Legal

Privacy Policy

Last updated 25 September 2026. What we collect, why we collect it, and the rights you have over it, in plain English.

1. Who we are

SuperGorilla is operated by Uzair Hussain Sheikh, trading as SuperGorilla in the United Kingdom, who is the data controller for the personal data described here. Questions, requests and complaints all go to support@supergorilla.ai; our postal address is available on request.

2. Analytics without tracking you

The marketing site you’re reading sets no cookies. We use Vercel’s privacy-friendly web analytics, which counts visits in aggregate (page, referrer, country, device type) without cookies, fingerprinting, or anything that identifies you.

3. What we collect when you use the service

  • ·Account details: your name, email address, a hashed password or your linked GitHub account, profile details you add, the organisations you belong to and your role in each, notification preferences, sign-in session records (IP address and browser), and the email addresses of people you invite.
  • ·Billing records: your plan, credit balance, purchases, top-ups, refunds and disputes, your billing country, and whether a card is on file. The card itself, your full billing address and any tax id are held by Stripe, our payment processor; we never see or store card details.
  • ·Repository and application data: the code and running application needed to perform the tests you configure, and the pull request, commit and comment data GitHub sends us, including the GitHub usernames of the people involved.
  • ·Environment variables: the configuration and test accounts your application needs to run, stored encrypted.
  • ·Run artifacts: recordings, screenshots, console and network logs produced by your test runs, and what each run cost.
  • ·Memory: what the service learns about your application across runs, so tests improve over time.
  • ·Emails we send you about your account and billing, and support correspondence you send us.

4. Why we collect it

To provide the service you signed up for (performance of a contract): running tests, producing reports, remembering your app between runs, and billing. To keep the service secure and reliable, and to respond when you contact us (legitimate interests). And to meet legal obligations, such as tax records. We don’t sell personal data, and we don’t use your data for advertising.

5. AI model providers

Test runs use Anthropic’s Claude models, reached through Vercel’s AI Gateway. The data needed to run a test, such as your instructions, the code and change under test, command output and logs from your application, and what the agent sees on screen, is processed by the model provider under its API terms. We choose the models; which ones we use may change as better ones arrive, and this policy will name them.

6. Who else sees data

Service providers who help us run SuperGorilla, each processing data only as needed to provide their service to us:

  • ·GitHub: sign-in with GitHub, and repository access, pull request events and posting reports via the GitHub App you install.
  • ·E2B: the isolated sandboxes where your application runs during a test, destroyed afterwards.
  • ·Vercel: hosting for the application and this website, storage for recordings and screenshots, and the AI Gateway that routes model requests.
  • ·Neon: database hosting.
  • ·Cloudflare: DNS for our domains, and sending the emails we send you.
  • ·Inngest: orchestration of the background work behind runs and billing.
  • ·Mastra: hosted observability, holding traces of each run's agent activity.
  • ·Better Auth: sign-in security and account management; it receives sign-in events, including your email address, IP address and device details.
  • ·Stripe: payment processing, card storage, invoices and receipts.
  • ·Metronome: metering what runs use and producing invoices.
  • ·Anthropic, the AI model provider reached through the gateway: see section 5.

We’ll keep this list current as our infrastructure changes. Reports, screenshots and recordings are posted to your pull requests, where anyone with access to the repository can see them, and are served from unguessable links that anyone holding the link can open. Beyond these, we disclose data only where the law requires it. We don’t sell personal data.

7. How long we keep it

Account data lasts while your account does. Run artifacts and memory are kept for your team’s use; you can delete a run, a project or a memory yourself from the dashboard, and we delete the rest on request. Invoices and payment records are retained by our billing providers as long as tax law requires. Some providers we use process data outside the UK; where they do, transfers rely on appropriate safeguards such as the UK’s international data transfer mechanisms.

8. Security

Environment variables are stored encrypted, repository access is read-only for code with write access limited to checks and pull request comments, and runs execute in isolated environments that are destroyed afterwards. Guardrails you set bound what agents may do inside your application. No system is perfectly secure; if we learn of a breach affecting your data, we’ll tell you.

9. Your rights

Under UK data protection law you can ask for access to your personal data, correction, deletion, restriction of processing, portability, and you can object to processing based on legitimate interests. Email support@supergorilla.ai and we’ll respond within a month. If you’re unhappy with how we handle your data, you can complain to the UK Information Commissioner’s Office (ico.org.uk).

10. Changes

If this policy changes materially, we’ll tell you by email or in the product before the change takes effect.