Effective 21 July 2026 · Version 1.2
Privacy policy
SideQuesto is local-first. The app needs enough context to help you understand coding work, but that does not mean we need a copy of your project. This policy explains what stays on your Mac, what is sent to our service providers, and what you can control.
Who is responsible
The controller is ulterier sp. z o.o., registered in the Register of Entrepreneurs of the National Court Register, KRS 0000983425, VAT PL5273012387, REGON 52267137400000.
Registered address: al. Jerozolimskie 85/21, 02-001 Warszawa, Poland. Correspondence: Chmielna 73, 00-801 Warszawa, Poland. Represented by Ahmad Piraiee, Founder and CEO. Privacy requests: hi@sideques.to.
What the Mac app does locally
SideQuesto reads coding-agent event sources on your Mac so Dex or Pip can understand the current task. Raw prompts, source code, full commands, tool input and output, full logs, secrets, and absolute file paths are not retained in SideQuesto history or uploaded as learning data. The app reduces events locally to a limited description before deciding whether anything should be shown or spoken.
Saved Dex and Pip messages and cached summaries are encrypted with authenticated AES-256-GCM. A random key is created for each installation and stored in macOS Keychain. Local database files are owner-only and excluded from device backups. Preferences, usage totals, onboarding choices, entitlement state, token-ledger totals, and Mastery Lab scores are also stored locally. Device activation uses a separate P-256 signing key held by Secure Enclave when available, or by the non-migrating macOS Keychain otherwise. The private key is never uploaded.
Data we process
| Data | Why and legal basis | Where it goes |
|---|---|---|
| Account email, user ID, sign-in provider, role and session | Create and secure your account, provide the service and prevent misuse. Contract; legitimate interests in security. | Supabase; Google or Apple only when you choose that sign-in. |
| Activation-code and email HMAC digests, device public key, public-key fingerprint, activation and revocation times | Enforce one account and one activated Mac, reject replayed requests and prevent copied codes or sessions from unlocking a second laptop. Contract; legitimate interests in security and fraud prevention. | Supabase. The device private key remains on the activated Mac. Resend receives the invitation email and private DMG attachment. |
| Plan, Stripe customer and subscription IDs, payment status, invoices and natural-voice allowance | Take payment, manage subscriptions, prevent overspend, keep accounting records. Contract; legal obligations. | Stripe and Supabase. SideQuesto does not receive full card numbers. |
| The exact words Dex or Pip will speak, or a locally minimized description of a complex event | Produce optional natural voice or an optional cloud-generated explanation. Contract, initiated by your selected feature. | OpenAI only when the relevant cloud feature is enabled. |
| Optional thumbs rating, character, source category, priority, bucketed length and random message ID | Adapt locally and evaluate whether explanations are useful. Legitimate interests in product improvement; you may object. | Stored locally. When signed in, the minimized rating signal is also sent to Supabase. The message itself is not included. |
| Daily active seconds, sessions, tasks started and completed, failures, approvals, coding-agent provider, app version, locale and time zone | Understand private-beta onboarding, reliability and broad product use without collecting project content. Legitimate interests in improving and operating the service; you may object. | Supabase while you are signed in and have active access. No prompts, code, paths, logs, messages or audio are included. |
| Beta invitation source and cohort, onboarding status, lifecycle stage, follow-up and action history, product-email choice and limited founder notes | Deliver and improve private-beta onboarding and support, avoid duplicate contact, and show the founder what was or was not done. Contract; legitimate interests. Product, upgrade and win-back email is sent only with consent, which you may withdraw. | Supabase; Resend for an opted-in email; Stripe only when a customer-specific promotion code is created. |
| Email address, authentication email and support messages | Sign you in, answer requests and send service notices. Contract; legitimate interests; legal obligations where applicable. | Supabase and Resend; our support mailbox. |
| IP address, browser and basic security request data | Deliver and protect the website. Legitimate interests in a secure and reliable service. | Website hosting and Cloudflare. |
| Website pages, section views, demo and product choices, plan interest, beta/contact intent, checkout-return status, approximate city or country, browser, device and operating system | Understand broad website use and improve the site. Consent; analytics remains off unless you allow it. | Google Analytics after your permission. |
Website analytics and storage
Sideques.to uses essential security storage and a first-party local preference named sidequesto.cookiePreferences.v2. The preference remembers your choice for 180 days.
Google Analytics remains completely blocked unless you select “Allow analytics.” If allowed, Google may set _ga and_ga_* first-party cookies for up to two years to distinguish visitors and maintain session state. Advertising storage and personalisation remain disabled. Reopen “Cookie preferences” in the footer to withdraw permission at any time.
Analytics events use product labels such as the selected companion, coding agent, plan or section. They do not include an email address, source code, prompts, project paths, payment-card details or the contents of a message. A return from Stripe is measured only as a success or cancellation status; a website return alone is not treated as proof of a completed purchase.
The restricted founder dashboard retrieves aggregated reports through Google’s read-only Analytics Data API. This does not send account, subscription or Stripe records to Google, and Google Analytics is not used as the authoritative record of members or revenue.
Voice, mute, and cloud processing
Apple on-device speech does not send speech text to a SideQuesto voice provider. OpenAI natural voice sends the words being spoken to the OpenAI API. A complex-event summary sends only the locally filtered event description. When SideQuesto or the device output is muted, hosted voice and hosted summaries are not requested.
OpenAI states that API data is not used to train its models by default unless the customer opts in. Its standard abuse-monitoring logs may retain API content for up to 30 days unless a different approved data control applies. SideQuesto does not opt user content into model training.
Learning and Mastery Lab
SideQuesto does not upload raw prompts, code, paths, commands, logs, transcripts, audio, or a copy of Dex or Pip’s message as learning data. Mastery evidence contains aggregate event counts, active observed time, benchmark results, dimension scores and security-gate status. It does not make decisions that produce legal or similarly significant effects about you.
The current L2 “Reliable Observer” milestone records that this version passed SideQuesto’s local SQMB-1-L2 product preflight. It is not an independent certification and does not grade, rank or profile a user.
Service providers and transfers
We use suppliers only for the functions described below. Some may process data outside the EEA. Where required, transfers rely on the provider’s data-processing terms and safeguards such as Standard Contractual Clauses, an applicable adequacy decision, or the EU-U.S. Data Privacy Framework.
- Supabase — authentication, account database, entitlements and minimized feedback.
- Stripe — checkout, subscription management, invoicing, tax and fraud prevention.
- Resend — authentication and transactional email delivery.
- OpenAI — optional natural voice, optional complex-event summaries and site hosting services.
- Cloudflare — website delivery, security and bot protection.
- Google — optional account sign-in and consent-based website analytics; and Apple — optional account sign-in selected by the user.
Codex and Claude are separate services selected by the user. Their own terms and privacy policies govern the data they already process. We do not sell personal information, share it for cross-context behavioural advertising, or run targeted advertising.
How long we keep data
- Local messages and cached summaries: 30 days by default; you can choose 7, 30 or 90 days, or keep them until deletion.
- Local ratings: follow the related message retention and can be deleted with one click.
- Account and entitlement data: while the account is active, then deleted or anonymised after a valid deletion request, subject to required records and short-lived backups.
- Identifiable feedback signals: no longer than 24 months, unless deleted with the account sooner.
- Daily product-activity summaries: no longer than 24 months, unless deleted with the account sooner.
- Private-beta lifecycle records, action history and founder notes: while the account or beta relationship is active, then deleted or anonymised after a valid deletion request unless a legal dispute requires limited retention.
- Billing and tax records: for the statutory period required by Polish tax and accounting law.
- Support correspondence: up to 24 months after the matter closes, unless a dispute or law requires longer.
- Website storage: as listed in the website analytics and storage section.
Security
We use data minimisation, encrypted transport, per-install local encryption, macOS Keychain, database row-level security, signed webhooks, least-privilege access and access-controlled provider accounts. No system is risk-free; we maintain a response process for security incidents and will notify authorities and affected users when required by law.
Your choices and rights
Depending on where you live, you may request access, correction, deletion, restriction, portability or objection, and may withdraw any consent without affecting earlier processing. We may need to verify your identity. We normally respond within one month under GDPR.
Delete local messages, summaries and ratings in the app’s Privacy & Data settings. For account deletion or any other request, email hi@sideques.to. Account deletion also ends access to paid entitlements; billing records required by law may remain.
You may complain to Poland’s supervisory authority, the President of the Personal Data Protection Office (UODO), or another competent authority where you live.
California privacy
California users receive the disclosures required by CalOPPA: this policy identifies the categories collected, purposes, recipients, correction process, effective date and third-party collection. We do not use behavioural advertising. Optional Google Analytics remains off unless you consent, and a Global Privacy Control signal keeps it off. We do not sell or share personal information as those terms are used by the CCPA.
Whether or not SideQuesto currently meets the CCPA’s business thresholds, California residents may use the same access, correction and deletion channel described above. We do not discriminate against a user for making a privacy request.
Children and changes
SideQuesto is not directed to children under 16. If you are under the age at which you can enter a contract where you live, a parent or legal guardian must approve your use. Contact us if you believe a child’s data was provided improperly.
We will post material changes here and, when appropriate, notify account holders before they take effect. Earlier versions may be requested at hi@sideques.to.
Back home