Legal

Privacy Policy

Last updated: September 1, 2026

This policy explains what information Yggdrasil handles when you use the hosted service at app.yggdrasil.cfd, and the choices you have. The short version: we collect what the service needs to operate — your GitHub identity, the repositories you connect, and the jobs you run — and nothing is sold or shared for advertising.

01Information we collect

02How we use it

We use this information solely to operate the service: authenticating you, dispatching and running agent jobs against your repositories, streaming progress back to you, deploying previews you request, and diagnosing failures. We do not sell your data, and we do not use your code or content for advertising.

03Where your code goes

Agent jobs run inside isolated, ephemeral environments that are torn down when the job finishes. To generate code, relevant portions of your repository and your instructions are sent to the model provider you have configured for your project (for example OpenRouter, Anthropic, or OpenAI) under your own API keys. Those providers process that data under their own terms and privacy policies — review them before connecting a provider.

04Third-party services

Yggdrasil does not embed third-party analytics or advertising trackers.

05Self-hosted deployments

If you run Yggdrasil on your own infrastructure, your code, secrets, and job data stay on systems you operate — this policy applies only to the hosted service. The operator of a self-hosted deployment is responsible for its own privacy practices.

06Retention and deletion

Project and job data is retained while your account is active so you can review the history of what was built and why. Ephemeral job environments are destroyed when a job completes. If you disconnect the GitHub App, Yggdrasil loses the access it granted. You can request deletion of your account data via the contact below.

07Security

Security is a design constraint of the product itself: jobs run in isolated environments with no access beyond what each job needs, repository access uses scoped and short-lived tokens rather than standing credentials, and stored secrets are encrypted at rest and decrypted only server-side. No system is perfectly secure, but the architecture is built to limit the blast radius of any single component.

08Your choices

09Changes to this policy

We may update this policy from time to time. Material changes will be announced on this page with an updated "Last updated" date.

10Contact

Questions about privacy can be raised on GitHub.