Privacy Policy

Last updated: July 13, 2026 | Version 1.2

Introduction

SovrinTech LLC ("we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use the Charles website, desktop application, and related services (collectively, the "Service").

Data Controller: SovrinTech LLC is the data controller for personal data processed through the Service.

By using the Service, you consent to the practices described in this policy. If you do not agree, please do not use the Service.

Information We Collect

Account Information: Email address, hashed password, display name, and account preferences. We never store passwords in plain text.

Subscription & Billing: Plan tier, token usage counters, and payment information processed by Stripe. We do not store complete payment card numbers.

Device & Session Data: Device identifiers (for desktop app authorization), IP addresses, user agents, and session timestamps for security and fraud prevention.

Usage Metrics: Aggregate token consumption counts and feature usage to enforce plan limits and improve the product. These are numerical aggregates, not your code or conversations.

Product improvement signals (Version 1.2): When you use a paid plan and have not opted out of analytics, the desktop may send de-identified operational signals such as whether a turn succeeded, whether tools ran, failure counts, mode (chat/agent/auto), platform, and app version. We use these signals to improve routing, tool reliability, and agent quality. We do not upload your source code, project files, or full conversation transcripts through this channel.

Future Charles models: We may use de-identified operational statistics and, only where permitted by this policy and your preferences, carefully processed service logs from managed AI (not BYOK) to develop and evaluate Charles-trained models focused on productive, high-quality software work. You can opt out of product-improvement analytics in account settings; billing and abuse prevention still require usage metering.

Website Analytics: When you consent, we collect page views, approximate location (country/city derived from your IP address), referrer, browser type, and a hashed visitor identifier. IPs are not stored in plain text; we store a one-way hash for deduplication.

Desktop Update Telemetry: The desktop app reports anonymous update events (started, downloaded, installed, failed) including app version, platform, and architecture. No code, messages, or personal files are included. You can disable this in the desktop settings.

Communications: Support tickets, feedback submissions, and email correspondence.

What We Do NOT Collect

Charles is designed with a local-first architecture. We do NOT collect or have access to:

  • Your source code, project files, or repository contents
  • File system contents from your local machine
  • Keystrokes, screen recordings, or clipboard data

Bring Your Own Keys (BYOK): If you connect your own provider API keys, AI requests are sent directly from your machine to your chosen provider. We are not in that data path and do not store your prompts or outputs.

Managed AI: When you use Charles-managed models (Pro, Max), your prompts and generated outputs pass through our secure gateway so we can route, meter, bill usage, and operate background system AI (memory/skills on Charles's cost). We process this data to provide the service, enforce plan limits, prevent abuse, and — subject to your product-improvement preference — improve Charles. We do not sell your prompts. BYOK traffic never passes through our gateway for model training.

How We Use Your Information

  • To provide, maintain, and secure the Service
  • To authenticate your account and prevent unauthorized access
  • To enforce subscription limits and prevent abuse
  • To process payments through Stripe
  • To send transactional emails (password resets, security alerts, billing receipts)
  • To detect and prevent fraud, spam, and security threats
  • To improve agent quality, routing, tools, and (over time) first-party Charles models using de-identified operational signals and permitted managed-service data
  • To comply with legal obligations

Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA) and United Kingdom, we process personal data on the following legal bases:

  • Performance of a contract: Processing necessary to provide the Service under our Terms of Service
  • Legitimate interests: Fraud prevention, security monitoring, and service improvement
  • Legal obligation: Compliance with applicable laws and regulations
  • Consent: Marketing communications (where you have opted in)

Data Sharing and Third Parties

We do not sell, rent, or trade your personal data. We share data only with:

  • Stripe: For payment processing. See Stripe's privacy policy.
  • Hosting providers: For infrastructure services (encrypted at rest and in transit).
  • Law enforcement: When required by law or to protect our rights and safety.

Data Security

We implement industry-standard security measures to protect your data:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Passwords hashed with scrypt (salted, 64-byte output)
  • Session tokens signed with HMAC-SHA256 and bound to IP/user-agent
  • Single-session and single-device enforcement
  • Rate limiting and CSRF protection on all state-changing endpoints
  • Regular security audits and automated dependency scanning

Data Retention

We retain personal data only as long as necessary for the purposes outlined in this policy:

  • Account data: Retained while your account is active
  • Deleted accounts: Personal identifiers are removed immediately; remaining anonymized records are purged after 30 days
  • Legal acceptance records: Retained as legal proof even after account deletion, but with personal identifiers removed
  • Auth event logs: Retained for 90 days for security monitoring
  • Email logs: Retained for 1 year for delivery verification
  • Usage and invoice records: Retained for accounting and tax purposes until the 30-day purge of deleted accounts
  • Aggregate, anonymized statistics: May be retained indefinitely

Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your personal data (right to be forgotten)
  • Restrict or object to certain processing activities
  • Data portability (receive your data in a structured format)
  • Withdraw consent for marketing communications and analytics

To exercise these rights, contact us at privacy@sovrintech.com. We will respond within 30 days.

California Residents (CCPA/CPRA)

We do not sell or share your personal information. California residents have the right to know, delete, and correct their personal information. For details and to submit a request, see our California Privacy Rights page.

Cookies and Tracking

Our website uses the following categories of cookies and similar technologies:

  • Necessary: __Host-charles_site_session for authentication. Required for signed-in features and cannot be disabled.
  • Consent cookie: charles-consent stores your choices for analytics and marketing preferences.
  • Analytics: First-party page-view analytics are collected only after you opt in. You can change this choice at any time below or via the banner.
  • Marketing: We do not load third-party advertising cookies. The marketing preference is used only for our own newsletter and product-update emails, which require a separate opt-in.

The desktop application does not use cookies. Desktop update telemetry can be disabled in settings.

Loading preferences...

Children's Privacy (COPPA)

The Service is not directed to children under the age of 13, and we do not knowingly collect personal data from children under 13. If you are under 13, please do not use the Service or provide any personal information.

If you are between 13 and 18 (or the legal age of majority in your jurisdiction), you may use the Service only with the involvement and consent of a parent or guardian and only if you are legally able to enter into a binding contract.

If you believe we have collected personal data from a child under 13, contact us immediately at privacy@sovrintech.com and we will promptly delete the information.

International Data Transfers

Your data is stored on servers in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) for transfers from the EEA and UK.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. The "Last updated" date at the top indicates when changes were made.

Contact

For privacy-related questions or to exercise your rights, contact:

SovrinTech LLC
Email: privacy@sovrintech.com