Privacy Policy
Last updated: 20 July 2026
This Privacy Policy explains how Angada AI ("Angada AI", "we", "us") handles personal data when you use our service and website. Angada AI delivers GitHub pull-request notifications and reports into your team's messaging tools.
We process personal data responsibly and in line with applicable data-protection laws.
1. Who we are
Angada AI is operated by Kaustav Chakraborty as an individual. For any privacy question or request, contact us at hello@angada.ai. We do not maintain a public postal address; please use the email above.
2. Information we collect
We collect only what we need to provide and improve the service, which may include:
- Account and identity data — such as your name, email, and the identifiers of the accounts you connect (for example, GitHub and your messaging workspace).
- Integration and configuration data — settings and credentials needed to connect the service to your tools.
- Usage data — information about how the service is used, to operate, secure, and improve it.
- Communications — messages you send us, such as support requests.
We do not knowingly collect special-category (sensitive) personal data, and we do not sell personal data.
3. How we use your information
We use personal data to provide, operate, maintain, secure, and improve the service; to deliver the notifications and reports you sign up for; to communicate with you; to process payments where applicable; and to comply with our legal obligations.
4. How we share information
We use trusted third-party service providers ("sub-processors") to host, operate, secure, analyze, and support the service. They process personal data only on our behalf and only as needed to perform services for us. Our current sub-processors:
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Application database (accounts, identifiers, encrypted tokens, config) | EU |
| Fly.io | Application / API hosting | EU (Frankfurt) |
| Vercel | Website & app hosting (data in transit) | US (under SCCs) |
| Cloudflare R2 | Encrypted backups | EU |
| PostHog | Product analytics (pseudonymous) | EU |
| Sentry | Error & performance monitoring | EU |
| Resend | Transactional email | US (under SCCs) |
| Zoho Mail | Support correspondence | EU |
| Slack | Message delivery to your workspace | US |
| GitHub | Source of pull-request & identity data | US |
| Doppler | Secrets & configuration (no personal data) | US |
| Paddle | Payments & billing — merchant of record | UK (adequacy decision) |
Our payment provider, Paddle, is our Merchant of Record — the seller of record for your purchase. It collects and holds your payment-card details as an independent controller under its own privacy policy; we receive only limited billing information (such as your name, email, country, and plan).
We may also share information where required by law, to protect our rights or our users, or in connection with a business transfer. We do not sell your personal data.
5. International processing
Most personal data is stored and processed in the EU. Two providers process limited personal data in the United States under Standard Contractual Clauses (SCCs): Vercel (data in transit) and Resend (transactional email). Doppler (US) holds configuration and encryption keys only — no personal data. Slack and GitHub process the data you direct to them through the integrations you connect, under their own terms. Payment and billing data for paid plans is processed in the United Kingdom by our Merchant of Record, Paddle, which benefits from the European Commission's UK adequacy decision. Where personal data is transferred across borders, we rely on appropriate safeguards such as SCCs.
6. Data retention
We keep personal data for as long as your account is active and as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements. Indicative retention periods: operational/delivery logs 30–90 days; error-monitoring data ~90 days; product-analytics data 12 months; encrypted backups 14–30 days; support correspondence 24 months.
When you delete your account, we irreversibly anonymise your personal data and hard-delete integration tokens. We retain one-way hashed identifiers (a SHA-256 hash of your GitHub user ID and email) for up to 24 months solely to stop banned or fraudulent accounts from re-registering; these hashes cannot be reversed to identify you (our legitimate interest under Art 6(1)(f)). Personal data in backups expires on the 14–30 day rollover.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or object to the processing of your personal data, and to withdraw consent where we rely on it. To exercise any of these rights, email hello@angada.ai. You may also have the right to lodge a complaint with your local data-protection authority.
8. Security
We use reasonable technical and organizational measures to protect personal data, including encrypting sensitive credentials at rest and restricting access. No system is completely secure, but we work to protect your data and will notify you of a qualifying breach as required by law.
9. Cookies
We use cookies and similar technologies that are necessary to operate the service and to understand how it is used. You can control cookies through your browser settings; disabling some may affect functionality.
10. Children
Angada AI is a tool for software teams and is not directed to children. We do not knowingly collect personal data from children.
11. Changes
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated to you.
12. Contact
Questions about this policy or your data: hello@angada.ai.