Standard Code

Privacy Policy

Last updated August 8, 2026

The short version: Your code and conversations belong to you. We never train on your data, and neither do our model providers. Your workspace is private to your account and stays there unless you choose to share something with us. AI requests go only to US-based providers with no-training commitments — and most retain nothing after delivering your response.

1. Who we are

Standard Code™ is a hosted coding agent operated by FormKit, Inc. d/b/a Standard Agents (“we,” “us”). This policy covers the Standard Code CLI, web console, desktop and mobile apps, and the hosted Standard Code service. Your use of Standard Code is also governed by our Terms of Use.

2. What we collect

  • Account information — name, email, sign-in identifiers, and billing status. Stripe processes payments; we never see full card numbers.
  • Your workspace — the threads, messages, files, and agent activity you create.
  • Model request records — requests to and responses from AI models, plus operational metadata (timestamps, token counts, errors) used to run and bill the service — never to profile you.
  • Support communications — anything you send us directly.

3. Where your data lives

Your workspace is stored privately within your account on our infrastructure, encrypted in transit and at rest. Each thread lives in its own isolated storage partition — there are no shared data pools across customers. Your content leaves your account only when you direct it to, such as attaching a thread to a bug report.

Your machine stays yours. The agent runs in our cloud, but your execution environment — the computer where it reads files and runs commands — is your own. We never scan or upload your filesystem. Only the files and command output the agent actually uses for your session become part of your thread, where this policy protects them.

4. Our commitments

  • We never train on your data — and neither do our providers. Your code, prompts, and conversations are never used to train or improve any AI model.
  • Your data stays private to your account. We don’t mine or merge customer workspaces.
  • US-based model providers only.
  • No-training commitments from every provider, contractually.
  • We never sell your data. No advertising, no data brokers.

5. How AI processing works

When your agent works on a task, the relevant context — your prompt, code, and conversation history — is sent to a model provider to generate the response.

Most of our providers operate with zero data retention: your content is processed to generate the response and not retained afterward, aside from narrow legal and trust-and-safety exceptions. Where zero data retention is not yet in place, content is retained up to 30 days solely for abuse monitoring, then deleted. In every case: no training, no resale, no other use. Providers keep only non-content metadata (timestamps, token counts, error codes) for billing and reliability.

6. Operating a hosted service

Because Standard Code is hosted, our systems store and process your workspace to provide it. Authorized team members may access account data when needed to operate, secure, bill, or support the service — investigating an outage, a security event, or an issue you reported. Access is limited to the task at hand. We don’t browse customer workspaces.

7. Service providers

  • Cloudflare — hosting, networking, storage
  • Stripe — payments
  • Email providers — receipts, sign-in, account notices
  • AI model providers — per Section 5

Each processes data only as needed to serve us.

8. Retention and deletion

Your workspace stays in your account until you delete it. Deleting a thread permanently removes its storage; deleting your account removes your workspace. Usage and operational records are kept up to 12 months for billing and reliability. Billing records are retained as required by law.

9. Your choices

  • Delete your content anytime — remove individual threads, or erase all of your content at once from your account area.
  • Delete your account — contact us and we’ll erase your account and all associated data, confirmed by email.
  • Get a copy of your data by contacting us.
  • Share content with us only when you choose to — for feedback or support.

10. California privacy rights

If you are a California resident, you have the right to know what personal information we collect (Section 2), to access it, correct it, and request its deletion. We do not sell or share your personal information as defined under California law, so there is nothing to opt out of — and we will never treat you differently for exercising your rights.

To make a request, email privacy@standardcode.ai from your account email (we use it to verify the request). We respond within 45 days. Where the law permits us to retain certain records — completed transactions, security, legal compliance — we retain only what those exceptions cover.

11. Contact

Questions about this policy or your data: privacy@standardcode.ai

12. Changes to this policy

If we make material changes, we’ll notify you by email or in the product before they take effect. We will never retroactively weaken the commitments in Section 4 — changes to those apply only going forward, with clear notice.