Privacy Policy
Effective 7 October 2026
This policy explains what Superhands collects, why, who it is shared with, and the choices you have.
Who we are
Superhands is the service at app.superhands.ai that lets a team capture its knowledge and skills in one place and share them with the coding agents its members use. In this policy "Superhands", "we" and "us" refer to the operator of that service, and "you" refers to a person who visits the site, joins the waitlist, creates an account or connects an agent.
Questions about this policy go to hello@superhands.ai.
What we collect
We collect only what the product needs to work. In practice that is:
- Account details: your email address, your name if you sign in with Google, and a password hash if you choose a password. Sign-in is handled by Supabase on our behalf.
- Team details: which teams you belong to, your role in each, invitations you send or accept, and the plan the team is on.
- Content you and your team write: knowledge, skills, instructions and the edits, labels and reviews around them. This is your team's content and it is only ever shown to that team and the agents its members connect.
- Agent activity: when a connected agent asks Superhands for guidance, we record which items were supplied, what the agent reported it changed, and the task context the agent sent with the request. This is what the Activity view shows your team.
- GitHub data, if your team installs the Superhands GitHub App: the installation, the repositories it covers, and repository metadata. Where a feature reads source code it does so at one revision inside a short-lived sandbox that holds no credentials, and the source is not kept after the run.
- Connection tokens: a connected agent holds an access token scoped to one team. We store a hash of it, when it was issued, and when it was last used.
- Billing details, if your team moves to a paid plan: Stripe collects and stores your card details. We keep the Stripe customer and subscription identifiers and the plan state, never the card.
- Waitlist: the email address you give us, and a short-lived record of the network it was sent from, used only to limit repeat submissions.
- Usage analytics: product events such as a team being created, an agent connecting or a plan limit being reached. Events carry counts and opaque identifiers only. They never carry repository names, file paths, source, guidance text, email addresses or tokens.
- Technical logs: the requests our servers receive, including IP address, browser and timing, kept for operating and securing the service.
Why we use it
- To run the service: sign you in, show your team its own content, answer your agents' requests and keep teams separate from each other.
- To bill paid teams and enforce the limits of the free plan.
- To tell you about your account, your team and invitations you have been sent. We do not send marketing email without asking first.
- To understand how the product is used in aggregate so we can improve it.
- To keep the service secure, investigate abuse and meet our legal obligations.
We do not sell your personal data, and we do not use your team's content to train models.
Who we share it with
We share data with the providers that run parts of the service for us, each under its own agreement and only to the extent that part needs:
- Supabase, which hosts our database and handles sign-in and transactional email.
- Vercel, which hosts the application.
- Modal, which runs the short-lived sandboxes used when a feature reads source code.
- Anthropic, whose models judge which guidance is relevant to a task and read source inside a sandbox. Requests are sent through our own infrastructure and are not used to train Anthropic's models under our agreement with them.
- Stripe, which processes payments for paid plans.
- PostHog, which stores the product analytics described above.
- GitHub, when your team installs the GitHub App or signs in through it.
Beyond these, we disclose personal data only when the law requires it, to protect the rights and safety of our users, or as part of a merger, acquisition or sale of assets, in which case this policy continues to apply to the data transferred.
Your team can see your activity
Superhands is a team product. Members of a team can see the content, instructions and agent activity that belong to that team, including the work you and your agents did in it. If you want something kept to yourself, do not put it in a team.
How long we keep it
Account and team data is kept while the account or team exists. When you delete your account, or a team is deleted, its data is removed from our systems within thirty days, except for what we must keep to meet legal, billing or security obligations. Waitlist addresses are kept until you create an account or ask us to remove them. Technical logs are kept for a short, fixed period and then discarded.
Your choices and rights
- You can view and change your account details in Settings.
- A team owner can remove members, revoke agent connections and delete the team.
- You can ask us to access, correct, export or delete the personal data we hold about you, or to stop processing it, by writing to hello@superhands.ai. We will answer within a month.
- If you are in the UK, the EU or another jurisdiction with a data protection authority, you also have the right to complain to that authority.
Security
Data is encrypted in transit and at rest. Access tokens are stored hashed. Sandboxes that read source hold no credentials and are destroyed after each run. Team data is separated by membership checks at the point it is read, not only at the edge. No system is perfectly secure, and if we learn of a breach that affects you we will tell you without undue delay.
Children
Superhands is a work tool and is not directed at children under sixteen. We do not knowingly collect data from them.
Changes to this policy
When we change this policy we update the date at the top. If a change materially reduces your rights we will tell account holders by email before it takes effect.