Privacy Policy
Effective July 10, 2026
This Privacy Policy explains how Default Alive LLC, a California limited liability company doing business as BoxHaven ("BoxHaven," "we," "us," or "our"), collects, uses, discloses, and retains information when you use the hosted BoxHaven websites, console, API, command-line service, remote machines, and support (collectively, the "Service"). It does not govern a self-hosted BoxHaven deployment operated by someone else.
1. Information we collect
Information you provide
- Account information: name, email address, password hash, GitHub account identifiers, authentication tokens, and account preferences.
- Team and support information: team names, membership, invitations, messages, feedback, and information you send when requesting help.
- Billing information: team billing status, subscription and customer identifiers, usage, and transaction metadata. Stripe processes payment-card details; we do not receive full card numbers.
- Customer Content: code, files, prompts, command output, agent sessions, environment data, credentials, and other material you choose to sync, forward, store, or run on a hosted machine.
Information collected through the Service
- Machine and usage data: machine names, provider, region, size, IP address, status, team ownership, image and snapshot metadata, connection state, preview hostnames, and timestamps.
- Device and log data: IP address, browser or client type, operating system, request metadata, error reports, security events, and diagnostic logs.
- Local storage and cookies: the console stores an authentication token in browser local storage and may use cookies during authentication. Our providers may set strictly necessary cookies.
Information from others
We may receive profile and authentication information from GitHub, billing and payment status from Stripe, delivery information from Resend, machine information from infrastructure providers, and team invitations or account details from other users.
2. How we use information
We use information to:
- provide, operate, authenticate, maintain, and support the Service;
- provision machines, sync projects, issue connection credentials, route previews, and run commands you request;
- manage teams, subscriptions, metered usage, payments, and transactional email;
- secure the Service, prevent abuse, debug problems, and enforce our Terms;
- understand and improve performance, reliability, and product design;
- communicate about accounts, changes, security, and support; and
- comply with law, resolve disputes, and protect rights and safety.
3. How we disclose information
We may disclose information to the following categories of recipients:
- Infrastructure and service providers that host the website, control plane, remote machines, email, monitoring, and related systems, including GitHub, DigitalOcean, Hetzner, and Resend.
- Payment providers, including Stripe, to create customers, process subscriptions and usage charges, prevent fraud, and manage billing.
- Authentication and integration providers, including GitHub, when you connect or use those services.
- Your team, including owners and administrators who can view and manage team members, machines, images, usage, and billing.
- Professional advisers and business counterparties in connection with legal, accounting, financing, merger, acquisition, reorganization, or sale activities.
- Authorities and affected parties when we believe disclosure is required by law or reasonably necessary to protect the Service, users, providers, rights, property, or safety.
A tool or coding agent you run may send Customer Content to its own provider under your account and instructions. Those transfers are controlled by you and governed by that provider's terms and privacy policy.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use third-party advertising trackers.
4. Customer Content and hosted machines
Project sync normally transfers files directly between your device and your hosted machine. Customer Content resides on infrastructure operated for us by our cloud providers. BoxHaven and its providers may have administrative access to hosted machines and may process Customer Content when necessary to provide support, protect the Service, investigate abuse, comply with law, or as otherwise directed by you. Do not place regulated, highly sensitive, or third-party data in the Service unless you have determined that doing so is lawful and appropriate.
Preview URLs are public unless you secure the application running behind them. Anyone with a preview URL may be able to access the content your machine serves there.
5. Retention
We retain account, team, machine, billing, and log information for as long as reasonably necessary to provide the Service, maintain security and business records, comply with law, and resolve disputes. Retention periods depend on the type of information, why we use it, and legal or operational needs. Hosted machine data remains until the machine is destroyed or the account is terminated and may be deleted without a recovery period. Providers may retain backups or logs for limited periods under their own retention practices. We may retain de-identified information that cannot reasonably identify you.
6. Security
We use reasonable administrative, technical, and organizational measures designed to protect information. No system is completely secure. You are responsible for protecting account credentials, limiting agent permissions, securing services on your machines, and maintaining independent backups. Please report suspected security issues to security@boxhaven.dev.
7. Your choices and rights
You may update certain account and team information in the console, disconnect integrations, destroy machines, or cancel billing through the billing portal. You may request access to, correction of, or deletion of personal information by emailing legal@boxhaven.dev. We may verify your identity and authority, and may retain or decline to delete information where permitted or required by law. Depending on where you live, you may have additional rights, including rights to appeal or complain to a regulator. We will not discriminate against you for exercising a privacy right.
8. California online tracking disclosures
The Service does not currently track users across unaffiliated websites for targeted advertising. We therefore do not currently respond differently to browser "Do Not Track" signals, which are not standardized. Because we do not sell personal information or share it for cross-context behavioral advertising, there is no sale or advertising share to opt out of. Other parties may collect information about your activity over time and across services when you intentionally use their integrations, such as GitHub or Stripe, or follow external links; their practices are governed by their own policies.
9. International use
We and our providers may process information in the United States and other countries where privacy laws may differ from those where you live. By using the Service, you understand that information may be transferred to and processed in those locations, subject to applicable law.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. You must be at least 18 to create an account. Contact us if you believe a child has provided personal information.
11. Changes to this Policy
We may update this Policy to reflect changes in the Service or law. We will post the updated Policy, revise the effective date, and provide additional notice of material changes when required. Your continued use of the Service after the effective date is subject to the updated Policy.
12. Contact
For privacy questions or requests, contact Default Alive LLC at legal@boxhaven.dev.
