Privacy policy
Last updated: 27 September 2026
Whitebox Ultimate is a desktop app. Your code, files, terminals, notes and API keys stay on your computer. This policy explains the little data we do handle.
What we collect
- Account: your email address and a hashed password, stored by our authentication provider (Supabase) to sign you in.
- Subscription: your subscription status and billing period, received from Paddle. Paddle processes payments as merchant of record; we never see card details.
- Licence checks: a random device identifier generated by the app, used to enforce the device limit.
- Settings sync (optional): if you click “Upload settings”, non-secret preferences (such as theme, profiles and model choices) are stored with your account. API keys and environment variables are never synced.
- Waitlist: the email you enter on this website, used only to tell you about the launch.
What we don’t collect
No analytics or telemetry inside the app. Your source code, prompts, AI replies, terminal output and files are never sent to us. When you use AI features, requests go directly from your computer to the AI provider you chose, under that provider’s terms, using your own key. Dependency checks send package names and versions to OSV.dev.
Where secrets live
API keys, MCP server secrets and project environment variables are stored in Windows Credential Manager on your device.
Your rights
You can ask us to export or delete your account data at any time by emailing privacy@whiteboxultimate.com. Deleting your account cancels access to the app.
Changes
If this policy changes in a meaningful way, we’ll update the date above and tell account holders by email.