corpusAI

Legal

Privacy policy

Effective 2026-09-26

This policy covers www.trycorpus.ai, the corpusAI API at api.trycorpus.ai, the corpusAI CLI and the machines they deploy. The service is operated by Julian Traversa, trading as corpusAI. The short version: we keep what we need to sign you in, run your machines and keep the books on your positions. There are no analytics scripts, tracking pixels or advertising identifiers.

corpusAI Cloud Pricing at cloud.trycorpus.ai has its own privacy policy, published there.

What we record

  • Your GitHub profile. When you sign in, GitHub gives us your GitHub user id, login, display name, avatar URL and one email address: your public profile email, or else a verified address from your account (the read:user and user:email scopes). We store these and refresh them each time you sign in. The GitHub access token is used only during sign-in and is not stored.
  • Sessions and CLI tokens. A session is a random token held in a cookie; we store only its SHA-256 hash and its expiry. CLI tokens are stored the same way, with the name you give them and when they were last used. A CLI login request stores its short code until it expires.
  • The GitHub App installation. If you install the corpusAI GitHub App, we store the installation id and the GitHub account it is installed on. We read the list of repositories you granted to show the picker, and each build clones the chosen repository with a short-lived token. Your code is not stored in our database; the built image is stored in Fly.io’s container registry so the machine can run it.
  • Machines and deploys. Each machine’s name, region, size, monthly cost, repository, branch, status and Fly.io identifiers. For each deploy, what triggered it, the commit, its status, any error and the full build output.
  • Runtime logs. Your machine’s output is held in memory, up to the last 500 lines per machine, to show on its logs tab. It is not written to our database and is gone when the API restarts.
  • Payments, positions and withdrawals. For each checkout, its deposit address, the amounts quoted and received, its status and the transactions that funded it. For each position, its price, principal, terms, ledger entries and monthly settlements. For each withdrawal, the destination address, the amount, the due date and the payout transaction. Deposits and payouts are public Ethereum transactions, and they are permanent.
  • Access. When you redeem an invite or developer code, the time access was granted to your account.
  • Email. If you write to us, we keep the correspondence.

What we do not record

No passwords: GitHub handles sign-in. No analytics, tracking pixels, advertising identifiers or third-party cookies. The API does not store your IP address or browser details in its database; it reads your IP address in memory to rate-limit requests.

Cookies and browser storage

The API sets these cookies. All are first-party, HttpOnly and SameSite=Lax, and none is used for tracking.

  • corpus_session keeps you signed in. It lasts 30 days, or until you log out.
  • corpus_oauth_state and corpus_oauth_next protect the GitHub sign-in round trip and remember where to send you afterward. They last 10 minutes.
  • corpus_app_state protects the GitHub App install round trip. It lasts 10 minutes.

The dashboard keeps a machine you are still setting up, simulated machines and one pending error message in your browser’s session storage, which is cleared when the tab closes. Nothing is kept in local storage.

Services that process it

  • GitHub: sign-in, the GitHub App and your repositories. Your avatar is loaded from GitHub’s servers.
  • Fly.io: hosts the API and runs your machines, their builds, their images and their logs.
  • Neon: hosts the Postgres database that holds the records above.
  • Vercel: hosts www.trycorpus.ai and sees ordinary request data, such as IP address, browser and page, to serve and protect it.
  • Alchemy: our Ethereum RPC provider, used to watch deposits and payouts. It sees the addresses we query.
  • Discord: operator notifications go to a private channel. They include withdrawal requests (machine name, amount, due date and destination address), breached positions and underpaid deposits.
  • Google Fonts: the site’s typefaces load from Google, which sees your IP address and browser.
  • Public Ethereum RPC endpoints: if you type an ENS name as a withdrawal address, your browser looks it up directly through cloudflare-eth.com, falling back to ethereum-rpc.publicnode.com. They see the lookup and your IP address; corpusAI receives only the resolved address.
  • Ethereum: deposits, the treasury, venue positions and payouts are public on-chain.

We do not sell personal data. We share it only with the services above, as needed to run corpusAI, or when the law requires it.

How we use it

To sign you in, build and run your machines, show you their logs, quote and settle positions, pay withdrawals, keep accounting records, prevent abuse, and contact you about your account, machines and positions.

Retention

  • Sessions expire after 30 days. CLI login requests are deleted a day after they expire.
  • Deleting an unfunded machine deletes its record. Developer machines are deleted, with their deploys and build logs, 48 hours after they are created.
  • Records of funded machines, payments, positions, ledger entries and payouts are kept after a position closes, as the accounting record.
  • Runtime logs live only in memory.
  • Fly.io, Vercel and the other services above keep their own logs for their own retention periods.

Your choices

You can revoke corpusAI’s sign-in access and remove the GitHub App in your GitHub settings at any time. You can ask what we hold about you, ask us to correct it, or ask us to delete your account by writing to hello@trycorpus.ai. We will delete what we can; records of payments and positions are kept as financial records.

Children

The service is not for anyone under 18, and we do not knowingly collect data about children.

Changes to this policy

We may change this policy by publishing a new version at www.trycorpus.ai/privacy with a new effective date. If a change materially affects how we use data we already hold, we will tell you by email before it takes effect.

Contact

Questions about privacy: hello@trycorpus.ai.