Legal

Privacy Policy

This policy explains how Resin handles information across local tools, the web Console, and cloud services.

Effective

Information Resin processes

Local Raw Sessions: Resin is designed with a local-first architecture. Raw interactive session artifacts—including raw user prompts, model reasoning and thought blocks, raw tool calls, and local workspace code—stay on your local machine. They are stored in your local state database and are never uploaded to the cloud.

Sanitized Cloud Evidence: When you connect your environment to the Resin cloud service, Resin processes sanitized, allowlisted observation records, tool capability profiles, verification digests, and evaluation results. Sensitive tokens, secrets, and system usernames are stripped locally prior to transmission.

Identity and Account Data: When you sign in with supported providers (such as Google or GitHub), Resin receives account identifiers, email addresses, and basic profile details required to authenticate you, manage personal versus workspace memberships, and secure your account. Resin does not sell your personal data.

Technical Diagnostics: Technical request logs and error traces may be collected to operate the service and secure system reliability.

How information is used

Resin uses processed information to provide the Resin Console, evaluate and qualify compiled tools, maintain workspace access controls, diagnose system issues, and protect against unauthorized access or abuse.

Personal vs. workspace visibility

Personal account details, device authentications, and linked identity providers belong solely to your personal user account.

Tool qualifications, activation history, and sanitized performance evidence created within an explicit team workspace are accessible to authorized members of that workspace according to their role.

Configured service providers and model processing

Resin relies on service providers for specific operational functions:

  • Authentication Providers: Google Identity and GitHub OAuth process sign-in requests and provide identity verification.
  • Configured Model Providers: When tool evolution, repair, or evaluation features invoke AI models, sanitized prompts and capability schemas are transmitted to the configured model provider (such as OpenRouter, Anthropic, or OpenAI) under their respective privacy terms.
  • Hosting & Storage: Cloud evidence bundles and qualified tool artifacts are stored in configured database and object storage infrastructure.

Data is shared with providers only to the extent necessary to deliver the configured service.

Retention, export, deletion, and legal holds

Retention Lifecycle: Local session records are retained according to local configuration (default 30 days) and automatically pruned. Cloud-hosted sanitized evidence is retained for the active lifecycle of the workspace or standard 90-day retention periods before scheduled pruning.

Credential Revocation vs. Deletion: Logging out or disconnecting a device revokes authentication tokens immediately and clears local vault keys. Revoking a credential prevents future synchronization but does not delete historical workspace records. Durable data deletion is executed through a separate deletion workflow.

Data Export & Deletion: You can request an export of your personal and workspace data archive, or request durable account deletion. Upon deletion, cloud evidence and account records are purged, and local daemons are instructed to clean local caches.

Legal Holds: When an active legal hold is applied to an account or workspace, automated retention pruning and deletion jobs are suspended for the designated records until the hold is formally released.

Support and contact

For questions about this policy, data export or deletion requests, or technical inquiries, please email hello@resin.sh.

Changes to this policy

This policy may be updated as Resin evolves. The effective date at the top of this page indicates the current revision.

Use of Resin is also subject to the Terms of Service.