Privacy Policy
My ADAM CTO · Last updated: August 11, 2026
This policy explains what My ADAM CTO ("ADAM," "we") collects, why, and what we do — and deliberately don't do — with it.
The short version
We collect what's needed to watch your engineering reality and report it to you. Your code stays yours: deep code reading is off by default, enabled by you per repository, and we keep findings, never source. We never sell your data. You can leave and take everything with you.
1. What we collect
Account data. Name, email, password (stored hashed by our authentication provider), company name.
Repository data. When you connect GitHub: repository names, metadata, activity (commits, pull requests, CI status, contributor identities), and configuration signals (branch protection, READMEs). Source code content is read only for repositories where you have explicitly enabled deep reading, with a consent step, and can be disabled at any time. Analysis produces findings; we retain the findings, not copies of your source code.
Documents. Files you upload to the vault and e-signature status from our signing provider (e.g., whether an IP assignment is signed).
Billing data. Handled by Stripe. We store your subscription tier, status, and Stripe identifiers. We never see or store card numbers.
Usage data. Sign-ins and basic product usage, for security and improving the Service.
Developer data you provide. Names, emails, and roles of developers you add, and reports they submit through the portal.
2. What we use it for
To operate the Service: producing scores, findings, reports, and checklists; running the developer portal; generating investor share links you create; billing; support; and security. We also use aggregate, de-identified usage to improve the product.
We do not sell personal data. We do not use your code or documents to train AI models. We do not show ads.
3. AI processing
To generate plain-English analysis, relevant content (including source code only where you enabled deep reading) is processed by third-party AI providers acting as our sub-processors under confidentiality obligations, currently including Anthropic. Content sent for analysis is used to produce your results, not for the provider's model training under our agreements.
4. Who else touches data (sub-processors)
- Supabase — database, authentication, file storage
- Stripe — payments and subscription management
- GitHub — repository connection (per the permissions you grant)
- SignWell — e-signatures
- Anthropic — AI analysis
- Pass provider (digital wallet cards) — Founding Member cards
- Hosting/infrastructure providers for the application
Each processes data only to provide their function.
5. Sharing you control
Investor share links display a curated, read-only snapshot (scores, readiness, repository health aggregates) to anyone with the link. You create and revoke them. Developer portal users see only their scoped view, never company financials.
6. Referral program and wallet cards
If you take part in the Founding Member referral program, we record the invitation link that brought an account in, the resulting signups and paid conversions, and the credits earned. Where you hold a digital wallet card, we send it your company's headline score, grade, and punch-card progress so the card stays current; those updates go through our pass provider and, if you added the card to a phone, through Apple's or Google's push services. Invitees see only the inviting member's founding number, never their contact details. Delete the card or ask us at support@myadamcto.com to stop the updates.
7. Retention and deletion
We retain data while your account is active. If your subscription ends, data is kept and visible read-only — never deleted for non-payment. If you close your account or request deletion at support@myadamcto.com, we delete Customer Content within 30 days, except minimal records we must keep for legal, tax, or security purposes.
8. Security
Encryption in transit, hashed credentials, row-level access controls separating tenants, signature-verified webhooks, and least-privilege access to production. No system is perfectly secure; we notify affected customers of breaches as required by law.
9. Your rights
Depending on your location (e.g., EU/EEA GDPR, Israeli Privacy Protection Law), you may have rights to access, correct, export, restrict, or delete your personal data, and to complain to a supervisory authority. Requests: support@myadamcto.com.
10. Cookies
We use only the cookies needed to keep you signed in and the Service functioning. No third-party advertising cookies.
11. Children
The Service is for business use by adults; we do not knowingly collect data from anyone under 18.
12. Changes
We'll post updates here and notify you of material changes.
13. Contact
180Breadcrumbs Inc. (Delaware, USA) · support@myadamcto.com