LEGAL — PRIVACY

Privacy Policy

LAST UPDATED — 29 JULY 2026

01 — WHO WE ARE

Precursor, and what this policy covers

Precursor is a macOS application that acts as the memory layer for AI coding agents. It interviews you about a software project and writes every decision, constraint, and open question into a versioned graph that your agents build from.

This policy explains what information Precursor collects, why, how long we keep it, and who it is shared with. It applies to the Precursor desktop application, theprecursor.build website, and any account you create to sign in. Precursor is currently in public beta.

Precursor is operated by the Precursor team. For any privacy question or request, contacthello@precursor.build.

02 — WHAT WE COLLECT

Only what the product needs to work.

ACCOUNT INFORMATION

Depending on the sign-in method you choose, we receive a verified email address, provider account identifier, display name, and optional profile image from Google or GitHub. If you use a magic link, we process your email address through Resend.

Better Auth stores the account, linked identity, session metadata, verification records, and versioned legal acceptances. Precursor does not offer or store passwords.

PROJECT CONTENT

Your conversations, projects, drafts, files, and provider runs remain on your device. Precursor's cloud services do not receive, store, synchronize, or back up this content.

ESSENTIAL DIAGNOSTICS

We process a limited set of allowlisted operational data needed for security, authentication, reliability, and software updates. This may include app version, platform, architecture, updater state, and error codes. It does not include conversation content, prompts, files, paths, tokens, or email addresses.

OPTIONAL PRODUCT ANALYTICS

Product analytics is disabled by default. If you choose "Share," we collect allowlisted feature-usage events without content. You can change this choice at any time without losing core functionality.

SUPPORT AND FEEDBACK

Messages you send us, including bug reports and product feedback, and any information you choose to include in them.

We retain the text and product status of feedback indefinitely. If you delete your account, we remove its link to your identity, contact preference, and attached diagnostics. You may request removal or redaction of personal information contained in a feedback message.

03 — SIGN-IN DATA

How we handle data from Google, GitHub, and magic links.

GOOGLE USER DATA

If you sign in with Google, we receive your name, email address, profile picture, and Google account identifier from Google's OpenID Connect scopes (openid,email, profile). We use this solely to create and authenticate your Precursor account. We do not request access to Gmail, Google Drive, Calendar, Contacts, or any other Google service.

Precursor's use of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements.

  • Access. We request only the sign-in scopes listed above. Authorization happens through Google's consent screen, and you can see exactly which scopes are requested before you approve them.
  • Use. Google user data is used only to provide and improve user-facing features of Precursor — specifically, authenticating you and identifying your account.
  • Storage. We store your Google account identifier, email address, name, and profile picture URL on our servers for as long as your account exists. OAuth tokens are stored encrypted and are used only to establish and verify your identity — never to access Gmail, Drive, or any other Google service.
  • Sharing. We do not transfer Google user data to third parties except as necessary to provide or improve the service (our hosting and authentication providers, as service providers bound by contract), to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
  • Never. We do not use Google user data for advertising, ad personalization, retargeting, or credit assessment. We do not sell it. We do not use it to train, fine-tune, or generalize AI or machine learning models. No humans read your Google user data except with your explicit consent for a specific support request, for security purposes, or where required by law.

You can revoke Precursor's Google authorization at any time fromyour Google account permissions page. Revoking Google authorization prevents future use of that authorization. Use Precursor's session controls to revoke active Precursor sessions, and use account deletion to remove cloud account data.

GITHUB

If you sign in with GitHub, we receive your GitHub account identifier, verified email address, display name, and avatar URL. We use them only to create and authenticate your Precursor account. The OAuth token is stored encrypted and is used only for identity — we do not request or use access to your repositories, organizations, or any other GitHub resource. You can revoke the authorization from your GitHub applications settings, and revoke Precursor sessions from Precursor's session controls.

MAGIC LINK

If you sign in with a magic link, we process your email address to send a single-use sign-in link through Resend, our email delivery provider, and we store the verification record needed to confirm that the link was used. No password is created or stored.

04 — AI AGENTS AND MODELS

Your agents, your subscription.

The desktop application communicates with AI provider tooling that you run under your own account. Selected local context may be sent directly to that provider. Precursor's cloud account service does not receive or store that project content.

That content is handled under your agreement with the provider, whose privacy terms apply to it.

We do not use your project content or your sign-in data to train, fine-tune, or otherwise develop AI or machine learning models.

05 — LEGAL BASES AND SHARING

Why we may process your data, and who touches it.

Where the GDPR or similar law applies, we process your data to perform our contract with you (operating your account and the product), on the basis of our legitimate interests (security, abuse prevention, reliability), to comply with legal obligations, or with your consent where we ask for it.

We share data only with the service providers below, who process it on our behalf, and where required by law or valid legal process. We do not sell personal information and we do not share it for cross-context behavioral advertising.

  • Vercel — website and API hosting, and BotID abuse protection.
  • Neon — managed PostgreSQL database.
  • Better Auth Infrastructure — authentication operations and audit records.
  • Resend — delivery of magic-link and account emails.
  • Google and GitHub — identity providers for sign-in.
  • GitHub Releases — distribution of installers and application updates.

06 — RETENTION AND SECURITY

Kept while you need it, then deleted.

Project content lives on your device and is not subject to our retention schedule. For the cloud data we do hold:

DATARETENTION
Rate-limit records48 hours
Detailed essential diagnostics30 days
Minimal authentication audit90 days
Detailed opt-in analytics90 days
Pseudonymous per-subject rollups12 months
Feedback and its statusIndefinite — unlinked from your identity on account deletion
AccountWhile active, plus a 7-day recovery period

Data is encrypted in transit with TLS and at rest. Access to production systems is limited to the people who need it and is authenticated. No system is perfectly secure, but if a breach affects your data, we will notify you as required by law.

07 — YOUR RIGHTS

Access, correct, export, delete.

  • Request a copy of the personal data we hold about you, in a portable format.
  • Correct data that is inaccurate or incomplete.
  • Delete your account and the data associated with it.
  • Object to or restrict certain processing, and withdraw consent you previously gave.
  • Lodge a complaint with your local data protection authority.

HOW TO DELETE YOUR DATA

You can request account deletion from Precursor after recent reauthentication. We immediately disable the account and revoke its sessions. You may recover the account during the following seven days. After that period, cloud identity data is permanently deleted, subject to narrowly limited legal and security records.

Cloud deletion cannot erase local files on other devices. The desktop application separately lets you export or delete local data. Questions about a request go tohello@precursor.build.

08 — OTHER

Children, transfers, and changes.

Precursor is not intended for anyone under 18 or anyone who has not reached the legal age required to enter into this agreement where they live. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

We and our service providers may process your data in countries other than your own, including the United States. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

Precursor uses host-only cookies on api.precursor.build that are strictly necessary for authentication and session security. We do not use advertising cookies or cross-site tracking.

If we change this policy in a way that materially affects you, we will update the date at the top of this page and notify you by email or in the application before the change takes effect. Questions go tohello@precursor.build.