Privacy Policy

Last updated August 6, 2026

This Privacy Policy explains how MANTEON PTE. LTD. ("Company," "we," "us," "our") collects, uses, discloses, and protects personal data when you visit sourceindex.dev, request access to, or use SourceIndex (the "Services").

We are registered in Singapore at 160 Robinson Road, #14-04 Singapore Business Federation Center, Singapore 068914.

This Privacy Policy is incorporated into our Terms of Service. If you want to know how your source code is handled specifically, see Section 3 of this policy and Sections 3, 4, and 5 of the Terms of Service.

If you do not agree with this Privacy Policy, please do not use the Services.

Table of contents

1. SUMMARY

The short version, in plain terms:

  • We collect very little personal data. Mainly the email address and setup details you give us when you request access, plus operational metadata about how much you use the Services.
  • We do not store your source code. Code passes through our infrastructure in memory only and is not written to persistent storage under our control.
  • We do not train any model on your code or your data.
  • Your index stays on your machine. We never receive or hold a copy of it.
  • Your code is processed by Amazon Web Services and Microsoft. They do not train on it, but they may retain it briefly for abuse monitoring under their own policies. See Section 3(c).
  • We do not sell personal data and we do not share it for cross-context behavioural advertising.

This summary is not a substitute for the full policy below.

2. PERSONAL DATA WE COLLECT

(a) Data you give us

DataWhenWhy
Email addressAccess request; support; correspondenceTo issue an access key and communicate with you
Name, company or organisation (if provided)Access requestTo evaluate and prioritise beta requests
Project type, coding agent used, approximate repository sizeAccess requestTo assess fit for the private beta and plan capacity
Content of your emails and support messagesWhen you contact usTo respond and resolve issues
Feedback, bug reports, and survey responsesIf you choose to provide themTo improve the Services

(b) Data generated by your use of the Services

DataDescription
Access key identifierThe identifier of the key used for a request (not the key itself in plain form)
Operational metadataRequest timestamps, request counts, token counts, inference cost, repository size, and language distribution
Diagnostic dataWhere a request fails: error codes, stack traces, and limited technical context, which may incidentally include file paths
Technical dataIP address, user agent, client version, and similar information sent automatically when your client or browser connects to us

Operational metadata does not include the content of your source code.

(c) Website data

When you visit sourceindex.dev we may collect IP address, browser and device information, referring URL, pages viewed, and similar information. See Section 11.

(d) What we do not collect

We do not knowingly collect special categories of personal data (such as health, biometric, or political data), payment card details (the Services are currently free), or government identifiers.

3. YOUR SOURCE CODE

Source code is not usually personal data, but it may contain personal data — for example, author names in comments, email addresses in configuration files, or personal data embedded in test fixtures. This section explains how source code is handled. It mirrors, and is subject to, Sections 3, 4, and 5 of the Terms of Service.

(a) We do not store it. Source code you submit ("Customer Code") is not written to any persistent storage system under our control. It exists on our infrastructure only transiently in memory for the duration of a request, and is discarded once the response is returned.

(b) We do not train on it, and no one here reads it. We do not use Customer Code to train, fine-tune, or evaluate any model. No SourceIndex personnel reads or reviews Customer Code in the ordinary course of providing the Services. We do not sell, license, or publish it.

(c) It is processed by third-party cloud providers. To generate results, we transmit Customer Code to model-inference services operated by Amazon Web Services and Microsoft. Those providers state that they do not use customer prompts or responses to train their models. However, a provider may retain prompt and response content for a limited period for abuse-monitoring, safety, and service-reliability purposes under its own published policies, which may include limited review by authorised personnel of that provider. Those policies are set by the provider, may change without notice to us, and are outside our control. We make no representation or warranty regarding the data handling practices of any third-party provider. If this matters to you, review their published policies before submitting code.

(d) The index stays on your machine. The index generated for your repository, including the .sourceindex/ directory, is written to and stored on your own device. We do not host, mirror, or retain a copy. Deleting that directory deletes the index; no request to us is needed.

(e) We do not filter secrets. The Services do not detect, redact, or filter credentials, API keys, tokens, certificates, or personal data present in the files you index. You are responsible for excluding such material. If you believe secrets or personal data were submitted in error, contact us at support@sourceindex.dev — but note that, because we do not retain code, there is generally nothing on our side to delete, and any deletion request for retained provider-side data would need to be directed to that provider.

(f) You are responsible for your basis to submit. Where Customer Code contains personal data, you act as the controller of that data and we act as your processor. You are responsible for having a lawful basis for submitting it and for giving any notices required to the individuals concerned. If you require a data processing agreement, contact us.

4. HOW WE USE PERSONAL DATA

We use personal data to:

  • evaluate access requests and issue, manage, and revoke access keys;
  • provide, operate, and maintain the Services;
  • enforce usage quotas, account for inference cost, and detect and prevent abuse, fraud, and security incidents;
  • diagnose and fix errors and improve the reliability and quality of the Services;
  • respond to your enquiries, support requests, and feedback;
  • send service communications about the private beta, including changes, downtime, and end-of-beta notices;
  • comply with legal obligations and enforce our Terms of Service.

We do not use your personal data or your source code to train any machine learning model.

We do not use personal data for automated decision-making producing legal or similarly significant effects.

5. LEGAL BASES FOR PROCESSING (EEA / UK)

If you are in the EEA or UK, we rely on the following legal bases:

PurposeLegal basis
Providing the Services under our Terms of ServicePerformance of a contract (Art. 6(1)(b))
Evaluating access requestsPerformance of a contract / steps prior to entering a contract (Art. 6(1)(b))
Quota enforcement, cost accounting, abuse prevention, securityLegitimate interests (Art. 6(1)(f)) — operating a sustainable and secure service
Diagnostics and product improvementLegitimate interests (Art. 6(1)(f))
Service communicationsPerformance of a contract / legitimate interests
Marketing communications, non-essential cookiesConsent (Art. 6(1)(a)), where required
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object at any time — see Section 10.

6. WHO WE SHARE DATA WITH

We do not sell personal data. We share it only as follows.

(a) Sub-processors

Sub-processorPurposeData involved
Amazon Web ServicesCloud hosting and model inferenceCustomer Code (transient), technical data
MicrosoftModel inferenceCustomer Code (transient)
CloudflareWebsite and API delivery, DNS, security, serverless hosting, and storage of access requestsTechnical data, IP address, access request details
Google (Google Workspace and Google Sheets)Access request intake, record-keeping, and emailEmail address, access request details, correspondence
ResendTransactional email notificationsEmail address, access request details

We maintain a current list of sub-processors and will update this policy before adding or replacing one.

(b) Others

  • Professional advisers — lawyers, accountants, and auditors, under confidentiality obligations.
  • Legal and safety — where we are required by law, court order, or regulator, or where necessary to establish, exercise, or defend legal claims, or to protect the rights, property, or safety of any person.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply to the transferred data.

7. INTERNATIONAL TRANSFERS

We are based in Singapore. Our website and API gateway run on Cloudflare's global edge network, and our sub-processors operate principally in the United States; AWS model inference uses cross-region routing and may process requests in AWS regions outside the United States. Where personal data is transferred out of the EEA, the UK, or Singapore, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and contractual commitments requiring recipients to provide a standard of protection comparable to that required under the Singapore Personal Data Protection Act 2012.

You may request a copy of the relevant safeguards by contacting us.

8. HOW LONG WE KEEP DATA

DataRetention
Customer CodeNot retained by us. Transient in memory only. Provider-side retention is described in Section 3(c)
Local indexHeld only on your device; we never receive a copy
Access request detailsFor the duration of the beta programme and up to 12 months after, unless you ask us to delete them sooner
Access key and associated account recordsFor as long as your key is active, and up to 12 months after revocation
Operational metadataUp to 24 months, for capacity planning and cost analysis
Diagnostic dataUp to 7 days
Support and email correspondenceUp to 24 months
Website analyticsUp to 14 months

We may retain data for longer where required by law or where reasonably necessary to establish, exercise, or defend legal claims.

9. HOW WE PROTECT DATA

We use technical and organisational measures appropriate to the nature of the data, including encryption in transit (TLS), access controls and least-privilege access to production systems, and a design in which source code is never written to persistent storage under our control.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you transmit data to us at your own risk. If we become aware of a personal data breach affecting you, we will notify you and any relevant regulator as required by applicable law.

10. YOUR RIGHTS

Depending on where you live, you may have the right to:

  • access the personal data we hold about you;
  • correct inaccurate or incomplete data;
  • delete your data;
  • restrict or object to certain processing, including processing based on legitimate interests;
  • withdraw consent where processing is based on consent, without affecting prior processing;
  • portability — receive your data in a structured, machine-readable format; and
  • complain to a supervisory authority.

To exercise any of these, email support@sourceindex.dev. We will respond within the period required by applicable law (generally 30 days). We may need to verify your identity before acting.

Note on source code: because we do not retain Customer Code, a deletion request will generally have nothing to act on with respect to your code. Your index is on your own machine and you can delete it yourself at any time by removing the .sourceindex/ directory.

11. COOKIES AND ANALYTICS

We use only cookies strictly necessary to deliver and secure the website. We do not use analytics, advertising, or cross-site tracking cookies. You can block cookies in your browser, though parts of the site may not function.

The SourceIndex command-line client does not use cookies.

12. CHILDREN

The Services are not directed to children and are intended for users aged 18 and over, or the age of majority in your jurisdiction. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

13. SINGAPORE PDPA

We comply with the Singapore Personal Data Protection Act 2012 ("PDPA"). We collect, use, and disclose personal data only for the purposes set out in this policy, or as permitted or required by law. You may withdraw consent to our collection, use, or disclosure of your personal data at any time by contacting our Data Protection Officer, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent may mean we can no longer provide the Services to you.

Data Protection Officer
Email: support@sourceindex.dev
MANTEON PTE. LTD., 160 Robinson Road, #14-04 Singapore Business Federation Center, Singapore 068914

You may lodge a complaint with the Personal Data Protection Commission of Singapore at www.pdpc.gov.sg.

14. EEA AND UK (GDPR)

Controller. For personal data described in Section 2, MANTEON PTE. LTD. is the controller.

Processor. Where Customer Code contains personal data, you are the controller and we act as processor on your instructions. See Section 3(f). A data processing agreement is available on request at support@sourceindex.dev.

Supervisory authority. You have the right to lodge a complaint with your local data protection authority.

15. CALIFORNIA AND OTHER US STATES

We do not sell personal information and we do not share personal information for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act as amended.

If you are a resident of California, Colorado, Connecticut, Virginia, or another state with comparable legislation, you may have rights to know, access, correct, delete, and appeal, and to be free from discrimination for exercising those rights. To exercise them, email support@sourceindex.dev.

Under California's "Shine the Light" law, California residents may request information about disclosures of personal information to third parties for direct marketing purposes. We do not make such disclosures.

16. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. The updated version will be indicated by a revised "Last updated" date and takes effect on posting. Where changes are material — for example, adding a new category of sub-processor that processes source code — we will give notice by email to the address associated with your access key before the change takes effect.

17. CONTACT US

For any question about this policy, or to exercise your rights:

MANTEON PTE. LTD.
160 Robinson Road, #14-04 Singapore Business Federation Center
Singapore 068914
Singapore

Data Protection Officer / General enquiries: support@sourceindex.dev