Privacy Policy
Last updated: 31 July 2026
This Privacy Policy describes how Samwise AI Limited ("Samwise AI", "we", "us", "our") processes personal information that we collect when you use or engage with Barad, our online coding harness, through our digital and online properties or services that link or refer you to this Privacy Policy, as well as our marketing activities and other activities described in this Privacy Policy (collectively, the "Services").
Samwise AI is the controller in respect of the processing of your personal information covered by this Privacy Policy for the purposes of European data protection legislation (the EU GDPR and the UK GDPR). See the "How to contact us" section below for our contact details.
References to "personal information" in this Privacy Policy include "personal data" as defined in the GDPR — information about individuals who are either directly identified or identifiable.
This Privacy Policy does not apply to information we process about our employees, independent contractors, or job candidates.
1. Who we are
Samwise AI Limited is a private limited company registered in England and Wales under company number 17094690, with registered office at 6th Floor Manfield House, 1 Southampton Street, London, England, WC2R 0LR. You can contact us at support@barad.io.
2. Personal information we collect
Information you provide to us
Personal information you may provide to us includes:
User-submitted content. Barad enables you to direct coding agent sessions that work on repositories and other resources you connect. We collect the personal information that you submit to, make available through, or expose to the Services in the course of your use of them. This includes:
- content and information you directly input or transmit to the Services, such as your prompts, instructions, and messages to agents, files you upload, session transcripts, and any other materials you provide (together with associated metadata); and
- content and information held in or accessible through any account, repository, system, environment, platform, or data source that you connect to the Services, otherwise make available to them, or with which you cause them to interact — including, for example, source code, commit history, issues, configuration, documents, and any other information that the Services access, process, or interact with as a result of the way you configure or use them (together with associated metadata).
User-submitted content may include any records and logs of the further categories of personal information set out below.
- Contact data, such as your first and last name and email address.
- Profile data, such as account name, the username and password that you may set to establish an online account on the Services, Git author identity you configure, and any other information that you add to your account profile.
- Credential data, such as model provider API keys and OAuth tokens for Third-Party Services you connect (for example an OpenAI API key, a ChatGPT subscription connection, or a GitHub installation). These are stored encrypted and used solely to operate the Services as you direct.
- Transactional data, such as information relating to or needed to complete your orders on or through the Services (where subscriptions are offered), including order numbers and transaction history.
- Payment data needed to complete transactions, where subscriptions are offered, including payment card information. We would use third-party payment processors, such as Stripe, to directly collect and process your payment card information, as described further below.
- Communications data based on our exchanges with you, including when you contact us through the Services, communicate with us via email, or otherwise.
- Marketing data, such as your preferences for receiving our marketing communications and details about your engagement with them.
- Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.
Data about individuals who are not users of the Services
We may receive personal information relating to individuals who are not themselves users of the Services, principally where a user exposes such information to the Services — for example, where a connected repository contains personal information of others (such as commit author names and email addresses, code comments, or data files), or where a user uploads or publishes content that contains personal information of others.
Third-party sources
We may combine personal information we receive from you with personal information of the kinds identified above that we obtain from other sources, such as:
- Third-Party Services you connect, such as source-control platforms that provide account and repository metadata; and
- service providers that provide services on our behalf or help us operate the Services or our business.
Automatic data collection
We and our service providers may automatically log information about you, your computer or mobile device, and your interaction over time with the Services, our communications, and other online services, such as:
- Device data, such as your computer or mobile device's operating system type and version, manufacturer and model, browser type, screen resolution, IP address, unique identifiers, and language settings.
- Location data, which will be approximate (for example, as inferred from network data). We do not intentionally collect precise geolocation data.
- Communication interaction data, such as your interactions with our emails.
- Online activity data, if you visit our websites, such as pages or screens you viewed, how long you spent on a page, navigation paths between pages, and access times and duration of access.
- Service operation data, such as session lifecycle events, agent execution logs, and technical logs generated by the operation of sessions.
Cookies
Some of our automatic data collection is facilitated by cookies and similar technologies. For more information, see our Cookie Policy. We use only strictly necessary cookies and similar technologies.
3. How we use your personal information
We may use your personal information for the following purposes or as otherwise described at the time of collection:
Services delivery and operations
We may use your personal information to:
- provide and operate the Services (including to run agent sessions as you direct, connect Third-Party Services, and process your orders and transactions);
- establish and maintain your user profile on the Services;
- enable security features of the Services, such as by sending you security codes via email, and remembering devices from which you have previously logged in;
- communicate with you about the Services, including by sending Services-related announcements, updates, security alerts, and support and administrative messages; and
- provide customer support for the Services.
Research and development
We may use your personal information for research and development purposes, including to analyse and improve the Services and our business, develop new products and services, and train our AI/ML models (where permitted). Where you connect your own model provider, that provider processes your content under your agreement with it; we do not grant model providers rights over your personal information for their own separate purposes.
Marketing
We may send you direct marketing communications and may personalize these messages based on your needs and interests. You may opt out of our marketing communications as described in the "Your choices and your rights" section. We do not use third-party advertising cookies or pixels on the Services, and we do not share personal information with third parties for those third parties' own direct marketing purposes.
Services improvement and analytics
We may use your personal information to analyse the operation and your usage of the Services, to improve the Services, to improve the rest of our business, to help us understand user activity on the Services, and to develop new products and services. This may include use of personal information contained in technical information relating to the operation of the Services, such as agent execution logs, session activity data, performance metrics, and usage metadata.
Compliance and protection
We may use your personal information to:
- comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas, court orders, investigations, or requests from government authorities;
- protect our, your, or others' rights, privacy, safety, or property (including by making and defending legal claims);
- audit our internal processes for compliance with legal and contractual requirements or our internal policies;
- enforce the terms and conditions that govern the Services; and
- prevent, identify, investigate, and deter fraudulent, harmful, unauthorised, unethical, or illegal activity, including cyberattacks, abuse of session compute, and identity theft.
Aggregated, de-identified, and anonymised data
We may create aggregated, de-identified, and/or anonymised data from your personal information and other individuals' personal information we collect, by removing information that makes the data identifiable to you. We may use this data and share it with third parties for our lawful business purposes, including to analyse and improve the Services and promote our business.
Data sharing in the context of corporate events
We may use and share certain personal information in the context of actual or prospective corporate events — for more information, see "How we share your personal information" below.
Further uses
In some cases, we may specifically ask for your consent to collect, use, or share your personal information for further purposes not set out above, such as where required by law where those further purposes are not compatible with the initial purpose for which the personal information was collected.
4. How we share your personal information
We may share your personal information with the following parties and as otherwise described in this Privacy Policy, in other applicable notices, or at the time of collection.
- Affiliates. In some cases, our corporate parent, subsidiaries, and affiliates might have access to personal information.
- Service providers. Vendors that provide services on our behalf or help us operate the Services or our business, such as hosting providers (the Services are hosted with Amazon Web Services in the European Union), email delivery providers, and customer support vendors.
- Model providers you connect. Where you connect a model provider account (such as an OpenAI API key or ChatGPT subscription), your prompts, relevant repository content, and other session context are shared with that provider to generate outputs and drive agent actions, under your own agreement with that provider.
- Payment processors. Where subscriptions are offered, certain payment data, including payment card information you use to make a purchase for the Services, would be collected and processed directly by our payment processors, such as Stripe. These payment processors are primarily required to process personal information only on our behalf as necessary to process your payment, but in limited circumstances they may also use your payment data for their own purposes (e.g., complying with their own legal or regulatory obligations, or monitoring, preventing, and detecting fraudulent payment transactions).
- Third parties you designate or cause the Services to interact with. We may share personal information with third parties where you have instructed or directed us to do so, or where you use the Services in a way that causes them to interact or communicate with, transmit data to, or otherwise make personal information available to a third party — for example, where an agent session pushes commits to a repository host, or where you publish content through the Services.
- Professional advisors. Professional advisors, such as lawyers, auditors, bankers, and insurers, where necessary in the course of the professional services that they render to us.
- Authorities and others. Law enforcement, government authorities, and private parties in litigation, as we believe in good faith to be necessary or appropriate for the compliance and protection purposes described above.
- Corporate transactions. We may disclose personal information in the context of actual or prospective business transactions, such as investment, financing, or the sale, transfer, or merger of all or part of our business. We may disclose your personal information to an acquirer, successor, or assignee of Samwise AI as part of any merger, acquisition, sale of assets, or similar transaction, or in the event of insolvency, bankruptcy, or receivership.
- The public. Your user-submitted content may become visible to the public if you choose to use the Services in a way that makes it publicly available — for example, if you publish session content to a public URL or push content to a public repository. If you choose to do this, this information can be seen, collected, and used by others, including being cached, copied, or stored elsewhere by others (e.g., search engines), and we are not responsible for any such use.
We do not sell personal information to data brokers, we do not share personal information with third parties for targeted advertising, and we do not share personal information with third parties for those third parties' own direct marketing purposes. We do not currently offer sign-in via third-party accounts (such as Google or Apple).
5. Our legal basis for processing
In respect of each of the purposes for which we use your personal information, the GDPR requires us to ensure that we have a "legal basis" for that use. Our legal bases are:
- Where we need to perform a contract we have entered into with you or are about to enter into with you ("Contractual Necessity").
- Where it is necessary for our legitimate interests and your interests and fundamental rights do not override those interests ("Legitimate Interests"). More detail about the specific legitimate interests pursued for each purpose is set out in the table below.
- Where we need to comply with a legal or regulatory obligation ("Compliance with Law").
- Where we have your specific consent to carry out the processing for the purpose in question ("Consent").
The table below sets out the legal bases we rely on for the purposes described in "How we use your personal information" above.
| Purpose | Categories of personal information involved | Legal basis |
|---|---|---|
| Services delivery and operations | User-submitted content; contact data; profile data; credential data; transactional data; payment data; device data; service operation data | Contractual Necessity. Legitimate Interests — ensuring the proper operation of the Services and the performance of our contracts with users, and the ongoing security of the Services and our business. |
| Research and development | Any and all data types relevant in the circumstances | Legitimate Interests — understanding how our users use our Services. |
| Direct marketing | Contact data; profile data; communications data; marketing data; communication interaction data | Legitimate Interests — promoting our operations and sending marketing communications. Consent, where required under applicable law. |
| Services improvement and analytics | User-submitted content; contact data; profile data; device data; online activity data; service operation data | Legitimate Interests — providing and improving the Services and growing our business. |
| Compliance and protection | Any and all data types relevant in the circumstances | Compliance with Law. Legitimate Interests — participating in and supporting legal process, and protecting our rights, property, and safety. |
| Aggregated, de-identified, and anonymised data | Any and all data types relevant in the circumstances | Legitimate Interests — preserving user privacy while researching how the Services are used. |
| Data sharing in the context of corporate events | Any and all data types relevant in the circumstances | Legitimate Interests — pursuing and consummating actual or prospective corporate events. |
| Further uses | Any and all data types relevant in the circumstances | The original legal basis relied upon, if the further use is compatible with the initial purpose. Consent, if it is not. |
6. Your choices and your rights
If you are not a Barad user
If personal information about you has been exposed to the Services by a user — for example, because it appears in a repository or published content a user connected to or created with the Services — you may contact us at support@barad.io to exercise the rights described below in respect of that information.
Your rights under the GDPR
Under UK and EU GDPR you may have the right to:
- Access. Ask us for information about our processing of your personal information and for access to your personal information.
- Correct. Ask us to update or correct inaccuracies in your personal information.
- Delete. Ask us to delete your personal information where there is no good reason for us continuing to process it, including where you have exercised your right to object to processing.
- Transfer. Ask us to transfer to you or a third party of your choice a machine-readable copy of your personal information that you have provided to us and that we process based on Consent or Contractual Necessity.
- Restrict. Ask us to restrict the processing of your personal information, for example while we establish its accuracy or the reason for processing it.
- Object. Object to our processing of your personal information where we rely on Legitimate Interests, or where we process your personal information for direct marketing purposes.
- Withdraw consent. Where we use your personal information based on your consent, withdraw that consent at any time.
- Complain. Complain to us if you are not satisfied with our handling of your personal information, by emailing support@barad.io.
You may exercise these rights by emailing support@barad.io. We may request specific information from you to confirm your identity. If we reject a request, in whole or in part, we will let you know our grounds for doing so, subject to any legal restrictions. You will not normally have to pay a fee, though we may charge a reasonable fee if a request is clearly unfounded, repetitive, or excessive. We try to respond to legitimate requests within one calendar month; it may take longer if your request is particularly complex, in which case we will notify you and keep you updated.
If you are not satisfied with our response, you can complain to the data protection regulator in your habitual place of residence. For individuals in the European Economic Area, contact details for your regulator are available at edpb.europa.eu. For individuals in the UK, the relevant regulator is the ICO, at ico.org.uk.
Opt out of communications
You may opt out of marketing-related emails by following the opt-out or unsubscribe instructions at the bottom of the email, or by contacting us. It may take time for your opt-out to take effect. If you opt out of marketing-related emails, you may continue to receive service-related and other non-marketing emails.
Cookies
For information about cookies used by the Services, see our Cookie Policy.
7. Data processing outside Europe
Although we are a UK-headquartered business and the Services are hosted in the European Union, some of our service providers, advisers, partners, or other recipients of data — including model providers whose accounts you connect, such as OpenAI — are based in the U.S. This means that your personal information may be accessed and processed in the U.S., and may also be provided to recipients in other countries inside and outside the UK and the European Union ("Europe").
The U.S. is not the subject of an "adequacy decision" under the GDPR, meaning the U.S. legal regime is not considered by relevant European bodies to provide an equivalent level of protection to relevant European laws. Where we share your personal information with third parties based outside Europe, we try to ensure a similar degree of protection by using one of the following mechanisms:
- Transfers to territories with an adequacy decision, such as under the EU-U.S. Data Privacy Framework or the UK Extension to it, where the recipient is certified.
- Transfers to territories without an adequacy decision, using appropriate safeguards designed to give personal information effectively the same protection it has in Europe, such as standard-form contracts approved by relevant authorities; or, in limited circumstances, relying on an exception (or "derogation"), such as your explicit consent to the transfer.
You may contact us at support@barad.io for further information on the specific mechanism we use when transferring your personal information out of Europe, or to request a copy of the appropriate safeguards under which it is transferred.
8. Information for individuals in the United States
Some U.S. states, such as California, Colorado, Connecticut, Minnesota, New Jersey, Oregon, Texas, and Virginia, have enacted privacy laws that grant their residents certain rights and require specific disclosures ("State Privacy Laws"). To the extent we are subject to State Privacy Laws, if you reside in an applicable state, this section applies to you. This section also serves as our California notice at collection.
This Privacy Policy explains how we collect, use, disclose, and retain information about you. As required by certain State Privacy Laws, we use the table below to explain this same information.
| Category of personal information | Categories of recipients | Use of personal information |
|---|---|---|
| User-submitted content; contact data; profile data; credential data; transactional data; payment data; communications data; marketing data; device data; location data; communication interaction data; online activity data; service operation data; other information you choose to provide or we receive from others in response to your use of the Services | Vendors and service providers; affiliates; model providers whose accounts you connect; payment processors; other individuals and entities you instruct or cause the Services to interact with; professional advisors; government and law enforcement authorities; prospective counterparties and their advisors in the context of corporate transactions; others at your instruction, such as the public if you publish content through the Services | Provide and operate the Services, including our online coding harness; research and development; improve and analyse our Services; marketing; compliance and protection; create aggregated, de-identified, and/or anonymised data |
We do not use data that may be considered "sensitive" under the State Privacy Laws other than as necessary to provide the Services you request. As described in "Personal information we collect" above, we collect personal information from various sources, including directly from you, automatically when you access or use the Services, and from other sources.
Sales, sharing, and targeted advertising
We do not "sell" personal information, we do not "share" it for cross-context behavioural advertising, and we do not process it for "targeted advertising" as those terms are defined under State Privacy Laws.
Your rights under State Privacy Laws
Access, correction, and deletion. You may have the right to (1) request to know more about and access your personal information, including in a portable format, (2) request deletion of your personal information, and (3) request correction of inaccurate personal information. To request access, correction, or deletion of your personal information, please email support@barad.io. To authenticate your request, we may ask you to provide information about your recent interactions with the Services.
Nonretaliation. We will not retaliate against you for exercising your privacy rights.
Appeals. If we deny your request, you may appeal our decision by contacting us at support@barad.io. If you have concerns about the result of an appeal, you may contact the attorney general in the state where you reside.
Authorized agents. If you reside in California, you may designate an authorized agent to submit an access, deletion, or correction request on your behalf. We may ask authorized agents to submit proof of their authority, such as a valid power of attorney or your signed permission. In some cases, we may contact you directly to verify your identity or confirm the agent's permission to submit the request. If you are an authorized agent seeking to make a request on behalf of a California resident, please contact us at support@barad.io.
9. Other information
No obligation to provide personal information. You do not have to provide personal information to us. However, where we need to process your personal information either to comply with applicable law or to deliver our Services to you, and you do not provide it, we may not be able to provide some or all of our Services to you.
Retention period for personal information. We generally retain personal information for as long as needed to fulfil the purposes for which we collected it, including to satisfy legal, accounting, or reporting requirements, establish or defend legal claims, or prevent fraud. We consider factors such as the length of our relationship with you, the sensitivity of the personal information, the risk of harm from unauthorised use or disclosure, whether we can achieve our purposes through other means, and any applicable legal or regulatory retention requirements. We will generally retain your personal information for as long as you keep using the Services, and for a further period afterwards during which we may have a legitimate need to reference it. When we no longer need personal information, we either delete it or de-identify it.
Other sites and services. The Services may enable access to or interact with websites, applications, and other online and offline systems and services operated by third parties, including source-control platforms and model providers. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party. We do not control third-party websites, applications, or online services, and are not responsible for their actions. We encourage you to read the privacy policies of any other websites, applications, or online services you use, including those of any model provider you connect.
Security. We employ technical, organisational, and physical safeguards designed to protect the personal information we collect, including hardware-isolated execution environments for agent sessions and encryption of stored credentials. However, security risk is inherent in all internet and information technologies, and we cannot guarantee the security of your personal information.
Children and teens. The Services are not intended for use by anyone under 18 years of age. If you are a parent or guardian of a minor from whom you believe we have collected personal information, please contact us at support@barad.io. If we learn that we have collected personal information from a child without the consent of the child's parent or guardian as required by law, we will comply with applicable legal requirements to delete the information.
10. Changes to this Privacy Policy
The "last updated" date at the top of this Privacy Policy shows when it was last revised. We may modify this Privacy Policy at any time. We will notify you by updating the "last updated" date, and depending on the nature of the change, we may also notify you directly or ask for your consent where required by law. Changes take effect once we post the modified version, or as otherwise indicated at the time of posting.
11. How to contact us
If you have questions about our practices, or would like to exercise any privacy-related right available to you under applicable law, please email support@barad.io.