Privacy Policy
What personal data Sarcio collects, why, who we share it with, how long we keep it, and the choices and rights you have.
Effective September 13, 2026
1. Who we are
Sarcio is operated by Dayne Mentier, a sole proprietor doing business as Sarcio in New Jersey, USA (“Sarcio”, “we”, “us”). This policy covers the sarcio.io website, the Sarcio dashboard and API, and the bug-report widget and other components our customers install (together, the “Service”). Privacy questions and data requests go to privacy@sarcio.io.
2. Our two roles
- Controller. For the people who visit our website, sign up, and use the dashboard as members of a customer's workspace, we decide how their personal data is used, and this policy applies directly.
- Processor. Our customers install the Sarcio widget and other components on their own websites. When a customer's site sends us a bug report, or a customer gives us access to its repositories and trackers, we process that data on the customer's behalf and under its instructions. The customer is the controller. If you use a site that runs Sarcio, read that site's privacy policy and send your requests to its operator; we will help them respond. A data processing agreement is available on request for Enterprise customers.
3. What we collect
- Account data: your name, email address, workspace name and role. Passwords are stored only as argon2id hashes. Two-factor secrets are encrypted at rest, and recovery codes are stored only as digests. If you sign in with Google or GitHub, we receive your verified email address, name and provider account id. When you create a workspace, we record when you agreed to our Terms of Service and this policy, and which version.
- Billing data: your plan, subscription status and the Stripe customer and subscription ids. Stripe collects and holds your payment details; we never see full card numbers.
- Bug reports submitted through the widget on a customer's site: the description the reporter types, the page URL, the selector and HTML of the element they picked (up to 2 KB), recent console errors and warnings, metadata about recent network requests (method, URL, status and timing, never request or response bodies or authorization headers), the browser's user agent and window size, and an optional screenshot. To limit abuse we count reports per IP address using a one-way digest of the address that expires after a day; the address itself is not stored with the report.
- Workspace content: sites and their settings, patches, approvals and who gave them, source files read from connected repositories to draft fixes, and writing instructions.
- Integration credentials and linked accounts: tokens for GitHub, GitLab, Bitbucket and Jira connections, stored envelope-encrypted (AES-256-GCM). The Sarcio GitHub App keeps no long-lived token. When a member links their own Git host or Jira account, we keep its login, display name, avatar and account id, and no token unless the workspace turns on acting links and the member opts in, in which case that token is encrypted too.
- Audit and usage data: an append-only audit log of security-relevant actions with the actor, source IP address and time, and AI usage records (token counts per model call).
- Technical data: our servers keep standard request logs (IP address, user agent, requested URL and time) to operate and secure the Service.
We do not use advertising or third-party analytics trackers, and we do not buy personal data.
4. How we use it, and our legal bases
Where the EU or UK GDPR applies, we rely on these legal bases:
- To provide the Service (create and secure accounts, capture reports, draft and deliver patches, open pull requests, send service email): performance of our contract with you or your organization.
- To bill you and keep accounting records: contract and legal obligation.
- To keep the Service secure (rate limits, account lockout, audit logs, fraud and abuse prevention, debugging): our legitimate interest in protecting the Service and our customers.
- To answer your messages and improve the Service: legitimate interest.
- To comply with the law, keep a record of your agreement and enforce our Terms of Service: legal obligation and legitimate interest.
Bug-report data we process as a processor is handled only to provide the Service to the customer that owns the site; the customer determines its legal basis.
5. AI processing
To triage a report and draft a fix, we send the report description, the selected element, recent console and network lines, and for server and module fixes the relevant source files to an AI model provider through OpenRouter. Screenshots are not sent. The same route writes pull request, commit and ticket text from the patch. Prompts are sent only to generate the output you asked for. Sarcio does not use customer data to train AI models, and where a provider offers the option we configure it not to retain prompts or train on them. AI output is not used to make decisions about individuals.
6. Who we share it with
We share personal data only with the service providers below, each to the extent needed for its purpose, and when the law requires it or to protect our rights and users. We do not sell personal data. If the business is sold or merged, personal data would transfer under this policy. Within Sarcio, access to customer workspaces is limited to what support and operating the Service require.
- Amazon Web Services (EC2): Hosting of the Service and its database, in the us-west-2 region (Oregon, USA).
- Stripe: Subscription billing and payment processing. Card details go to Stripe, never to us.
- Resend: Transactional email: verification, sign-in security, billing and product notices.
- OpenRouter and the AI model provider it routes to (Anthropic Claude models by default): Triage of bug reports and drafting of fixes, source edits and change text.
- ImprovMX: Forwarding of email sent to sarcio.io addresses.
- GitHub, GitLab, Bitbucket and Atlassian (Jira): Only when you connect them: reading source files, opening pull or merge requests, and mirroring patches into tickets.
- Google and GitHub: Only when a member chooses to sign in with that provider.
7. Cookies and local storage
- Session cookie (
sarcio_session): a first-party, HTTP-only cookie scoped to sarcio.io and its workspace subdomains that keeps you signed in, for up to 12 hours. - Signed-in header (
sarcio:sessionin local storage on this website): your workspace name and URL and your first name, so the header shows you as signed in. It holds no token and is cleared when you sign out. - The dashboard and widget use session storage for short-lived interface state, such as a dismissed notice or a patch preview.
These are strictly necessary for the Service, so there is no cookie banner. We set no advertising or analytics cookies.
8. How long we keep it
- Bug reports are kept for your plan's retention window: 30 days on Solo, 90 on Team, 365 on Scale. After that, reports that never produced a patch are deleted, and reports that did are stripped of their captured context, screenshot, element HTML and AI triage reply, keeping only the description, URL and status that live patches refer to.
- Account and workspace data is kept while the workspace exists. Admins can export it as JSON or delete the workspace from the dashboard, which removes its data at once. Removing a member deletes their account.
- Cancelled workspaces are kept for 90 days after cancellation, during which they can be restored or exported on request to privacy@sarcio.io, and are then permanently deleted.
- Unfinished sign-ups are deleted automatically after they expire.
- Request logs are kept for a limited, rotating period of up to 30 days.
- Audit logs are kept for the life of the workspace, and billing records as long as tax and accounting law requires.
- Backups, where kept, are rotated, and data deleted from the Service is removed from them within 30 days after the retention period above ends.
9. Security
We protect data with TLS in transit, envelope encryption for secrets at rest, argon2id password hashing, optional two-factor authentication, role-based access, workspace isolation, rate limiting and an append-only audit log. No system is perfectly secure; our security page describes the controls in detail. Report a vulnerability to security@sarcio.io.
10. International transfers
Sarcio is based in the United States and hosts the Service there, in Amazon Web Services' us-west-2 region (Oregon). Some of our providers process data in other countries. If you are outside the US, your data is transferred to the US. Where the law requires a transfer mechanism, such as under the GDPR, we rely on the European Commission's standard contractual clauses.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to withdraw consent where we rely on it. Many of these you can do yourself in the dashboard (your account, email address and two-factor settings; for admins, export and deletion). For anything else, email privacy@sarcio.io; we may need to verify your identity, and we respond within the time the law requires. If you are in the EU or UK, you can also complain to your data protection authority. If your data reached us through a customer's site or workspace, we will refer your request to that customer.
12. US state privacy rights
Residents of California and other US states with privacy laws may have the right to know what personal data we collect and how we use and disclose it, to access, correct and delete it, and to opt out of its sale, sharing for cross-context behavioral advertising, or profiling. We do not sell or share personal data for advertising and do not profile people. The categories we collect are identifiers and account data, commercial information (plan and billing), internet activity (request logs, bug report context) and any personal data in content you submit, for the purposes in section 4. We will not discriminate against you for exercising your rights. You or an authorized agent can make a request at privacy@sarcio.io.
13. Children
The Service is for businesses and is not directed at children under 16. We do not knowingly collect their personal data; if you believe we have, contact privacy@sarcio.io and we will delete it.
14. Changes to this policy
We will post any update on this page with a new effective date, and notify workspace admins by email or in the dashboard before a material change takes effect.
15. Contact
Dayne Mentier, doing business as Sarcio, New Jersey, USA. Privacy and data requests: privacy@sarcio.io. Security reports: security@sarcio.io. Legal notices: legal@sarcio.io.