Legal
Last updated: July 23, 2026
This Privacy Policy explains how Alkhemy AI ("Alkhemy AI," "we," "us," or "our") handles information in connection with the Muninn product and the alkhemy.ai website (together, the "Service"). We keep what we collect narrow and we state it precisely.
The short version. Muninn is content-free, not data-free. Muninn never receives your raw code, file contents, file paths, matched strings, or secrets. It receives signed, content-free metadata: fingerprints, keyed pointers, typed verdicts, counts, timestamps, and signatures. We say "content-free" rather than "zero data" because the precise claim is the honest one.
If you join the waitlist, we collect the email address you submit and the timestamp of your submission. We use it only to contact you about Muninn availability and updates. We do not sell it, and we do not share it for others' marketing.
The website is served through Cloudflare's edge network. Standard request metadata (such as IP address, user agent, and timestamps) may be processed transiently to deliver the site, guard against abuse, and keep the Service reliable. We do not use third-party advertising or cross-site tracking scripts on the website.
The website does not set advertising or analytics cookies. Any cookies used are strictly necessary to operate and secure the site.
Muninn analyzes the context behind AI-authored code changes on your side of the boundary and transmits only signed, content-free metadata. This is the boundary, stated precisely.
Muninn never receives:
Muninn does receive:
policy_collision.package_manager = true);
The exact, human-readable finding you see is composed on your machine from content-free pointers; the specifics do not cross the wire. A published, field-level data dictionary documents every field Muninn receives, so this list is verifiable rather than merely asserted.
Muninn establishes identity through GitHub App installation and key-binding rather than a self-asserted email. When you connect GitHub, we process the installation and account identifiers needed to bind receipts to your installation and to post receipts on your pull requests. Your use of GitHub is also governed by GitHub's own privacy policy.
We do not sell your personal information. We share information only with service providers that help us operate the Service (such as our infrastructure and email providers), bound to handle it on our behalf, and where required by law or to protect rights and safety.
We keep waitlist information until you ask us to remove it or until it is no longer needed for the purpose it was collected. Signed metadata and audit records are retained as needed to operate and verify the Service. Depending on your boundary settings, you may retain the richer evidence in your own store, in which case you control its retention and deletion.
We use reasonable technical and organizational measures to protect information, including a content-free architecture that keeps raw content on your side of the boundary, cryptographically signed receipts, and a tamper-evident, hash-chained audit log. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
You may ask us to access, correct, or delete the personal information we hold about you, and you may unsubscribe from the waitlist at any time. Depending on where you live, you may have additional rights under applicable law. To make a request, email support@alkhemy.ai.
The Service is not directed to children under 13, and we do not knowingly collect personal information from them.
The Service is operated from the United States, and information may be processed there and in other countries where our providers operate. By using the Service, you understand your information may be processed in those locations.
We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice.
Questions about this Policy or your data? Email support@alkhemy.ai.