Privacy Policy
Last updated: 3 September 2026
Bystep (bystep.dev) turns an idea or a codebase into a PRD, features and tasks, and hands those tasks to your AI coding agent. This policy explains what we collect, why, and what you can do about it.
1. What we collect
Account data: your name, email address and profile picture from Google Sign-In. Product data: the ideas, answers, PRDs, features, tasks, chat messages and attachments you create in Bystep. Codebase data: when you run `bystep sync`, the CLI uploads file paths, sizes and short summaries of your repository — never your source code or `.env` files. Technical data: IP address, browser type, pages visited and first-touch attribution (UTM parameters, referrer).
2. How we use it
To run the service: generate documents, plan work, sync with your agent and show your history. To bill you and prevent abuse (quota, rate limits, fraud checks). To improve Bystep, using aggregated and anonymised usage statistics. To answer support requests. We do not sell your data and we do not use your content to train models.
3. AI processing
Your ideas, answers, documents, chat messages and codebase summaries are sent to third-party large-language-model providers to generate results. They are transmitted over encrypted connections and processed under the providers' API terms, which exclude training on API inputs.
4. Payments
Payments in Indonesian rupiah are handled by Pakasir (PT Geksa) through QRIS and virtual accounts; payments in US dollars by Paddle, which acts as merchant of record. Bystep never sees or stores your full card number. We keep the order id, amount, payment method and status.
5. Cookies and analytics
We use strictly necessary cookies for your session, language and theme. Where enabled, Google Analytics and Microsoft Clarity collect anonymised usage data to help us understand how the product is used. You can block them with a browser extension without losing any functionality.
6. Retention and deletion
Your data is kept for as long as your account exists. Delete plans, workspaces and attachments at any time from the product. To delete your whole account and all associated data, email us; we complete deletion within 30 days, except for records we must keep for tax or accounting purposes.
7. Your rights
You can access, export (PRD as Markdown, project as ZIP), correct and delete your data. If you are in the EU/EEA or UK, you also have the rights granted by the GDPR, including the right to lodge a complaint with a supervisory authority.
8. Security
Data is encrypted in transit (TLS) and stored on servers with access limited to the Bystep team. API tokens are shown once and stored hashed. No system is perfectly secure; report any concern to the email below.
9. Changes
We may update this policy. Material changes are announced on the site or by email before they take effect.