collect (identifiers, commercial/account data, internet or electronic activity, and customer content you upload to cloud features), the business purposes for use (Section 3), and the types of service providers involved (see Subprocessors).

We do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are commonly defined. You may request access, correction, or deletion as described in Section 9.

6. Third-party services and subprocessors

Dispatcher relies on subprocessors for auth, hosting, database, email, and similar infrastructure. The current list is published at getdispatcher.dev/subprocessors. We aim to provide at least 30 days’ notice of material subprocessor additions for customers who subscribe to that list via privacy@getdispatcher.dev.

When you connect integrations or run third-party AI agents, those providers process data under their own policies. Review their terms before connecting or launching agents.

7. Data storage, security, and international transfers

Local application data is stored on your device. Cloud account and synced content are stored by our service providers, typically in the United States or other regions where those providers operate. We use TLS in transit to our cloud services and industry-standard controls at rest within our hosting providers’ platforms.

If personal data is transferred from the EEA/UK to countries without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) with subprocessors where applicable. Business customers may execute our Data Processing Agreement.

No method of transmission or storage is perfectly secure. Please use strong account protections and keep devices updated.

8. Retention

  • Local data: until you delete it or uninstall the application
  • Account and cloud content: for the life of the account, then deleted or anonymized within a reasonable period after deletion (backup copies may persist up to about 30 days)
  • Diagnostics / crash data: typically up to 90 days
  • Analytics events: typically up to 12 months
  • Security and abuse records: as needed for investigation and legal compliance

9. Your rights and requests

Depending on your jurisdiction, you may have rights to access, correct, delete, export, or restrict certain processing of personal data, and to withdraw consent where processing is consent-based. To exercise these rights, email privacy@getdispatcher.dev. We may need to verify your request.

You may request deletion of your account and associated cloud data via the same contact (or in-product controls when available). We will also honor deletion requests from users who cannot sign in, subject to verification. Organization-owned content may require an organization admin request.

10. Children’s privacy

Dispatcher is not intended for users under 16. We do not knowingly collect personal information from children.

11. Cookies and similar technologies

The website uses strictly necessary cookies or local storage for authentication and security. We do not use third-party advertising trackers. If we enable optional product analytics on the web, we will present consent where required (including for visitors in the EEA/UK) before non-essential analytics run. The desktop app does not use browser cookies; analytics disclosure and any opt-out live in Settings when analytics are available.

12. Published Sites

If you publish a Site, the content you publish may be accessible to anyone with the link (or more broadly if you mark it public). Do not publish personal data or secrets you are not authorized to share. Abuse reports: abuse@getdispatcher.dev.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will revise the “Last updated” date and version above. Material changes will be posted on this page and, when appropriate, communicated by email or in-product notice.

14. Contact

Privacy questions and requests: privacy@getdispatcher.dev. Security: security@getdispatcher.dev. Related documents: Terms of Service, DPA, Subprocessors.

Privacy Policy: Dispatcher