Skip to content

Privacy Policy

Last updated: September 2, 2026 | Version 1.2

Introduction

SovrinTech LLC ("we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use the Charles website, desktop application, and related services (collectively, the "Service").

Data Controller: SovrinTech LLC is the data controller for personal data processed through the Service.

By using the Service, you consent to the practices described in this policy. If you do not agree, please do not use the Service.

Information We Collect

Account Information: Email address, hashed password, display name, and account preferences. We never store passwords in plain text.

Subscription & Billing: Plan tier, token usage counters, and payment information processed by Stripe. We do not store complete payment card numbers.

Device & Session Data: Device identifiers (for desktop app authorization), IP addresses, user agents, and session timestamps for security and fraud prevention.

Usage Metrics: Aggregate token consumption counts and feature usage to enforce plan limits and improve the product. These are numerical aggregates, not your code or conversations.

Product improvement signals (Version 1.2): When you use a paid plan and have not opted out of analytics, the desktop may send account-linked operational signals such as whether a turn succeeded, whether tools ran, failure counts, mode (chat/agent/auto), platform, and app version. We use these signals to improve routing, tool reliability, and agent quality. This telemetry channel does not accept source code, project files, prompts, or full conversation transcripts.

Future Charles models: We may use de-identified operational statistics and, only where permitted by this policy and your preferences, carefully processed service logs from managed AI (not BYOK) to develop and evaluate Charles-trained models focused on productive, high-quality software work. You can opt out of product-improvement analytics in account settings; billing and abuse prevention still require usage metering.

Website Analytics: When you consent, we collect page views, approximate location (country/city derived from your IP address), referrer, browser type, and a hashed visitor identifier. IPs are not stored in plain text; we store a one-way hash for deduplication.

Desktop Update Telemetry: When you enable telemetry, the desktop app may report update events (started, downloaded, installed, failed) with an opaque device identifier, your account identifier, app version, platform, and architecture. Raw local error details, code, messages, and personal files are not included. Telemetry is off unless you enable it in desktop settings.

Communications: Support tickets, feedback submissions, and email correspondence.

What Local-First Means

Charles does not upload your workspace as a background collection process. In particular, product analytics do not collect:

  • A blanket copy or inventory of your source code, project files, or repository
  • Unrelated file-system contents outside the workspace and permissions you choose
  • Keystrokes, screen recordings, or clipboard contents

Content you intentionally send to an AI provider is processed according to the route you choose. Tool output needed to complete a request may become part of that request, so review workspace scope and approvals before an agent acts.

Bring Your Own Keys (BYOK): If you connect your own provider API keys, AI requests are sent directly from your machine to your chosen provider. We are not in that data path and do not store your prompts or outputs.

Managed AI: When you use Charles-managed models (Pro, Max), your prompts and generated outputs pass through our secure gateway so we can route, meter, bill usage, and operate background system AI (memory/skills on Charles's cost). We process this data to provide the service, enforce plan limits, prevent abuse, and — subject to your product-improvement preference — improve Charles. We do not sell your prompts. BYOK traffic never passes through our gateway for model training.

How We Use Your Information

  • To provide, maintain, and secure the Service
  • To authenticate your account and prevent unauthorized access
  • To enforce subscription limits and prevent abuse
  • To process payments through Stripe
  • To send transactional emails (password resets, security alerts, billing receipts)
  • To detect and prevent fraud, spam, and security threats
  • To improve agent quality, routing, tools, and (over time) first-party Charles models using de-identified operational signals and permitted managed-service data
  • To comply with legal obligations

Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA) and United Kingdom, we process personal data on the following legal bases:

  • Performance of a contract: Processing necessary to provide the Service under our Terms of Service
  • Legitimate interests: Fraud prevention, security monitoring, and service improvement
  • Legal obligation: Compliance with applicable laws and regulations
  • Consent: Marketing communications (where you have opted in)

Data Sharing and Third Parties

We do not sell, rent, or trade your personal data. We share data only with:

  • Stripe: For payment processing. See Stripe's privacy policy.
  • Hosting providers: For infrastructure, storage, and delivery needed to operate the Service.
  • Law enforcement: When required by law or to protect our rights and safety.

Data Security

We use layered safeguards appropriate to the data and route involved:

  • HTTPS for traffic to Charles remote services, plus an authenticated local-loopback boundary between the desktop and local agent service
  • AES-256-GCM encryption for stored provider credentials and OAuth verifier material
  • Passwords hashed with scrypt (salted, 64-byte output)
  • HMAC-SHA256-signed session tokens backed by server-side session revocation
  • Tier-based limits and server-side revocation for authorized desktop devices
  • CSRF protection for browser mutations and request throttling on sensitive or abuse-prone endpoints
  • Automated security tests and dependency scanning as release checks

Data Retention

We retain personal data only as long as necessary for the purposes outlined in this policy:

  • Account data: Retained while your account is active
  • Deleted accounts: Personal identifiers and active credentials are removed or anonymized when deletion is processed
  • Account-linked acceptance, usage, invoice, authentication, and delivery records: Scheduled for purge after the 30-day deletion window, except where a longer period is required by law
  • Product outcome and crash-health records: Limited to bounded operational fields; records older than 30 days are removed when the application processes new records of that type
  • Aggregate, anonymized statistics: May be retained indefinitely

Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your personal data (right to be forgotten)
  • Restrict or object to certain processing activities
  • Data portability (receive your data in a structured format)
  • Withdraw consent for marketing communications and analytics

To exercise these rights, contact us at privacy@sovrintech.com. We will respond within 30 days.

California Residents (CCPA/CPRA)

We do not sell or share your personal information. California residents have the right to know, delete, and correct their personal information. For details and to submit a request, see our California Privacy Rights page.

Cookies and Tracking

Our website uses the following categories of cookies and similar technologies:

  • Necessary: __Host-charles_site_session for authentication. Required for signed-in features and cannot be disabled.
  • Consent cookie: charles-consent stores your choices for analytics and marketing preferences.
  • Analytics: First-party page-view analytics are collected only after you opt in. You can change this choice at any time below or via the banner.
  • Marketing: We do not load third-party advertising cookies. The marketing preference is used only for our own newsletter and product-update emails, which require a separate opt-in.

The desktop application does not use cookies. Desktop update telemetry can be disabled in settings.

Loading preferences...

Children's Privacy (COPPA)

The Service is not directed to children under the age of 13, and we do not knowingly collect personal data from children under 13. If you are under 13, please do not use the Service or provide any personal information.

If you are between 13 and 18 (or the legal age of majority in your jurisdiction), you may use the Service only with the involvement and consent of a parent or guardian and only if you are legally able to enter into a binding contract.

If you believe we have collected personal data from a child under 13, contact us immediately at privacy@sovrintech.com and we will promptly delete the information.

International Data Transfers

Your data is stored on servers in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) for transfers from the EEA and UK.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. The "Last updated" date at the top indicates when changes were made.

Contact

For privacy-related questions or to exercise your rights, contact:

SovrinTech LLC
Email: privacy@sovrintech.com