Skip to content
drifted Back to Drifted

Legal / Privacy

Last updatedSeptember 15, 2026

Legal / Privacy

Privacy Policy

This policy explains what Drifted handles when you create an account, connect your systems, and run end-to-end validation.

1. Scope

This Privacy Policy applies to the Drifted website, product, APIs, runners, and related services (the “Service”). “Drifted,” “we,” “us,” and “our” refer to the operator of the Service.

If you use Drifted through your employer or another organization, that organization may control the workspace and the information submitted to it. Its own policies may also apply. When a customer uses Drifted to test its systems, the customer decides what data to submit and is responsible for having permission to do so.

2. Information we collect

Account and contact information

We receive account identifiers, name, email address, profile image, authentication status, and similar account details from Clerk and the sign-in provider you choose, such as Google, GitHub, or GitLab. If you contact us, we receive the information in your message.

Workspace and configuration information

We store the apps, environments, workflows, schedules, URLs, assertions, alert settings, and team choices you configure. If you connect a repository, we process repository and installation identifiers, branch information, authorization tokens, source snapshots, and pull request details needed to provide that connection and prepare a requested draft repair.

Test credentials and customer data

You may provide API tokens, test account credentials, browser storage state, cookies, headers, variables, or other secrets for a selected environment. These values are encrypted at rest and used to run the workflows you configure. A workflow can interact with your application and may encounter data in the pages and responses it tests.

Run evidence and operational information

We process workflow steps, requests, responses, status codes, timing, failure details, browser diagnostics, console and network evidence, and other results needed to show what passed or failed. We attempt to redact configured secret values from saved evidence, but you should use dedicated test accounts and avoid placing sensitive production data in test flows.

Billing and transaction information

Stripe processes payment details. We receive transaction status, customer and subscription identifiers, plan, renewal dates, and limited billing contact information. Drifted does not store full payment card numbers.

Device, log, and usage information

We collect IP address, browser and device information, request logs, timestamps, authentication events, audit events, feature usage, error information, and security signals when you use the Service. We also use cookies and similar local storage required to keep you signed in, protect the Service, remember settings, and operate checkout.

3. How we use information

We use information to:

  • provide accounts, workspaces, workflow execution, evidence, alerts, and billing;
  • connect the repositories, identity providers, webhooks, and runners you select;
  • generate workflow drafts or repair suggestions when you ask for an AI feature;
  • secure the Service, prevent abuse, enforce limits, and investigate incidents;
  • diagnose errors, maintain reliability, and improve product performance;
  • communicate about the Service, support requests, billing, and policy updates; and
  • comply with law and protect the rights and safety of Drifted, customers, and others.

We rely on the need to perform our agreement with you, our legitimate interests in operating and securing the Service, your consent where required, and compliance with legal obligations. The legal basis depends on the information and where you live.

4. AI-assisted features

AI assistance is optional. Manual workflow creation and execution do not require an AI provider.

When you request AI-assisted drafting, review, or repair, Drifted may send the prompt and relevant context to OpenAI, Anthropic, or OpenRouter. Depending on the feature, that context can include an app name and URL, your description, site text, a diagram or screenshot, workflow configuration, failure evidence, or relevant repository source. Direct OpenAI requests are configured not to store responses for model training where that provider option is available.

Do not include information in an AI request unless you are permitted to share it. AI output can be inaccurate and should be reviewed by a person before it is used, merged, or deployed.

5. When we disclose information

We may disclose information to:

  • Service providers. Providers that host, secure, authenticate, store, process, or support the Service, including Clerk, Supabase, Microsoft Azure, Cloudflare, Stripe, OpenAI, Anthropic, OpenRouter, and infrastructure used for browser execution.
  • Integrations you choose. GitHub, GitLab, Google, configured HTTPS webhook destinations, CI systems, and private runners receive information needed to perform the action you request.
  • Your organization. Workspace owners and authorized users may access workspace configuration, run history, evidence, billing status, and audit records.
  • Legal and safety recipients. We may disclose information when we reasonably believe it is required by law or necessary to protect rights, safety, security, and the integrity of the Service.
  • Business transaction participants. Information may be transferred as part of a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.

We do not sell personal information or share it for cross-context behavioral advertising. We do not use customer workflow content or repository source to train our own general-purpose AI models.

6. Retention and deletion

We retain information while your account is active and as needed to provide the Service. Retention also depends on the type of record: short-lived authorization sessions expire; saved configurations and run evidence remain available as product history; and billing, security, and audit records may be kept longer for compliance, fraud prevention, dispute resolution, and reliable operations.

You can remove many resources, credentials, and repository connections in the product. Deleting a resource can also delete related content, but some audit, backup, transaction, or legally required records may remain for a limited period. To request account deletion or ask about a specific record, email [email protected].

7. Security

We use administrative, technical, and organizational safeguards designed to protect information. These include access controls, encryption for stored environment secrets and repository credentials, HTTPS in transit, scoped tokens, secret redaction, and audit records. No system is completely secure, so we cannot guarantee that information will never be accessed, lost, or altered without authorization.

You are responsible for securing your account, choosing appropriately scoped test credentials, restricting connected repositories and environments, and promptly revoking access you no longer need.

8. International processing

Drifted and its service providers may process information in the United States and other countries. Those countries may have different data protection laws from where you live. Where required, we use contractual or other recognized safeguards for international transfers.

9. Your choices and rights

You can update many account and workspace details in the Service, disconnect integrations, delete stored credentials, and cancel a paid plan through the billing portal. You may also ask us to access, correct, delete, restrict, or provide a copy of your personal information, or object to certain processing. These rights vary by location, and we may need to verify your identity before acting on a request.

To exercise a privacy right, email [email protected]. You may also have the right to complain to your local data protection authority.

10. Children

The Service is intended for business and professional use and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, contact us so we can address it.

11. Changes to this policy

We may update this policy as the Service or law changes. We will post the updated version here and change the “Last updated” date. If a change materially affects how we use personal information, we will provide additional notice when required.

12. Contact

Questions or requests about this policy can be sent to [email protected].

drifted
PrivacyTermsContact