Skip to content
Legal

Privacy Policy

This policy covers the public detent.build website and Detent Cloud at cloud.detent.build, operated by Digital Drywood.

Effective September 30, 2026

Visiting the website

The public website can be read without an account. Its application does not use advertising trackers, third-party analytics scripts, or tracking cookies. Your light or dark theme preference is saved in your browser's local storage.

Our servers and hosting infrastructure process technical information needed to deliver the site and diagnose problems. Application request logs include your IP address, requested URL, request identifier, response status, response size, and timing. Avoid placing sensitive information in URLs.

Accounts and Google sign-in

Detent Cloud uses WorkOS for authentication. We process your email address, WorkOS user identifier, organization memberships and roles, and session information to identify you and control access. Authentication cookies maintain your Cloud session and protect sign-in transactions.

When Google sign-in is available and you choose it, Google shares the basic account information you authorize with WorkOS, such as your email address, name, and profile picture. Detent uses the resulting verified identity to sign you in and associate you with your Detent account. Google sign-in requests basic identity scopes only; it does not request access to Gmail, Drive, or Calendar.

Google sign-in data is used for authentication, account administration, and security. We do not sell that data, use it for advertising, or use it to train general-purpose AI models. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Organization content and execution

Cloud stores the collaboration data you and your organization submit, including projects, issues, comments, conversations, workflow settings, run history, and access records. Text or attachments you submit may contain source code or other sensitive material. Organization members can access information according to their assigned permissions.

Runners execute work on their configured machines using the provider and repository access configured there. Cloud does not automatically clone repositories or collect raw worktrees and execution credentials. Content you deliberately submit, import, or upload can be stored or relayed by Cloud; choosing hosted artifact storage changes where those artifacts are held.

A workflow, conversation, or integration can send the content needed for your request to the model, repository, or storage provider you configure. Those providers have their own terms and data practices. Check your workflow and provider settings before submitting sensitive information.

Billing and service operation

When you purchase Cloud hosting, Stripe processes checkout and payment details. Detent stores the customer and subscription references, plan and payment status, and billing events needed to administer access. Card information entered in Stripe-hosted checkout is processed by Stripe.

Cloud records operational information such as request and heartbeat counts, response sizes, service health, artifact usage, and security or administrative events. We use this information to operate the service, administer plans, investigate failures, and prevent abuse.

How information is shared

Information is processed by the service providers needed to deliver Detent, including WorkOS for authentication, Stripe for billing, and DigitalOcean for hosted infrastructure. Organization content is shared with authorized collaborators and with integrations or execution providers selected for your work.

We may disclose information when required by law or when necessary to investigate abuse, protect the service, or respond to a security incident. If you contact us for support, we process the information you provide to handle your request.

Protecting information

The public website and Cloud use HTTPS to protect browser traffic in transit. Cloud requires authenticated access and checks organization permissions before returning protected data. Protect your own sessions, runner machines, and integration credentials, and contact us if you suspect unauthorized access.

Retention, access, and deletion

Cloud collaboration history is durable data, not a temporary analytics buffer. We retain information as needed to provide the service and handle security, billing, and legal obligations. Deleting an item or closing an account does not necessarily erase every related audit record or backup immediately.

Contact cory@lanou.com to request access to, correction of, or deletion of your personal information or Cloud account. We may need to verify your identity and authority over organization data. Shared organization records may need to remain available to other authorized members, and limited records may be retained for billing, security, or legal reasons.

You can revoke Detent's Google connection through your Google Account settings. Revoking Google access stops that connection; it does not by itself delete your Detent account or organization content. Contact us separately if you also want that data removed.

Self-hosted Detent and policy updates

When you run Detent yourself, your instance operator controls its storage, authentication, logs, integrations, and retention. This policy describes the public website and our Cloud service; it does not replace the policies of a separately operated instance or your chosen providers.

We publish updates to this policy on this page and update its effective date. Questions about this policy or your information can be sent to cory@lanou.com.