Box by ASCII

Privacy Policy

How Dedale AI, Corp. collects and uses personal information for Box. This is a notice, not a contract. The Terms of Service are the contract.

Effective: August 27, 2026Version: 2026-08-27Support: support@ascii.dev

PP-1

Who we are and what this covers

Dedale AI, Corp. ("Dedale," "we," "us," or "our") provides Box, Ascii Box, and Box by Ascii (collectively, "Box"). Our mailing address is 1111B S Governors Avenue, Dover, Delaware, United States.

This policy covers personal information we process when you visit box.ascii.dev or ascii.dev, create a Box account, use the dashboard, CLI, APIs, documentation, hosted virtual machines, snapshots, desktop access, public service URLs, or related Box services.

It does not cover third-party sites, models, or tools you connect to Box. Those have their own policies.

PP-2

Controller and processor

For your account, billing, support, security, and product analytics, we are the controller: we decide why that data is processed.

For what you put inside a Box — code, files, secrets, prompts, cloned repositories, hosted sites, logs you generate, and anything else on the VM disk — we are generally the processor. You (or your organization) are the controller of that content. We process it to provide Box on your instructions, as described in the Terms.

This policy is not a GDPR Article 28 Data Processing Agreement. If you need a DPA, email support@ascii.dev.

PP-3

Personal information we collect

Account and identity. Depending how you sign in: email address; GitHub name, login, email, avatar, and account id; Google name, email, avatar, and subject id; display name; and which sign-in method is primary. We also store session tokens, API keys, and linked identities.

Billing. Plan, seats, credits, invoices, and Stripe customer and subscription ids. Card numbers are handled by Stripe. We may store payment-method references and card fingerprints to bill you and to detect trial or payment abuse.

Usage and operations. Box lifecycle events, resource usage, API and CLI calls, errors, support tickets, and product events. On box.ascii.dev we record first-party funnel events (page view, engagement) tied to a random browser id in localStorage, not to your name.

Security and abuse. IP addresses, device and browser signals, assigned machine IP and MAC records, and related telemetry used to run Box, stop fraud, detect trial farming, and respond to provider or law-enforcement reports.

Integrations you connect. If you connect GitHub, we receive repository metadata and OAuth tokens so we can clone and operate on repos you select. If you send webhook events to your own endpoints, those destinations receive whatever payloads you configured.

Customer content. Whatever you or your agents put in a Box, including snapshots of the disk. See PP-8.

Related Ascii sites. ascii.dev uses Google Analytics. Older Ascii application surfaces may use PostHog (United States) for product analytics and session diagnostics.

PP-4

Why we process it and on what basis

Under GDPR and UK GDPR, we need a legal basis for each purpose:

  • Contract (Art. 6(1)(b)): creating and securing your account, running Boxes, billing, support, and delivering the service you asked for.
  • Legitimate interests (Art. 6(1)(f)): protecting infrastructure, preventing abuse and fraud, understanding how the marketing site converts, and improving Box. You may object; see PP-10.
  • Legal obligation (Art. 6(1)(c)): tax, accounting, and other records we are required to keep.
  • Consent (Art. 6(1)(a)): we do not currently rely on consent for Box itself. If we add optional marketing or non-essential third-party cookies, we will ask first.

You do not have to create an account to read the public website. If you want to use Box, we need account and billing information to perform the contract. Without it we cannot provide the service.

PP-5

Who we share information with

We do not sell personal information. We do not share it for cross-context behavioral advertising on Box.

We share information with processors and providers who help us run Box, including:

  • infrastructure hosts: OVH, Hetzner, and similar VM providers;
  • payments: Stripe;
  • identity: GitHub and Google, when you choose those sign-in methods;
  • email: Resend;
  • storage and edge: Cloudflare, including object storage for snapshots;
  • analytics on ascii.dev: Google;
  • and other vendors we use to host, secure, bill, or support Box.

We may also disclose information if required by law, to protect Dedale, users, or providers, to enforce the Terms, or in connection with a merger, financing, or sale of the business.

Team accounts: members and owners of a Box team can see activity and resources inside that team according to their role.

PP-6

Where data lives and international transfers

Dedale is a Delaware company. Boxes and their snapshots run in the EU (currently Germany, Finland, and France). Account, billing, email, and identity data may be processed in the United States and other countries where we or our providers operate.

When we transfer personal information out of the EEA or UK, we use a lawful mechanism such as an adequacy decision or Standard Contractual Clauses, plus whatever supplementary measures the transfer requires.

PP-7

How long we keep it

We keep personal information only as long as needed for the purposes above, then delete or irreversibly de-identify it, unless a longer period is required for security, abuse prevention, billing, tax, or legal claims.

  • Account. Until you close or erase it, then as described below.
  • Box content and snapshots. For the life of the Box unless you delete the Box or turn on zero data retention. Named snapshots last until you delete them. See Data retention.
  • Close account (dashboard). We archive Boxes, cancel the subscription, and keep a 30-day window to reopen. After 30 days, Box data is purged. Login methods and billing history remain so the account can be reopened empty.
  • Immediate erasure (GDPR). Available from the same dashboard screen. We delete Box content, snapshots, logs, secrets, sessions, API keys, and readable identity as soon as running Boxes can be stopped. This cannot be undone.
  • What erasure still keeps. Billing and usage records we must keep; Stripe customer/subscription ids; machine-assignment history (who had which IP/MAC and when); and a non-readable keyed identifier derived from each verified email, used only to prevent repeat fraud and trial abuse. We do not keep your disk, prompts, messages, or secrets.

PP-8

Customer content and zero data retention

You control what goes into a Box. Do not put data in Box unless you have the right to do so and have decided Box is appropriate for it.

By default, stopping a Box keeps a restorable snapshot. You can delete a Box or snapshot, or enable zero data retention on the Account tab: archived Boxes and named snapshots are then queued for deletion, and future stops do not keep a restorable disk.

We may inspect, log, or act on customer content when needed to operate Box, stop abuse, respond to a legal demand, or debug an outage, as described in the Terms. We do not train foundation models on your Box content.

PP-9

Cookies and similar technologies

box.ascii.dev. We use first-party localStorage and sessionStorage for a random analytics id and a session id. We do not load third-party advertising or analytics scripts on the Box marketing site. The dashboard uses cookies or local storage as needed to keep you signed in.

ascii.dev. That site loads Google Analytics, which sets cookies and sends usage data to Google. You can block cookies in your browser or use a tracker blocker. This is separate from Box sign-in.

PP-10

Your rights

If EU or UK law applies, you can ask us to access, correct, delete, or export your personal information; restrict or object to certain processing; and withdraw consent where we rely on it. You can also complain to your local data protection authority (in France, the CNIL).

If California or similar US state law applies to you, you may have rights to know, correct, delete, and opt out of sale or sharing. We do not sell personal information and do not share Box account data for cross-context advertising. We will not discriminate against you for exercising privacy rights.

How to exercise these rights:

  • Use the dashboard Account tab to close the account, erase immediately, manage sign-in methods, or enable zero data retention.
  • Email support@ascii.dev from the address on the account. We may need to verify it is you. We aim to respond within one month.

Some rights have legal limits. For example, we may refuse to erase records we must keep for billing, tax, security, or fraud prevention.

PP-11

Children

Box is for people 18 or older. We do not knowingly collect personal information from children. If you believe we have, email support@ascii.dev and we will delete it.

PP-12

Security

We use access controls, encryption in transit, isolation of customer VMs, and operational monitoring. No method of transmission or storage is perfectly secure. You are responsible for secrets you place in a Box, for public URLs you expose, and for who you invite to a team.

PP-13

Changes

We may update this policy. The effective date at the top will change. If a change is material, we may also notify you by email, in the product, or on the website. Continued use after the effective date means the updated policy applies.

PP-14

Contact

Privacy questions, requests, and complaints: support@ascii.dev.

Dedale AI, Corp.
1111B S Governors Avenue, Dover, Delaware, United States

This policy is written in English. If a translation conflicts with the English version, the English version controls.