1. Who we are
Fixa is a service operated by TELEOPSROBOTICS, LLC. at fixa.dev. We are the controller of the personal data described in this policy. For any privacy question or request, write to support@fixa.dev.
2. What we collect
We collect four kinds of data, and only what the product needs to work.
Account data
When you sign up, our authentication provider Clerk handles the sign up flow and gives us your email address, your name if you provide one, and the identifier of the login method you used, such as a Google or GitHub account. We store that identifier so we can associate your projects with you.
Billing data
Paid plans are processed by Stripe. Stripe collects and stores your payment details. Card numbers never reach our servers. We receive and store your Stripe customer and subscription identifiers, your plan, its status, and the current billing period so we can grant the right usage allowance.
Product data
This is the content of your work with the agent, and it is the largest category:
- Projects you create, including the name and creation history.
- Prompts and chat messages you send, and the agent's replies, including the tool calls it made and their results.
- Files the agent reads, writes, and edits, and the contents of the workspace it runs them in.
- Commands the agent executes and their terminal output.
- Environment variables and secrets you ask the agent to set for a project, which are stored so the sandbox can use them.
- Repository contents, branches, and commits, if you connect a GitHub account and import or push to a repository.
- Per request usage records used to calculate the percentage of your monthly allowance you have consumed.
- Feedback you submit in the app, which is emailed to us.
Technical and usage data
Standard server logs, including IP address, browser user agent, timestamps, and error traces. We also load a Gravity analytics pixel on our pages which records page views, referral source, and the acquisition link you arrived from, so we can understand which pages lead people to sign up.
3. How we use it
- To run the service: create sandboxes, execute the agent, store your projects, and show them back to you.
- To meter usage against your plan and enforce plan limits.
- To bill you and manage your subscription.
- To provide support, respond to your email, and investigate problems you report.
- To keep the platform secure: detect abuse, fraud, and misuse of the compute we hand out.
- To improve the product by looking at aggregate patterns such as which features are used and where builds fail.
- To comply with legal obligations.
We do not sell your personal data, and we do not show third party advertising in the product.
4. How your prompts and code reach AI providers
Fixa does not train its own models. To answer a request, we send the relevant context to a model provider through an AI gateway. That context normally includes your prompt, the conversation so far, and the parts of your code the agent needs to read or change. Depending on the model you select, the provider may be Anthropic, OpenAI, Google, or xAI. If the agent searches the web, the search query is sent to Tavily.
Each provider handles that data under its own terms and privacy policy, which we encourage you to read before putting sensitive material into a prompt. We do not use your prompts or your code to train models ourselves. We cannot make promises on behalf of a provider about its own retention or training practices, so please treat their published terms as authoritative.
5. Service providers
We use the following categories of provider to operate Fixa. Each one processes data only to deliver its part of the service.
| Purpose | Provider |
|---|---|
| Authentication and accounts | Clerk |
| Payments and subscriptions | Stripe |
| Application database and real time sync | Convex, managed PostgreSQL |
| Development sandboxes and previews | Daytona |
| Application hosting | Vercel, Google Cloud |
| AI model inference | Vercel AI Gateway, routing to Anthropic, OpenAI, Google, and xAI |
| Web search used by the agent | Tavily |
| Transactional and support email | Amazon Web Services (SES) |
| Caching and rate limiting | Upstash |
| Product analytics and attribution | Gravity |
| Source control integration | GitHub (only if you connect it) |
We may also disclose data if we are legally required to, or to protect our rights and the safety of our users. If the business is ever sold or reorganized, data may transfer as part of that transaction, and this policy will continue to apply until you are told otherwise.
6. Retention and deletion
- Projects, messages, and files are kept until you delete them. Deleting a project from your dashboard removes it from your account and schedules its data for deletion.
- Sandboxes pause automatically after a period of inactivity and their contents are removed once the workspace is reclaimed.
- Usage records and billing records are kept for as long as we need them for accounting, tax, and dispute purposes.
- Server logs are kept for a short operational window and then rotated out.
To delete your account and the data attached to it, email support@fixa.dev from the address on the account. We will confirm and complete the deletion, keeping only what the law requires us to retain.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You also have the right to complain to your local data protection authority. Exercise any of these by emailing support@fixa.dev. We do not charge for these requests and we do not treat you differently for making one.
We do not sell or share personal information as those terms are defined under California law.
9. Security
Access to production data is limited to the people who need it to operate the service. Data is encrypted in transit, agent code runs in isolated per project sandboxes rather than on shared machines, and credentials are stored as secrets rather than in plain application data. No system is perfectly secure, so if you believe you have found a vulnerability, please report it to support@fixa.dev before disclosing it publicly.
10. International transfers
We and our providers operate in the United States and other countries, so your data may be processed outside the country you live in. Where required, transfers rely on the standard contractual clauses or another lawful transfer mechanism offered by the provider involved.
11. Children
Fixa is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has created an account, contact us and we will remove it.
12. Changes to this policy
We will update this page when our practices change, and we will move the last updated date at the top. If a change materially affects how we handle your data, we will tell you in the product or by email before it takes effect.
13. Contact us
TELEOPSROBOTICS, LLC., operator of Fixa. Privacy questions and requests: support@fixa.dev.
This policy describes how we actually operate the service today. It is written for clarity rather than as legal advice, and it does not replace advice from your own counsel about your specific situation.