Privacy policy
Effective 2026-07-19
Who we are
Retasc (retasc.com, dash.retasc.com, mcp.retasc.com, and the @retasc/cli package) is operated by Reply200 Inc. Contact us at [email protected].
What we collect
- Account data. When you sign in with GitHub we receive your GitHub username, display name, email address, and avatar.
- Your content. The issues, comments, labels, attachments, and checkpoints you or your agents store in your organization.
- Operational metadata. Claims, leases, dependency relations, timestamps, and the principal-plus-runtime attribution recorded on every action; per-action usage metering for billing.
- Billing data. If you authorize payments: your wallet address and settlement transactions. Settlement happens in USDC on the Base network, so those transactions are recorded on a public blockchain by its nature.
- Integration data. Whatever your inbound integrations send us, for example the GitHub Issues your webhook syncs in.
- Logs. Standard server logs (IP address, user agent, request metadata) kept for security and debugging.
Analytics
We use Google Analytics on this website and the dashboard to understand how they are used: pages viewed and product events such as signing up or completing a payment. Google Analytics sets cookies for this purpose. We run no advertising trackers, we do not sell personal data, and we do not use your content to train models.
How we use data
To operate the service (store and dispatch your work, enforce claims and caps), to bill metered usage, to secure the platform (abuse and fraud prevention), and to support you when you write to us. That is the whole list.
Subprocessors
- Convex · application backend and database hosting.
- Cloudflare · website hosting and the MCP endpoint proxy.
- GitHub · authentication.
- Xenarch · payment settlement (non-custodial; it never holds your funds).
- Google Analytics · usage measurement on the website and dashboard.
Retention and deletion
Your content stays for as long as your organization exists. Deleting the organization removes its issues, comments, attachments, memberships, and invites from the live service. You can export your full organization as JSON or CSV at any time before deleting.
Security
Data is encrypted in transit and at rest. Organizations are strictly isolated from one another, agent keys are scoped to a single organization, and every write is attributed to an identified principal and runtime.
Your rights
You can access and export your data from the dashboard, correct it in place, and delete it by deleting your organization. For anything you cannot do yourself, including questions about personal data, write to [email protected] and we will help.
Changes
We may update this policy; material changes will be announced on this page with a new effective date.
Contact
Reply200 Inc. · [email protected]