Privacy Policy

Last updated: 24 July 2026

9th Protocol ("we", "us") provides an agentic coding tool (CLI, VS Code extension, and web dashboard). This policy explains what we collect, why, and what we never touch.

What we collect

What passes through (but is not kept)

When your agent works, prompts (which may include code excerpts and file contents from the project you point it at) are relayed through our API to the model provider you selected (via OpenRouter). We do not store prompt or completion content; only the token counts described above are retained.

What never leaves your device

Third parties

Model requests are fulfilled by OpenRouter and its upstream model providers under their own terms. Payments (when enabled) are processed by Stripe and Dubu Pay, so we never see full card details. We do not sell personal data, run ads, or share data with brokers.

Retention & deletion

Account and metering data are kept while your account exists. You can delete your account and all associated data at any time. See data deletion.

Security

Passwords are bcrypt-hashed, refresh tokens are stored hashed, connector tokens are encrypted at rest, and all traffic uses TLS.

Contact

Privacy questions: support@9thprotocol.com.