What this Site collects, why, and how it’s handled, and, because the two are easy to conflate, a plain explanation of what data the Strazh desktop application itself does and does not send anywhere.
Graphenlabs (“Graphenlabs,” “we,” “us,” or “our”) builds Strazh, a local-first desktop application, and operates this website at strazh.graphenlabs.com (the “Site”) as its marketing, account, and license-management portal. This Privacy Policy explains what data the Site collects, why, and how it’s handled. It also explains, because the two are easy to conflate and we’d rather be precise than reassuring, what data the Strazh desktop application itself does and does not send anywhere.
If you’re only ever going to read one paragraph of this policy, read this one: the Strazh desktop application is local-first and does not transmit your data to us. This Site, however, is an ordinary web application with an account system, and running an account system requires processing some data: an email address to authenticate you, payment details to bill you, and basic server logs to keep the thing running. Our homepage states Strazh runs locally in reference to passive tracking and advertising: we don’t run analytics cookies, ad pixels, or behavioral trackers. It is not a claim that zero data of any kind touches our servers, and this policy is where we reconcile that honestly rather than let the two statements sit in tension.
This policy covers two separate things, and we’ve tried to keep them separate throughout:
These are different systems with different data footprints. The Site necessarily collects account and billing information to function. The desktop app, by design, does not. See “The Strazh desktop app: what never leaves your machine” below for the full explanation of the second point.
Account information. When you create an account, authentication is handled by Clerk, our identity provider. Clerk collects and stores your email address and any authentication credentials you use to sign in (password, magic link, or OAuth provider identity, depending on how you choose to sign in). We receive your email address and a Clerk-issued user ID from this process so we can associate a license with your account.
Payment information. Billing is handled by Dodo Payments, who acts as the merchant of record for all Strazh purchases. When you purchase a license, Dodo Payments collects and processes your payment details (card number, billing address, and related transaction data) directly. Graphenlabs does not receive, store, or have access to your full payment card details. We receive confirmation that a payment succeeded, a transaction reference, and the billing metadata needed to issue and manage your license (such as plan tier and billing cycle).
License metadata. To issue and manage your license, we store a small, deliberately minimal record tied to your account: license tier (Free, Individual, or Enterprise), seat count (for Enterprise), the email address associated with the license, license status (active, expired, deactivated), and issuance/expiry timestamps. This metadata is what allows the desktop app to verify your entitlement offline. See the license system description below.
Server logs and technical data. Like most web applications, our hosting and infrastructure providers generate standard server logs when you access the Site: IP address, browser/user-agent string, requested URL, timestamp, and response status. These logs exist for operational purposes (debugging, abuse prevention, uptime monitoring) and are not used to build advertising profiles or sold to anyone.
Support communications. If you contact us for support, we retain the content of that communication (and the email address it came from) for as long as needed to resolve the issue and for a reasonable period afterward for context if you follow up.
What we do not collect on this Site. We do not run third-party analytics trackers, advertising pixels, or behavioral-profiling scripts. We do not sell personal information. We do not collect the contents of your dispatched work: the repositories you target, the prompts you send to a coding agent, or the output a dispatch produces never reach this website or our servers, because they never leave your machine (see the narrow, named exceptions — Devin adapter, MCP-mode usage, and Individual Pro’s dispatch-count reporting — below).
We process the information above for the following purposes, each tied to a specific need:
We do not use your account or payment data for advertising, and we do not build behavioral profiles from Site usage.
We rely on a small number of named third-party services to run the Site and account system. We do not hand your data to data brokers or ad networks, and we’ve limited this list to the processors actually required to authenticate you, bill you, and host the Site:
We do not control these providers’ own data practices beyond the data we send them, and we encourage you to review their respective privacy policies if you want the full picture of how each handles data on their end.
We retain account and license metadata for as long as your account is active, plus a reasonable period afterward to handle billing disputes, license reactivation, or legal obligations (typically no more than a few years past account closure, unless a longer period is legally required). Server logs are retained on a rolling basis for operational purposes and are not kept indefinitely. Clerk and Dodo Payments retain the data they process according to their own retention policies, which are described in their respective privacy policies linked above. We don’t dictate their retention windows, but we also don’t ask them to retain data longer than needed to serve their function for us.
You can request to access, export, or delete the account and license data we hold about you by contacting us at the address below. Because the data footprint here is intentionally small, an email address, a license tier, and billing status, not a behavioral profile, most requests are straightforward to fulfill quickly. Note that:
If you’re a resident of a jurisdiction with a statutory right of access, correction, deletion, or portability (such as the EU/UK under GDPR or certain U.S. states), those rights apply here and we’ll honor requests consistent with applicable law.
The Site uses the session cookies Clerk sets to keep you signed in: these are functional, not tracking, cookies; they exist so you don’t have to re-authenticate on every page load. We do not add any analytics, advertising, or cross-site tracking cookies of our own. If that ever changes, we’ll update this section before it does, not after.
The Site and Strazh are not directed at children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, contact us at the address below and we will take steps to delete it.
Graphenlabs and the third-party processors we use (Clerk, Dodo Payments, our hosting providers) may process and store data in countries other than your own, including the United States. Where required by applicable law, we and our processors rely on appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) to govern these transfers. By using the Site, you understand that your information may be transferred to and processed in a country with different data protection laws than your home jurisdiction.
We may update this policy as the Site, the account system, or applicable law changes. If we make a material change, we’ll update the “Last updated” date above and, where the change is significant, provide more prominent notice (such as a banner on the Site or an email to account holders). Continued use of the Site after a change takes effect constitutes acceptance of the revised policy.
Everything above describes this website. The desktop application is a different system with a different privacy story, and it’s worth stating plainly rather than leaving it implied.
Strazh is a local-first desktop application. It sits between you and any coding agent you dispatch, Claude Code, Codex, Cursor, or Devin, behind an allow-listed working-directory gate. Its database (SQLite), which stores dispatch requests, target repository paths, and dispatch output and audit records (including rejected attempts), lives on your computer, not on ours. We do not have a server that receives, stores, or has visibility into any of it. Specifically:
git remote/branch, not file contents, to Cognition’s hosted session API; and if you enable MCP-server mode, an external MCP client (such as Claude Desktop, Cursor, or Codex CLI) you’ve configured can trigger a dispatch through Strazh’s gate. In both cases, only the specific request goes out, governed by that provider’s own terms, not ours, and only because you turned it on.The only data flow between the desktop app and Graphenlabs is the offline license check described above, and even that is designed to work without a network round-trip in the common case. We built it this way deliberately: the thesis behind Strazh is that you shouldn’t have to trust an unaudited process with write access to your repositories, and that starts with a gate that runs locally, not on a server we control.
Questions about this policy, or requests relating to your account or license data, can be sent to privacy@graphenlabs.com. For questions specifically about how Clerk or Dodo Payments handle data they process on our behalf, their own privacy policies (linked above) are the authoritative source, though we’re glad to help you find the right channel if you’re not sure where a request belongs.