Privacy

Turn Zero is in a beta test phase. This page says what we collect when you use this website and the Turn Zero services, why we collect it, who else sees it, how long we keep it, and what you can do about it. "We" means Turn Zero and the people who operate it, based in Texas, United States. The Terms of Service govern your use of the services.

1. What we collect

When you sign in: the identity your sign-in method gives us, which is your email address, your name where the provider sends it, and the provider's own identifier for you, from Google, GitHub, Microsoft, or an emailed code. If you register a passkey, we hold its public key; the private key never leaves your device.

When you use the services: the applications you create, with their manifests, code, data, files, and configuration; secrets by name, the values held encrypted and never shown again; the actions your AI tool and your browser perform, with the time, the actor, and the outcome; usage counts and measures per application; and the log entries your application writes.

When anything connects: the network address, the path, the time, and the headers of every request reach the hosting provider, whose logs for the platform may hold them; the platform's own log entries record what the platform and your applications write.

When you or your AI tool files feedback about the platform, or records a rating: the report's kind, title, and text, the impact you name, any workaround or proposed fix you give, and your account as the author. The platform adds what its own record holds of the call the report cites: the action, the refusal, the code site, and the platform version and environment. Where the same problem is already known, the refusal or the answer names the issue and any workaround we trust, and once the fix is live your tool is told what to retry. Also the rating's score and reason. We tell AI tools to put no personal details in a report. Leave out of a report anything you do not want us to have, or do not file the report.

After a deploy or a promote puts a new version into production, the platform may put one question to you through your AI tool, at most once in ninety days: how likely you are to recommend it, and why. The question itself is kept with your account and the application that prompted it, and so is how it ended: your answer as a rating, your decline, or the tool's word that it could not ask you. The tool's own answer about the task's difficulty is kept beside it.

When a Blueprint project uses BlueprintService, the service that numbers a project's new requirements and orders its integrations: the project's id, which the project keeps in its own configuration; the names of the project's number lines and the counter on each; and, for each integration turn, the branch name, the commit id, a label naming the AI tool's provider and eight characters of its session, the step the integration has reached, and one word for how it ended. It receives no file, requirement, or other content of the project. For each landing hold a release opens, it receives the hold's name, the same kind of label, when the hold ends, and the repository-relative paths the hold covers, at most sixty-four, never a file's content or a diff. For a queue freeze, a record naming the branches a hotfix needs, it receives the issue each hotfix is tracked under, when the hotfix was declared, the names of the branches the freeze admits, at most thirty-two, and the same kind of label for each session that opens the freeze, admits a branch to it, or closes it.

2. Why

To run the services: to sign you in, to deploy and serve your applications, to enforce plans and quotas, to bill where a plan states a charge, to keep the services secure, and to investigate a fault or an abuse. We do not sell your data, we do not use it for advertising, and we do not use your content to train a model. Feedback you or your AI tools file with us is not your content: we reserve the right to use it to train a model, and we do not do that today. A report filed into an issue space of your own is your content, and we do not use it to train a model.

3. Who else sees it

These are the companies we pass your data to, each named, with what each receives. When one is added or replaced, this list changes with it.

Microsoft, through its Azure cloud, hosts everything in the United States. That covers the platform, your applications with their databases and files, the logs, and the mail that carries sign-in codes and notices. Each request's network address, path, time, and headers reach its logs for the platform.

Your sign-in provider, Google, GitHub, or Microsoft, learns that you signed in to Turn Zero.

Our AI model provider, Google at present, receives the requests the platform's shared AI allowance sends under Turn Zero's own key. It also reads the text of the feedback and ratings you or your AI tools file, when the platform's passes match reports about the platform to known issues. The passes read the platform's own feedback space, and a space of your own where its configuration runs them. With each report the provider reads its title, the impact reported, how it was filed, the details attached to it, whether the platform confirmed them, and the software versions it was seen in. For a space of your own, it also reads the list of parts you set the space up with, each with its name, release line, and file and folder path patterns, and the issue records in that space that the passes read.

Apple and Google, through their notification services, receive each notification's text and data where your application declares the push service, and nothing else of yours.

Adobe Fonts serves the site's typeface and sees each visitor's network address, and none of your content.

Anthropic and OpenAI provide Claude Code and Codex, the AI coding assistants the people who operate Turn Zero use for some of their work. What such an assistant reads reaches its provider. So the operator's assistant surface withholds account holders' sign-in addresses: it answers who the accounts are and how they stand, and no address. Where an operator types an address into it to invite someone, the provider receives that address.

The AI providers your application calls with your own keys receive the requests your application sends them, under your own agreement with them. The people who operate Turn Zero see what they need to run the services, and read the feedback you file. Anyone who holds a Blueprint project's id can read that project's live integration turns, its open landing holds, and its queue freeze in BlueprintService, and can open that freeze, admit branches to it, and close it, so the id is as private as the repository that holds it. And anyone the law requires us to give it to.

4. Your application's users

If your application has its own users, their sign-in identities, sessions, passkeys, and device registrations are held by the accounts service on your behalf, in a realm isolated from every other application's. A device registration is the token a phone's notification service hands your app, kept under the signed-in user. That data is yours: we process it on your instructions to run the service, and you are responsible for the privacy notice and the consents your users need under the law where they are. A user can delete their own account in your application, and the registrations end with it.

5. Cookies

The site sets a few cookies so that a signed-in browser stays signed in: the site cookie, the approval cookie, and the API cookie the dashboard pages use, each signed and each expiring on its own clock. An application's own sign-in sets a session cookie on that application's origin. No cookie tracks you across sites, and the site runs no analytics script.

6. How long we keep it

Log entries are deleted after 30 days, and the hosting provider's logs for the platform are kept 30 days. Usage measures are kept as monthly totals. Your applications, their data, and your identity are kept until you delete them or we close the account. When an account is deleted, the identity, sessions, and passkeys are erased at once, and the applications are torn down with their databases and files the same day; database backups are a rolling window of the last 35 days: any moment in it can be restored and nothing older, so what a deletion erased leaves the backups 35 days later, and a deleted file is gone at once. The platform copies each issue space your account lists, and its own feedback space, on each day the space changes, into storage it keeps for the account that holds the space. A copy is kept 35 days, and the newest is kept until a newer one is written, so an erasure or a dropped report text reaches the copies within 35 days while the daily copies continue. Copies we can no longer match to a space are kept until we remove them by hand. When a space is deleted, with its application or with the account, its copies are deleted with it; a copy that was being written at that moment is deleted at the next daily run. A working copy of the feedback space is kept on the operator's machine and refreshed from the platform; what is erased on the platform leaves it at the next refresh. An application's console output stays in the hosting provider's log store for up to thirty days, and no deletion, erasure, or log purge reaches it. A secret's value stays in the vault's soft-delete state for the vault's retention window of ninety days and is purged when the window ends. The operational records that remain, such as the record of past actions and usage counts, can no longer be tied to a person. No backup is restored to recover a deleted account. BlueprintService deletes the record of an integration turn once seven days have passed since that turn entered: each integration that joins any project's queue deletes up to a hundred such records, the oldest first, and a reading we run every hour joins a queue, so a record normally goes within about an hour past the seven days. It keeps a project's counters and its retired ids. It deletes a landing hold when the hold is closed, or, once the hold has ended, when a later hold is opened in any project, which deletes up to a hundred ended holds, the earliest ended first; a hold ends at most twenty-four hours after it was opened. It deletes a queue freeze when the freeze is closed, and keeps it until then with no time limit. During the test phase we may also delete data without notice, as the terms say.

Feedback and ratings are ours once you or your AI tools file them, as the terms say. We keep them to improve the services and use them for nothing else; that may come to include training a model, and we do not do that today. Each report carries your account's identifier, so that we can ask you about it. When the account is deleted, your identity is erased from every report and rating you filed. The text stays as written, including where it identifies you. A year after the issue a report belongs to is closed, the report's text is dropped; what the platform recorded about the call, the counts, and the issue itself are kept. That period is the platform's own feedback space's. A space of your own keeps its reports' text for as long as you keep the space, unless its configuration sets a period. When the account is deleted, each space of your own, and each of your applications' spaces, is deleted the same day with every record in it.

7. What you can do

Ask your AI tool to export your account, and you receive one file with your account record, your applications and their settings, and your sign-in, push, storage, and upstream settings. It names your secrets and tokens but never holds their values, and it carries the feedback you filed, your ratings, and the questions put to you. Your applications' databases and stored files are exported per application, by a separate request.

Delete your account from the Account page or through the delete_account action; the deletion is approved in your browser and then erases your identity and tears down your applications with their data; section 6 says what remains. Write to us at the postal address or the notice email below about your data. Where the law where you live gives you further rights, such as access, correction, portability, or objection, write to us and we answer within the time that law sets.

Read a report you filed, and its status, by asking your tool for it.

8. Age

The services are for people at least 13 years old, or older where the law where you live sets a higher age, and anyone under 18 needs a parent or guardian's permission. If we learn that we hold a child's data without that permission, we delete it.

9. Changes and contact

We may change this page at any time by publishing a new version here with a new date. Turn Zero, LLC, PO Box 26500, Austin, TX 78755, United States. Our notice email: notices@turnzero.ai.

For anything else, you may email contact@turnzero.ai. A message to that address may not get an answer. To report a service issue or a bug, ask your AI tool to file it with the platform; that is the preferred route.

Published 2026-10-06. This page is the current version.