Skip to content

Privacy policy

Your data stays tied to a clear purpose.

This policy explains what personal data To200 handles, why it is needed, where it goes, and the choices you have.

Effective July 25, 2026

1. Who is responsible

Bizlution AB is the data controller for account administration, billing, service security, product communications, and operation of the To200 website.

When your organization submits source code, logs, monitoring events, or other Customer Content, your organization normally decides why that data is processed. In that context, your organization is the controller and Bizlution AB processes the data to provide To200.

2. Personal data we process

  • Account data: name, work email, user identifier, authentication provider, organization, role, and account settings.
  • Workspace & integration data: repository names, provider account identifiers, project configuration, permissions, and connection status.
  • Operational content: source-code context, commit metadata, errors, stack traces, breadcrumbs, logs, task activity, pull-request evidence, and verification output.
  • Billing data: plan, credit balance, usage, transaction identifiers, invoice details, country, and tax information. Stripe handles full payment-card details.
  • Communications: support, security, product feedback, and other messages you send us.
  • Technical & security data: IP address, browser and device information, authentication events, audit records, and diagnostics needed to protect the service.
  • Launch attribution: UTM campaign fields and the page that referred you, when those values are carried into account creation.

3. Why we process personal data

Provide the service

Create accounts, connect tools, run repair workflows, maintain workspaces, and provide support.

Basis: Contract

Secure the service

Authenticate users, prevent abuse, investigate incidents, and maintain audit integrity.

Basis: Legitimate interests

Bill for paid use

Process subscriptions, top-ups, invoices, taxes, credits, and account entitlements.

Basis: Contract & legal obligation

Improve reliability

Diagnose failures, measure product performance, and improve safe stopping and verification.

Basis: Legitimate interests

Communicate

Send transactional messages and respond to requests. Marketing is sent only where permitted.

Basis: Contract, legitimate interests, or consent

Comply with law

Keep required business records and respond to valid legal requests.

Basis: Legal obligation

We do not use your Customer Content to train a public or shared model unless your organization separately agrees to that use.

4. Where data comes from

We receive data directly from you, from your organization’s administrators, and from providers you connect, such as GitHub, Vercel, Supabase, Slack, and Stripe. Operational data may also come from the monitoring script or server endpoint your organization installs.

The exact data available from an integration depends on the provider permissions you approve and your organization’s configuration.

5. Cookies & launch attribution

To200 uses strictly necessary cookies for authentication, session refresh, security, and preferences required to deliver the service. Blocking those cookies may prevent sign-in or workspace access.

Launch links can contain UTM parameters. Those values are carried through the signup flow and stored with account-creation events so we can understand which launch channel created an account. We do not currently set the optional signed attribution cookie or use third-party advertising cookies. If that changes, we will update this policy and request consent where required before enabling it.

6. Service providers & sharing

We share data only as needed to provide, secure, bill for, or lawfully operate the service:

  • Supabase for authentication, Postgres data, and server-side secret storage.
  • Vercel for application hosting, sandbox execution, and AI Gateway routing.
  • GitHub for OAuth, repository context, branches, checks, and pull requests.
  • Stripe for checkout, subscriptions, invoices, tax handling, and the customer portal.
  • Resend for transactional email when email delivery is enabled.
  • Configured model providers selected through Vercel AI Gateway for analysis and generation. Model provenance is recorded with the repair run.
  • Optional connected providers, such as Vercel, Supabase, or Slack, when your organization enables that integration.

We may also disclose data to professional advisers, regulators, courts, or law enforcement when required by law or reasonably necessary to protect rights and safety. We do not sell personal data.

7. International transfers

Some providers may process data outside Sweden or the European Economic Area. When GDPR requires it, transfers rely on an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful safeguard. You may contact us for information about the safeguard relevant to your data.

8. Retention

We keep personal data only as long as needed for the purposes above. Default workspace settings retain operational data for 365 days and audit records for 2,555 days. Workspace retention settings may change those periods within the limits shown in the product.

  • Account and workspace data is kept while the account is active and as needed to close it safely.
  • Billing and tax records are kept for the period required by applicable accounting and tax law.
  • Security records may be kept as needed to investigate abuse, protect users, or establish legal claims.
  • Data may remain longer when law requires it, a dispute is active, or deletion would affect another person’s rights or audit integrity.

9. Security

We use controls designed to protect data against unauthorized access, alteration, disclosure, and loss. These include scoped OAuth permissions, Row Level Security, server-side secrets, access checks, signed events, replay protection, branch isolation, and audit trails.

No internet service is risk-free. Report a suspected vulnerability or data incident to security@to200.dev. See the Security model and Trust center for current controls.

10. Your privacy rights

Depending on the processing and applicable law, you may ask for access, correction, deletion, restriction, portability, or an objection. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.

Send a request to security@to200.dev. We may need to verify your identity and your relationship to a customer workspace. If your request concerns data controlled by your employer or another customer, contact that organization first; we will assist it where required.

You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority.

11. Customer-controlled data

A customer organization decides what repository and production data it connects, who can access the workspace, which autonomy level is enabled, and how long workspace data is retained. If you use To200 through an employer or client, that organization’s policies also apply.

Organizations that need a data processing agreement or details about subprocessors can contact security@to200.dev.

12. Children

To200 is a professional developer tool and is not directed to children. You must be at least 18 years old to create an account. If you believe a child has provided personal data, contact us so we can investigate and delete it where appropriate.

13. Changes & contact

We may update this policy when the service, providers, or legal requirements change. We will post the new effective date and provide reasonable notice of material changes.

Privacy questions and requests may be sent to security@to200.dev or to Bizlution AB, c/o Albin Holmgren, Kalvhagen 7, 427 50 Billdal, Sweden.