Skip to main content
Sekreton Sign in

Privacy Policy

Last updated 2 October 2026

Who we are

Sekreton is operated by Shan Ming Yang Limited, a company registered in New Zealand. This policy explains what personal information we collect when you use Sekreton, what we do with it, and what you can ask us to do about it. We handle personal information in line with the New Zealand Privacy Act 2020 and its information privacy principles.

What we collect

Your account. Signing in is Google only. When you sign in we receive and store your name, your email address and your Google account id. We never see your Google password.

Your content. Whatever you and your team put into the product: task briefs, plans, chats, review comments, attachments, email you forward to your inbox, Google Meet transcripts if you turn that integration on, and the transcripts of the agent runs themselves.

Your credentials. The access token for your git forge and the model-provider keys your org configures. These are encrypted at rest and are only ever decrypted to run your work.

Connected apps. When you connect an AI app such as ChatGPT, Codex or Claude Code to Sekreton, we store which app it is, the teams you ticked, when you connected it and when it last called us. The tokens it signs in with are stored only as one-way hashes.

Billing. Stripe processes payments and holds your card details — we never see them. We store your Stripe customer and subscription ids, your subscription status, and the start and end dates of the current billing period.

Analytics. Every page carries Plausible Analytics, which records page views, referrers and coarse device and browser information. Plausible sets no cookies and does not track you across other websites.

Cookies. Two, both strictly necessary: a signed session cookie that keeps you signed in for up to 365 days, and a signed_in flag that lets our web server show you your dashboard rather than the home page. The flag holds no personal data. We set no advertising or tracking cookies at all.

Why we collect it

  • To sign you in and decide what you are allowed to see.
  • To run the product: read your repository, draft plans, build changes, and show you the diffs to approve.
  • To let the AI apps you connect read and manage your teams' backlogs on your behalf, and to show you which apps are connected.
  • To bill your org and meter the agent-minutes it uses.
  • To answer you when you write to us.
  • To keep the service working — debugging failures and stopping abuse.

We do not sell your personal information, and we do not use your content to train models of our own.

Who we share it with

Only the suppliers that make the product work, and only as much as they need:

  • Google — sign-in, and Meet transcripts if you enable that integration.
  • Stripe — payments and subscription management.
  • Plausible — cookie-free analytics, hosted in the EU.
  • Modal — the sandboxes some tasks run in.
  • Your model provider — the one your org configured. Prompts, and the excerpts of your code they carry, are relayed to that provider under its own terms. You choose the provider, so you choose those terms.
  • Your git forge — GitHub or GitLab, which already holds your repository and which we act against on your behalf.
  • The AI apps you connect — such as ChatGPT or Codex. They receive what their tools read from the teams you ticked, under that app's own terms.
  • Hetzner — hosts the application and its database.

We may also disclose information where the law requires it.

Where it lives

The application and its database run on Hetzner servers in Germany. Task sandboxes run either on Modal — in a region Modal chooses, which may be in the United States — or on our own server. Information sent to a supplier above may be processed in that supplier's own country.

Your source code is a special case. It is checked out from your forge inside a sandbox that belongs to a single task, and it is destroyed with that sandbox. We do not keep a copy of your repository at rest on our servers.

How we protect it

  • Everything is served over HTTPS.
  • Forge tokens and model-provider keys are encrypted at rest.
  • Each task runs in its own isolated sandbox, so one task cannot reach another team's work.
  • Access to production systems is limited to the people who need it.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects you, we will tell you and the Privacy Commissioner as the Privacy Act requires.

How long we keep it

  • Task content — briefs, plans, chats, comments, run transcripts — is kept for as long as your org has an account with us, because it is the record of your work.
  • Sandboxes, and the checkout inside them, are destroyed when a task finishes or after 30 idle minutes.
  • Database backups are taken nightly and kept for 7 days.
  • A connected app's access token lasts one hour and its refresh token 30 days; both are deleted the moment you revoke the app.
  • Your account, and every app connection it holds, is kept until you delete the account.

Ask us to delete your org's data and we will, subject to the backup window above.

What a connected app can do

An AI app you connect — ChatGPT, Codex or a coding agent on your own machine — acts as you, on the teams you ticked when you connected it and still belong to, and never beyond what your role on each team allows. It can:

  • Read those teams' projects, tasks, plans and run history, and the conversations on those tasks. Other people's private chats stay private.
  • Create tasks, which may start an agent working on your repository.
  • Edit a task's title, brief, plan or dependencies, and close a task still on the backlog.

It cannot approve plans or merges, change settings, see your model or forge credentials, or reach any team you did not tick.

Your controls

  • Under Account → Connected apps you can remove a team from an app or revoke the app outright. Either takes effect at once.
  • Leaving a team cuts every connected app off from it too.
  • Under Account you can delete your account, which removes your memberships and every app connection with it.
  • To delete your org's data, write to us at the address below.

Your rights

Under the Privacy Act 2020 you can ask us for a copy of the personal information we hold about you, ask us to correct it, and ask us to delete it. Write to hello@sekreton.com and we will respond within 20 working days.

Links to other sites

Sekreton links out to suppliers and to your own forge. Those sites have their own privacy practices, and we are not responsible for them.

Contact

Shan Ming Yang Limited, New Zealand — hello@sekreton.com.

Complaints

If you are not happy with how we have handled your information, you can complain to the Office of the Privacy Commissioner: privacy.org.nz, 0800 803 202, or info@privacy.org.nz.

Changes to this policy

We will update this page as the product changes, and the date at the top is how you tell. Continuing to use Sekreton after a change means you accept the current version.