sessiontwin

Privacy Policy

Last updated: 30 July 2026 · Draft for legal review

Draft — not yet reviewed by a lawyer, and not legal advice. Every factual statement below about what happens to data is derived from the sessiontwin source code (see the Evidence map at the end) and from the current published terms of the hosting platform, Base44. Statements about the platform inherit whatever the platform actually does. Open questions for counsel are listed near the end.

In plain language

sessiontwin lets you ask an AI agent to do a piece of software work and walk away while it runs. To do that we need three things about you: your email and name (so you can sign in and own your work), the task you type, and — for missions that edit code — the file from the repository you point us at. That file, and your task, are sent to an AI model (Anthropic) to do the work, and the result is written to GitHub as a pull request.

We do not show ads, sell your data, track you across other websites, or run analytics or session recording of our own. We don't set our own cookies; sign-in is handled by our hosting platform, Base44.

Two honest limits. First, sessiontwin runs entirely on Base44 (a Wix company), so your data lives on Base44's systems — in the United States by default — and passes through Base44's sub-processors, including the AI providers. Base44's own terms currently permit it to use customer data to improve and train its software tools; we can't promise otherwise than what its contract says. Second, if the code we process on your behalf contains other people's personal information (for example, names and emails in commit history), that comes along with the file — so please don't point us at repositories whose contents you're not entitled to share.

This summary is not a substitute for the full policy below.

1. Who we are

sessiontwin (the "Service", at sessiontwin.ai) is operated by an individual developer established in Israel (the "operator", "we", "us"). The formal legal-entity name, registered address, and a data-protection contact address are [TO BE SUPPLIED BY THE OPERATOR — see open questions]. Until then, privacy queries can be directed to [privacy contact — TO BE SUPPLIED].

2. The data we process, and why

Account data

When you sign in, we process your email address and, if supplied by your login provider, your name, together with an account role. Sign-in is by email/password or Google OAuth, handled by Base44. We also record a timestamp of when you were last active. Purpose: to authenticate you and attach your missions to you. Legal basis (GDPR, where it applies): performance of a contract (Art 6(1)(b)).

Mission data

We process the task you type ("goal"), and for code missions the repository identifier, file path and branch you specify, plus the resulting pull-request references. Purpose: to run and record the mission. Legal basis: performance of a contract.

Repository file contents

For a code mission, we fetch the current contents of the single file you name from the repository, hand it to the AI worker, and store the worker's revised file as part of the mission's signed record. The file — and any personal data it happens to contain (e.g. author names, emails or names in comments) — is therefore processed and stored. Purpose: to perform the requested change. Legal basis: performance of a contract; and, for any third-party personal data inside the file, see section 8 (our role).

Ledger, approvals and verdicts

Every step the agent takes is written to an append-only, cryptographically signed ledger, along with any approval questions you answer and the independent pass/fail verdict. These records are designed not to be edited or deleted — that immutability is the product's core feature. See section 6 on what that means for erasure.

3. Where your data goes (recipients & sub-processors)

sessiontwin is built and hosted entirely on Base44 (operated by Wix.com Ltd.; the controller entity named in Base44's own privacy documents is "Base44, Inc."). Base44 acts as our processor. The following recipients receive data:

RecipientWhat it receivesLocation
Base44 / Wix (platform, database, auth, agents)All account, mission and ledger data; AI promptsUnited States (default)
Anthropic (AI model)Your task and the file contents, as the AI promptUnited States
GitHubThe file, branch, commit and pull request (with mission id and task text)GitHub infrastructure
esm.sh (CDN)Your browser's request for the Base44 SDK (IP, user-agent)Third-party CDN
Cloudflare (CDN / edge)Request metadata and real-user-monitoring performance telemetryCloudflare global network
Base44 sub-processorsPer Base44's DPA Exhibit C — see the Data Processing TermsUS / Germany / UK / Israel

Base44's published sub-processors (which become ours) include MongoDB, SendGrid, Langfuse (Germany), Logfire (UK), Render, Google Cloud, OpenAI, Anthropic, Wix.com Ltd. (Israel), Supabase and DataDog. The full current list, with each one's purpose and country, is maintained by Base44 and reproduced in our Data Processing Terms.

AI providers and training

Your task and file contents are sent to an AI model (Anthropic) via Base44 to perform the work. Base44's Terms of Service, as published, grant Base44 a licence that includes using customer data to train its software tools, including AI/ML models; its Data Processing Addendum states that personal data is used only to provide the service or in anonymised/ aggregated form. These two provisions are in tension. We disclose this rather than paper over it, and we are seeking written confirmation from Base44 of the controlling term and of the retention/training terms of the underlying model providers (this is an open question below).

4. International transfers

Because the Service runs on Base44's US-based infrastructure by default, data from the EU/EEA, the UK or elsewhere is transferred to the United States and other countries where Base44's sub-processors operate. The operator is in Israel, which currently benefits from a European Commission adequacy decision (reconfirmed 15 January 2024), so EU→Israel transfers do not currently require additional safeguards; transfers onward to the US rely on the transfer mechanisms in Base44's DPA (EU-US Data Privacy Framework and/or Standard Contractual Clauses). Adequacy status is under ongoing review — see open questions.

5. What we do not do

6. Retention and your rights

Account data is retained while your account exists and then per Base44's retention and backup practices (Base44 states backups are deleted "after set intervals" — we are confirming the exact period). Mission ledgers are, by design, append-only and immutable.

Where the GDPR, UK GDPR or Israel's Privacy Protection Law applies, you may have rights to access, rectify, erase, restrict, port or object to the processing of your personal data, and to complain to a supervisory authority. To exercise them, contact us at the address in section 1.

Honest limit on erasure. The signed ledger cannot be edited or deleted by design; a public exhibit mission additionally cannot be deleted by its owner. Where an erasure request meets a technical or legal barrier like this, we will explain it, redact where we can (as we already do for the operator's email on public rows), and escalate the conflict rather than pretend it away. Resolving this against data-subject rights is a priority open question for counsel.

7. Security

Missions are signed with a key the backend never holds, so records are tamper-evident even against the most privileged platform write. Hosting security (encryption, access control, penetration testing) is provided by Base44, which asserts SOC 2 Type II and ISO 27001 on its trust pages. See the Security & Vulnerability Disclosure page.

8. Third-party personal data in repositories

Code you ask us to work on may contain other people's personal data (names and emails in commit history, code or comments). If you connect a repository, you confirm you are entitled to have its contents processed. In such cases you are typically the controller of that data and we act as your processor; the Data Processing Terms govern that relationship. (In the current build, code access uses the operator's own GitHub credentials, so this scenario is limited — see the Data Processing Terms.)

9. Children

The Service is not directed to children and is intended for professional developers. We do not knowingly collect data from children under the age set by applicable law.

10. Changes

We will update this policy as the Service changes and revise the "Last updated" date. Material changes will be signposted on this page.

Open questions for counsel

  1. Operator identity & contacts. Confirm the legal-entity name (or that it is a sole proprietor), registered address, and the data-protection / privacy contact to publish in section 1.
  2. Base44 training licence conflict. Base44's ToS licence permits training on Customer Data while its DPA restricts Personal Data to service/anonymised use. Which controls, and does training on our users' data actually occur? Should we disclose it more strongly or seek a carve-out?
  3. Model-provider terms. Confirm the retention/no-training terms of the Anthropic/OpenAI calls Base44 makes on our behalf, and Langfuse log retention.
  4. EU/UK representative (GDPR Art 27). Given continuous public operation, is an EU (and UK) representative required? If so, appoint and name.
  5. Israel PPL / Amendment 13. Confirm whether a Privacy Protection Officer must be appointed, database-notification thresholds, and the breach-notification runbook against the current statute.
  6. Erasure vs immutable ledger. Confirm a defensible position reconciling data-subject erasure/rectification with the append-only, non-deletable ledger and non-deletable public exhibits.
  7. Legal bases. Confirm the stated legal bases (contract vs legitimate interests) for each processing purpose, including the AI processing.
  8. Retention periods. Obtain Base44's actual backup-deletion interval and state concrete retention periods.
  9. `audit` endpoint exposure. Verify whether the unauthenticated `audit` function can disclose a private mission's ledger (see report) before publishing any confidentiality assurance.

Evidence map (source in code)

Each factual claim above traces to the following sources. Full detail: legal/_data-map.md.

ClaimSource
Email/name/role + Google OAuth & email loginbase44/auth/config.jsonc; base44/entities/User.json; base44/functions/chat/entry.js:18
Last-active timestampbase44/entities/User.json:9-13
Task/goal, repo/path/branch storedbase44/functions/chat/entry.js:22,37-40; base44/entities/Mission.json
File contents fetched & stored in ledgerbase44/functions/advance/shared/github.js:readFile; base44/functions/advance/entry.js (kind:"edit")
Sent to Anthropic via Base44base44/agents/worker.jsonc, architect.jsonc (model); base44/functions/advance/shared/agent.js
Written to GitHub as branch/PRbase44/functions/repo/entry.js; base44/functions/advance/shared/github.js
SDK from esm.sh CDNweb/connect.js:24
Immutable ledger (no update/delete)base44/entities/Step.json (rls); base44/functions/advance/shared/steps.js
Operator-email redaction on public rowsbase44/functions/publish/entry.js:33
No ads/analytics/cookies of our own; self-hosted fontsgrep of web/ & *.html (clean); web/fonts.css:1-14
"Twin" learns only from your answers, no stored modelbase44/functions/advance/shared/twin.js:precedent