Last updated 2026-09-06

Privacy

What we collect, what stays on your machines, who processes what, and how to get rid of it. Written in plain language because we expect operators to actually read it.

The shape of the service

Dark Product Factories (“dpf,” “we,” “us”) is a command line tool and a companion called Atlas that run on your machines, plus an online library of helpers that your subscription unlocks. The work of building your product happens on your side, with your own AI tools and your own keys. Our cloud holds your account, your subscription, and the library. It does not hold your product.

What we collect

Only what we need to run the service for you. Today that means:

  • Your email address, and your GitHub handle if you sign in with GitHub.
  • The fields you fill out on the beta-signup form: what you are building, where you are in the build, the AI tools you use, and any notes you choose to add.
  • Account and subscription records: your plan, the dates you subscribed and cancelled, and the customer identifier and invoice summaries Stripe gives us.
  • Subscription checks. When the tool or Atlas confirms that your subscription is active, we receive your account identity, the tool version, a device identifier, and a timestamp. Nothing about your project travels with that check.
  • Library requests. To deliver a library entry we have to know which entry your tool asked for. We keep those requests only as long as needed to serve them and to detect abuse.
  • Usage signals, if sharing is on. See the next section.
  • Standard request metadata (IP address, browser or tool identifier, timestamps) for the short period needed to serve traffic and prevent abuse.

There is no analytics SDK on this site. There is no marketing pixel. There is no fingerprinting.

Usage signals and contributions

The library gets better when it learns which helpers actually work. Two kinds of information can flow from your machines to us, and they are controlled separately.

  • Usage signals are on by default and can be turned off during setup or in Atlas at any time. They name the library entries your walk selected, their versions, and whether the work they were selected for succeeded. They never include your PRD, your code, your tickets, your evidence, your decisions, or any material you keep on your machines. We show you exactly what a signal contains before the first one is sent.
  • Contributions happen only when you add something to the library yourself: a skill, an agent, a piece of reference material. Everything in the library is shared, so a contribution may be delivered to other subscribers as part of their work. Nothing in the library is openly published. The library holds no private material: anything you want to keep private stays on your machines, and you hand it to your AI tool yourself. Material you never contribute is never sent to us.

Turning signals off stops future signals. It does not undo earlier ones. Contributed items may be evaluated for quality and fit, including with automated tools and AI models, and may remain in the library after your subscription ends. You can ask us to remove specific material and we will handle it case by case; the terms describe the licence you give us when you contribute.

What stays with you

  • Your source code. It stays on the machines and in the repositories you control. We never clone it, and no bot in our cloud opens pull requests on your behalf.
  • Your product record: PRDs, tickets, evidence, decisions, product models, and the state Atlas shows you. It lives on your machines and in the tracker you chose. We do not receive it and do not need it to run the service.
  • Your conversations with AI providers. Your tools talk to your providers with your keys, under their terms. We are not in that path and do not see it.
  • Credit card details. Stripe handles payment data end to end. We receive a customer identifier and an invoice summary; we never see the card.
  • Data about your customers' customers. If your product collects end-user data, that lives in your systems under your privacy policy, not ours.

How we use what we collect

  • To run the service: your account, your subscription, and delivery of the library to your tool.
  • To send transactional email: beta invitations, account notifications, billing receipts. There is no marketing list.
  • To improve the library, using usage signals and the items you chose to contribute.
  • To keep the library current. Our research crawls public sources. When the library is thin for a language or tool you chose, a background research job looks for more, starting from nothing more specific than the name of that language or tool.

We do not train AI models on your material, and we do not hand it to anyone who would.

Sub-processors

We use a small set of vendors to operate the service:

Cloudflare
Hosting, edge network, database, and static assets for this site and the library.
Stripe
Subscription billing, payment processing, invoice records.
GitHub
Sign-in, if you choose to sign in with GitHub.
Resend or Cloudflare Email Workers
Transactional email delivery.
Firecrawl
Web research for the library. It reads public pages, never your data.

We update this list when it changes. If we add a sub-processor that materially changes how your data is handled, we will tell active customers by email.

Retention

  • Beta signups: kept until we invite you, or for eighteen months, whichever comes first. If we do not invite you and you do not ask us to delete it, the record expires on its own.
  • Account and subscription records: kept for the length of your subscription plus ninety days after cancellation, so you can come back without starting over. Then deleted.
  • Usage signals: kept in aggregated form that no longer identifies your account. The per-account detail is deleted with your account.
  • Contributions: remain in the library after your subscription ends, unless you ask us to remove them.
  • Billing records: kept as long as tax and accounting law in our jurisdiction requires.

Your rights

  • Export. Ask us and we will send you a machine-readable copy of the data we hold for your account.
  • Delete. Ask us and we will delete your account and the data tied to it. Backups age out on their normal schedule; we will confirm in writing when the purge is complete.
  • Correct. Tell us what is wrong and we will fix it.
  • Stop sharing. Turn usage signals off in setup or in Atlas. Nothing is contributed unless you add it yourself.
  • Remove a contribution. Tell us what you contributed and what should come out. We locate the material and anything derived from it, agree the scope with you, remove it, and confirm what was done and any limits.

Email [email protected] for any of the above. A human reads that inbox.

Jurisdiction

Dark Product Factories is operated from the United States and governed by US law. We make no GDPR compliance claims at this stage: we are a small beta and the framework's machinery does not yet apply to us. We honor deletion and export requests regardless of where you live.

Changes to this policy

We will update this page when our practices change. Material changes get an email to active customers thirty days before they take effect. The date at the top reflects the current revision.

Contact

[email protected]