This policy explains what data Alfrig processes, for what purpose, who it is shared with and what your rights are, under Brazil’s General Data Protection Law (Law 13,709/2018, “LGPD”). Alfrig is operated by Dales Ltda, CNPJ 45.106.370/0001-46 (“we”), the controller of the personal data described here.
1. What Alfrig is
Alfrig is a service in which software agents carry out engineering tasks — they read repositories, write code, open and review pull requests — at the request of the customer organization. Each organization has an isolated space, with its own database and encryption keys.
2. Data we process
- Account: name, email and profile picture, received from the login provider you choose (Google, GitHub, Apple) or provided by you when signing in with a magic link.
- Organization and usage: organization name, members and roles, invitations, agents created, tasks and their records (descriptions, plans, reviews, results), workflow settings.
- Integrations: access tokens for services you connect (GitHub, ClickUp, Linear, language model providers). They are stored encrypted with a key unique to your organization and used only to carry out what you configured.
- Code and work content: the content of the repositories and tasks you point Alfrig to is processed while tasks run, in temporary environments that are discarded at the end.
- Technical data: access logs (IP address, browser, date and time), session cookies and error events, for security and diagnostics.
3. What we use it for
- Providing the service: authenticating you, maintaining your organization, running and recording the agents’ tasks (performance of contract).
- Communicating with you: sign-in links, invitations and service notices (performance of contract and legitimate interest).
- Security, fraud prevention and compliance with legal obligations.
- Improving the product: we analyze usage metrics and information about how tasks run (logs, steps, times and results), including in an automated way, to understand where the service fails or is slow and to improve it (legitimate interest). Whenever possible, personal data is removed or masked before this analysis. We do not use your code or your data to train models.
4. Language models
To carry out tasks, Alfrig sends code excerpts, descriptions and context to the language model provider configured by your organization (for example, z.ai, OpenAI or Anthropic), using the keys you registered. These providers process the data under their own terms; we recommend reviewing their retention policies before connecting sensitive repositories.
For the service improvement analyses (section 3), we use model providers contracted by Alfrig, with our own keys and at no cost to your organization, under conditions that do not allow the data to be used to train models.
5. Who we share it with
We do not sell personal data. We share it only with processors needed for the service:
- Fly.io — application hosting and agent execution (São Paulo region).
- MongoDB Atlas — database.
- Resend — transactional email delivery.
- Cloudflare — DNS and distribution of the desktop app.
- Google, GitHub and Apple — login providers, when you use them.
- Language model and integration providers chosen by your organization (section 4).
- Language model providers contracted by Alfrig, such as Anthropic, for the service improvement analyses (sections 3 and 4).
Some of these processors are located outside Brazil; international transfers follow the safeguards provided for in the LGPD, such as contractual clauses.
6. Retention
We keep your organization’s data for as long as it exists. When the organization is deleted, its database, files and encryption key are erased, which makes any token or record remaining in backups unreadable; backups are deleted within 30 days. Technical logs and the information used to improve the service are kept for up to 2 months, and the latter are also erased when the organization is deleted. Data required by law is kept for the legal period.
7. Your rights
You may request confirmation of processing, access, correction, anonymization, portability, deletion and information about sharing, and you may withdraw consent. Write to privacy@alfrig.com; we reply within 15 days. You may also file a complaint with Brazil’s National Data Protection Authority (ANPD).
8. Cookies
We use only strictly necessary cookies: the session cookie that keeps you signed in and the theme and language preference stored in your browser. We do not use advertising cookies or cross-site tracking.
9. Security
Encrypted traffic (HTTPS), secrets encrypted at rest with a per-organization key, per-organization database isolation and task execution in disposable containers. No system is infallible; in the event of an incident with relevant risk, we will notify you and the ANPD as required by law.
10. Children
Alfrig is intended for professionals and is not directed at anyone under 18.
11. Changes
We may update this policy; the date at the top shows the current version. Relevant changes will be announced by email or in the app.
12. Contact
Data protection officer (DPO): privacy@alfrig.com.