◆ policy // privacy
privacy policy
Short version: NeonDiff runs on your machine. We don't ingest your source code. The hosted services hold the bounded account, billing, fulfillment, and entitlement data needed to issue and verify activation.
last updated · july 12 2026 · applies to neondiff.com and the NeonDiff CLI
- ◆ NeonDiff-hosted services do not ingest your source code, diffs, file names, or repository contents for review processing.
- ◆ NeonDiff-hosted services do not proxy prompts or completions sent directly to your selected BYOK or local model provider.
- ◆ Usage analytics, telemetry, or session recordings from the CLI.
- ◆ Third-party tracking pixels or advertising cookies on this website.
- Account
- Email address and a hashed password (or an OAuth identifier from your Google account when you sign in with Google). Used to authenticate you to the license portal.
- Billing
- Stripe holds your payment method, billing address, and receipts. We store your Stripe customer id, subscription status, and trial/renewal dates so we can gate license features.
- Activation and validation
- The CLI sends the NeonDiff activation key, a machine identifier, and an optional repository identifier to the production license API over HTTPS. Long-term license records use a hash or redacted fingerprint, and validation timestamps may be retained for entitlement and abuse-control purposes.
- One-shot checkout fulfillment
- After a successful checkout, the issued plaintext activation key is held in a service-role-only one-shot record for up to 30 minutes so the buyer can retrieve it. It is cleared after the first retrieval; customers should then keep it only in an approved secret store.
- Transactional email
- Receipts, magic links, and cancellation notices are sent from notify.neondiff.com. Delivery events (queued / sent / bounced) are logged for reliability. You can unsubscribe from any non-essential message via the link in every email.
- Support correspondence
- If you contact us, we keep the email thread until the issue is resolved plus 12 months, then delete it.
We use a short list of vendors to run the site and billing. Each is contractually restricted to processing data only on our behalf.
- ◆ Stripe — payments, invoicing, tax.
- ◆ Supabase — authentication plus account, subscription, email, and short-lived checkout-fulfillment records.
- ◆ Lovable — application hosting, edge functions, and transactional email delivery.
- ◆ Cloudflare — CDN and DNS.
- ◆ Fly.io — production license API and hashed entitlement records.
GitHub and any hosted model provider you select are destinations you configure for repository and inference workflows. Their own data-handling terms apply to the requests those workflows require.
neondiff.com sets only essential cookies: an authenticated-session cookie after you sign in, a theme preference cookie, and — during checkout — cookies set by Stripe on their own domain. There are no advertising, analytics, or third-party tracking cookies.
- ◆ Access / export — email support and we'll send you every field we hold about you.
- ◆ Deletion — cancel your license in the dashboard, then email support to purge the account. Billing records are retained per Stripe's tax-compliance rules.
- ◆ Correction — update your email in the dashboard, or ask us for anything else.
- ◆ EU / UK / California residents — you have the same rights under GDPR / UK GDPR / CCPA. We act as the controller for account and billing metadata.
Data controller: NeonDiff, operated by Electric Sheep HQ. Reach the privacy contact at support@electricsheephq.com. We publish the effective date of policy changes and notify active subscribers when required by law, contract, or the nature of the change.