Last updated: June 12, 2026
Privacy Policy
Gentlybot helps teams ask questions about their product and codebase, create work, and preview changes in connected tools like Slack and GitHub. This policy explains the basic information we collect and how we use it.
Information we collect
- Account information, such as your name, email address, organization, invite status, and sign-in provider details.
- Connected workspace information, such as Slack workspace details, GitHub app installation metadata, repository metadata, and other integration settings you choose to connect.
- Product content, including prompts, chat history, tasks, generated answers, previews, screenshots, logs, and files needed to perform requested work.
- Code and sandbox data needed to understand a repository, run a temporary workspace, build or preview changes, and recover that workspace if a runtime node is replaced.
- Usage and operational data, such as model usage, job status, audit details, errors, and security logs.
How we use information
We use this information to provide Gentlybot, answer questions, operate sandboxes and previews, process requested changes, maintain integrations, improve reliability, prevent abuse, and support billing or usage review.
Where data is stored
Gentlybot production runs on AWS in the United States, currently in the us-east-2 region. Core application data is stored in a private AWS RDS Postgres database. Temporary queues and runtime state use private AWS infrastructure. Secrets are stored in AWS Secrets Manager, with human-authored production secrets managed from 1Password and synced into AWS.
Sandbox and preview artifacts may be stored in private AWS S3 buckets. This can include workspace bundles, runtime service volume snapshots, screenshots, videos, logs, and similar generated outputs. Sandbox recovery artifacts are encrypted at rest by S3, are not public, and have lifecycle cleanup rules for ephemeral data.
In local development, some artifact bytes may be stored on local disk under the configured GENTLY_DATA_DIR. Production does not rely on storing those files in the app repository.
Sharing
We do not sell personal information. We share information only as needed to operate the product, including with infrastructure providers, AI model providers, authentication providers, and integrations you connect, such as Slack or GitHub.
Security
Production data stores live in private AWS networking where possible. Public traffic is served over HTTPS. Access to production systems is limited to operational needs, and secrets are managed outside the codebase.
Retention
We keep account, organization, integration, conversation, usage, and operational records as long as needed to provide the service, meet business or legal needs, and troubleshoot issues. Temporary sandbox artifacts and generated files may have shorter lifecycle cleanup windows.
Your choices
You can choose which integrations to connect and what information to send to Gentlybot. If you need access, correction, deletion, or export of information, contact the Gentlybot team through your usual support or account channel.
Changes
We may update this policy as Gentlybot changes. We will update the date above when we make material changes.