← kygit.com

Privacy Policy

Last updated: 2026-08-05

KyGit is run402's git vault under its own product domain, operated by Kychee, Inc. Your use of KyGit is governed by the run402 Privacy Policy, reproduced below with the vault lane described precisely; the canonical copy lives at run402.com/humans/privacy.html.

The strongest privacy statement on this page is structural, not contractual: your repository history is encrypted on your own machine, under a key we never receive. Most of what a privacy policy usually promises about your code, we could not do to it if we tried.

Overview

Run402 provides cloud infrastructure — databases, APIs, authentication, storage, static site hosting, and the KyGit git vault. Unlike a static website, Run402 necessarily stores and processes data to deliver its services. This policy explains what data we collect, how we use it, and how we protect it — and, for the vault, what we structurally cannot see at all.

Data We Collect

Run402 collects and stores the following data as part of normal service operation:

the envelope, never the letter

How We Use Data

We use the data we collect exclusively for:

Run402 does not sell your data. We do not use your data for advertising. We do not train AI models on your data — and for vault content, this is not a policy choice we could later reverse: we hold ciphertext and no key, so there is nothing on our side to train on, index, sell, or hand to whoever asks next.

Buzz setup diagnostics are best-effort and never affect setup. Set RUN402_TELEMETRY=0 in the agent environment to disable their delivery.

Data Storage and Security

Data Retention

Your data lifecycle follows a ~104-day soft-delete grace. Your live site and end-user traffic keep working throughout — only the project owner's control-plane access (deploys, secret rotation, subdomain claims) is gated after day 14. Read-side vault routes are never lifecycle-gated: a vault stays readable while its organization is in billing grace, and the opt-in mirror means your history is never hostage to a billing state in the first place.

Any tier renewal, topup, or upgrade during grace instantly reactivates the project and clears the countdown. Server logs are retained for 30 days and then automatically deleted.

Hosted Application Data

Data stored by the applications you build on Run402 — including end-user data collected by your apps — is your responsibility. You are the data controller for any personal data your applications collect. Run402 acts as a data processor on your behalf. You are responsible for ensuring your applications comply with applicable privacy laws (GDPR, CCPA, etc.).

Third-Party Services

Run402 uses the following third-party services:

Run402's own pages — kygit.com included — set no cookies and use no third-party analytics. To measure which ad campaigns deliver real users, if you arrive from an ad the page stores the click's attribution parameters (such as gclid and UTM tags) in your browser's local storage and sends them only to our own API.

When you copy the agent prompt on run402.com, we may issue a unique promo code and attach it to the prompt. The code is unique so that your agent receives its starter credits, and it lets us connect that visit to what the agent later does on Run402. Once the code reaches your agent it identifies a machine account, not a person: no browser, cookie, device, or personal identifier crosses over with it. Copying still works if the code cannot be issued.

Children's Privacy

Run402 is not directed at children under 13. We do not knowingly collect personal information from children. If you are a developer building an application directed at children, you are responsible for ensuring COPPA compliance in your application.

Your Rights

You may export your data at any time using the Run402 API while your lease is active — for a vault, run402 repos mirror and run402 repos recover give you a complete, independently recoverable copy of your history with no server involved. If you need to exercise data subject rights (access, correction, deletion) for data stored in your project's database, you can do so directly through the API. For requests related to Run402 organization-level data, contact legal@kychee.com. Note the structural limit in your favor: for vault content we can delete ciphertext and metadata, but we cannot produce a readable copy of your repository history for anyone — including you — because we never hold the key.

Changes to This Policy

We may update this privacy policy from time to time. The “last updated” date at the top of this page reflects when changes were last made. Continued use of Run402 after changes constitutes acceptance of the updated policy.

Contact

Privacy questions? Email legal@kychee.com.

one thread, unbroken