Privacy Policy

My ADAM CTO · Last updated: August 11, 2026

This policy explains what My ADAM CTO ("ADAM," "we") collects, why, and what we do — and deliberately don't do — with it.

The short version

We collect what's needed to watch your engineering reality and report it to you. Your code stays yours: deep code reading is off by default, enabled by you per repository, and we keep findings, never source. We never sell your data. You can leave and take everything with you.

1. What we collect

Account data. Name, email, password (stored hashed by our authentication provider), company name.

Repository data. When you connect GitHub: repository names, metadata, activity (commits, pull requests, CI status, contributor identities), and configuration signals (branch protection, READMEs). Source code content is read only for repositories where you have explicitly enabled deep reading, with a consent step, and can be disabled at any time. Analysis produces findings; we retain the findings, not copies of your source code.

Documents. Files you upload to the vault and e-signature status from our signing provider (e.g., whether an IP assignment is signed).

Billing data. Handled by Stripe. We store your subscription tier, status, and Stripe identifiers. We never see or store card numbers.

Usage data. Sign-ins and basic product usage, for security and improving the Service.

Developer data you provide. Names, emails, and roles of developers you add, and reports they submit through the portal.

2. What we use it for

To operate the Service: producing scores, findings, reports, and checklists; running the developer portal; generating investor share links you create; billing; support; and security. We also use aggregate, de-identified usage to improve the product.

We do not sell personal data. We do not use your code or documents to train AI models. We do not show ads.

3. AI processing

To generate plain-English analysis, relevant content (including source code only where you enabled deep reading) is processed by third-party AI providers acting as our sub-processors under confidentiality obligations, currently including Anthropic. Content sent for analysis is used to produce your results, not for the provider's model training under our agreements.

4. Who else touches data (sub-processors)

  • Supabase — database, authentication, file storage
  • Stripe — payments and subscription management
  • GitHub — repository connection (per the permissions you grant)
  • SignWell — e-signatures
  • Anthropic — AI analysis
  • Pass provider (digital wallet cards) — Founding Member cards
  • Hosting/infrastructure providers for the application

Each processes data only to provide their function.

5. Sharing you control

Investor share links display a curated, read-only snapshot (scores, readiness, repository health aggregates) to anyone with the link. You create and revoke them. Developer portal users see only their scoped view, never company financials.

6. Referral program and wallet cards

If you take part in the Founding Member referral program, we record the invitation link that brought an account in, the resulting signups and paid conversions, and the credits earned. Where you hold a digital wallet card, we send it your company's headline score, grade, and punch-card progress so the card stays current; those updates go through our pass provider and, if you added the card to a phone, through Apple's or Google's push services. Invitees see only the inviting member's founding number, never their contact details. Delete the card or ask us at support@myadamcto.com to stop the updates.

7. Retention and deletion

We retain data while your account is active. If your subscription ends, data is kept and visible read-only — never deleted for non-payment. If you close your account or request deletion at support@myadamcto.com, we delete Customer Content within 30 days, except minimal records we must keep for legal, tax, or security purposes.

8. Security

Encryption in transit, hashed credentials, row-level access controls separating tenants, signature-verified webhooks, and least-privilege access to production. No system is perfectly secure; we notify affected customers of breaches as required by law.

9. Your rights

Depending on your location (e.g., EU/EEA GDPR, Israeli Privacy Protection Law), you may have rights to access, correct, export, restrict, or delete your personal data, and to complain to a supervisory authority. Requests: support@myadamcto.com.

10. Cookies

We use only the cookies needed to keep you signed in and the Service functioning. No third-party advertising cookies.

11. Children

The Service is for business use by adults; we do not knowingly collect data from anyone under 18.

12. Changes

We'll post updates here and notify you of material changes.

13. Contact

180Breadcrumbs Inc. (Delaware, USA) · support@myadamcto.com