1. Scope
This Privacy Policy describes how wcagent handles personal information when you visit our website, create or use a wcagent account, use WebCodingAgent in VS Code, pair the browser connector, contact us, or otherwise use services that reference this policy.
The AI provider you choose is a separate service. Information submitted to that provider is also governed by that provider’s own privacy policy, account settings, retention rules, and terms.
2. Information we handle
Account and billing information
We may receive information such as your name, email address, account identifiers, subscription status, plan, trial status, billing status, and support correspondence. Payment processing is handled by the payment provider identified at checkout. We do not need your full payment-card number to operate wcagent.
Service and device information
We may process technical information needed to operate and secure the service, including IP address, browser or extension version, device and session identifiers, timestamps, authentication events, error information, feature usage, and security or abuse signals.
Task and repository context
When you ask WebCodingAgent to work on a task, the extension may send the wcagent service information needed for that task, such as ranked path metadata, explicitly selected editor text, requested file contents, diagnostics, diffs, command output, approvals, task instructions, tool results, and completion evidence. The exact context depends on your request and the tools used.
3. Repository data and local execution
Your repository remains on your machine unless task context is intentionally selected or requested for processing. Repository commands and file mutations execute through the desktop VS Code extension under its local workspace, trust, path, and approval controls.
wcagent is designed to exclude absolute workspace paths from normal task context sent to the service. The extension also applies supported secret-redaction and policy checks before certain tool output leaves VS Code. These controls reduce exposure but cannot guarantee that every confidential value will always be detected, so you should avoid supplying secrets or data that is not needed for a task.
The browser connector does not receive general repository access. Its role is to transport selected prompts and responses between wcagent and the eligible AI provider you choose.
4. Third-party AI providers
You choose an eligible AI service and connection method you are authorized to use. For eligible web-account integrations, the connector is designed so provider passwords, cookies, authentication headers, and equivalent browser-session credentials are not returned to wcagent through the normal task protocol.
Task prompts and selected repository context may be submitted to the AI provider you choose because that provider supplies the model response. Responses and bounded runtime metadata are returned to wcagent so the task can continue. Conversations or prompts may remain in the provider’s history depending on that provider’s settings and policies.
Your use of an AI provider remains subject to that provider’s availability, usage limits, privacy practices, account settings, policies, and terms. wcagent does not include or resell model access and does not control how an independent provider processes information after it receives it.
5. How we use information
We use information to provide, authenticate, coordinate, secure, support, maintain, and improve wcagent; preserve task continuity; enforce local and cloud safety boundaries; process subscriptions; communicate with you; diagnose failures; prevent fraud and abuse; comply with legal obligations; and protect the rights, security, and integrity of users and the service.
We may create aggregated or de-identified information that cannot reasonably be used to identify you and use it for analytics, reliability, product planning, and service improvement.
6. Service providers and disclosures
We may use vendors to host infrastructure, deliver authentication and email, process payments, monitor reliability, provide customer support, or perform other functions on our behalf. They may process information only as needed to provide those services to us and subject to their applicable contractual or legal obligations.
We may disclose information when reasonably necessary to comply with law or valid legal process, protect users or the public, investigate abuse or security incidents, enforce our agreements, or support a corporate transaction such as a merger, financing, acquisition, reorganization, or sale of assets.
We do not sell personal information for money. If our practices change in a way that creates additional privacy choices under applicable law, we will provide the required notices and controls.
7. Retention and deletion
We keep personal information only for as long as reasonably necessary for the purposes described in this policy, including providing the service, maintaining account and task continuity, resolving disputes, enforcing agreements, meeting tax or accounting obligations, preventing abuse, and complying with law.
Different categories may have different retention periods. Some local extension state remains on your device until you remove it, clear the relevant workspace state, or uninstall the extension. Information held by a third-party AI provider is controlled by that provider’s retention settings and policies.
You may request deletion of eligible wcagent account information through the contact method below. We may retain limited information when required or permitted for security, fraud prevention, legal compliance, or legitimate recordkeeping.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, or alteration. Product controls include local workspace confinement, explicit approval modes, conflict-aware writes, bounded browser transport, secret-redaction measures, and recorded task evidence. More detail is available on our Security page.
No online service can guarantee absolute security. You are responsible for protecting your account credentials, your browser profile, your device, and access to repositories you connect to wcagent.
9. Your choices and privacy rights
You can choose which eligible AI provider to connect, what tasks to submit, what repository context to expose, and what local actions to approve. You can disconnect the browser connector, sign out, uninstall the extension, or stop using the service.
Depending on where you live, applicable law may give you rights to request access, correction, deletion, restriction, portability, or objection regarding personal information we control. We may need to verify your identity before completing a request, and some rights are subject to legal exceptions.
10. International processing
wcagent and its service providers may process information in countries other than the one where you live. Where required, we use appropriate legal mechanisms for cross-border transfers and take steps intended to protect information consistently with applicable law.
11. Children
wcagent is a developer tool and is not directed to children under 13 or any higher minimum age required by local law. If you believe a child provided personal information in violation of applicable law, contact us so we can review the request.
12. Changes to this policy
We may update this Privacy Policy as wcagent, our providers, or legal requirements change. We will post the revised policy on this page and update the effective date. If a change materially affects your rights or how we use personal information, we will provide additional notice when required.
13. Contact
For privacy questions or requests, contact wcagent through the contact page. You can also write to support@wcagent.ai. Please do not include passwords, provider cookies, API keys, or other secrets in a privacy request.