Home / Privacy Policy

Privacy Policy

Official Spec

StructZero enterprise privacy policy, data isolation, GDPR/CCPA compliance, and governance practices.

Executive Summary StructZero operates in isolated container sandboxes. Your source code, AST project DNA, and conversation transcripts are never used for public model training.

1. Executive Summary & Data Governance

This Privacy Policy describes how StructZero Platform ("StructZero", "we", "us", or "our") collects, uses, stores, and protects personal data and proprietary source code when you access our platform, website, or Model Context Protocol (MCP) server integration.

Enterprise Standard: Your source code, Abstract Syntax Tree (AST) project graphs, and AI debate transcripts belong exclusively to you and are never used to train public AI models.

2. Information We Collect

Account & Identity Information

When registering for an enterprise account, we collect your name, business email address, organization name, and authentication credentials.

Workspace & Codebase Metadata

To perform Project DNA indexing, StructZero parses file paths, exported symbol names, route topologies, and AST structures locally or within isolated execution containers.

Model Context & Conversation Logs

Structured transcripts of multi-model debates and agent tool invocations are logged to your local project directory (.system_generated/logs) for auditability.

Telemetry & Technical Usage

We collect anonymized operational metrics including API request latencies, error codes, and token consumption counters for platform health monitoring.

3. How We Use Information

  • To execute requested architecture debates, code generation, and certification checks.
  • To maintain isolated Model Context Protocol (MCP) server sessions across your preferred IDEs (Cursor, VS Code, Zed, Claude Code).
  • To enforce human-in-the-loop authorization guardrails for billable cloud operations and destructive execution commands.
  • To comply with legal obligations, enterprise security audits, and SOC2/SAIF compliance frameworks.

4. Zero Model Training Guarantee

StructZero maintains strict zero-retention and zero-training agreements with enterprise AI provider partners (Anthropic, Google Cloud Vertex AI, AWS Bedrock).

No source code, file contents, prompts, or AST metadata submitted to StructZero is ever used to train, retrain, or improve foundational AI models.

5. Data Isolation & Security Safeguards

Isolated Container Sandboxes Code compilation and certification checks run in ephemeral, isolated container runtimes with restricted network and filesystem permissions.
Encryption Standards Data in transit is encrypted using TLS 1.3, and data at rest is encrypted using AES-256.
Credential Masking API keys, tokens, and secrets are automatically masked before passing into model context windows.

6. Data Rights & International Compliance

Under GDPR, CCPA, and global privacy frameworks, users have the right to request access to, deletion of, or export of their account data. Requests may be submitted directly to privacy@structzero.app.

Ready to deploy with StructZero?

Connect StructZero's multi-agent debate engine directly into your existing editor using Model Context Protocol (MCP).