Privacy Policy
Effective July 27, 2026
1. Scope and who we are
This Privacy Policy explains how Carbon Copy Markets Inc., doing business as Hoplite (“Hoplite,” “we,” “us,” or “our”), collects, uses, discloses, and protects information that identifies or can reasonably be linked to a person (“Personal Data”) when you use our websites, applications, APIs, coding agents, sandboxes, integrations, support channels, and related services (collectively, the “Service”).
This Policy does not govern third-party services that you connect to Hoplite or third-party websites that link to us. If you use Hoplite through an organization, that organization may separately control Personal Data in its repositories, prompts, and workspace. Contact the organization about its privacy practices and your rights in that data.
2. Personal Data we collect
Depending on how you use the Service, we collect the following categories of Personal Data:
- Account and identity data, such as name, email address, profile image, authentication identifiers, organization membership, role, and account preferences.
- Customer Content, such as source code, repository metadata, branches, commits, pull requests, issues, prompts, instructions, messages, files, model inputs and outputs, tool calls, terminal commands, environment configuration, and other content processed at your direction.
- Integration data from services you connect, such as GitHub installation and repository information, issue-tracker records, messaging events, OAuth tokens, and integration configuration.
- Usage and technical data, such as IP address, browser and device information, dates and times, routes, feature usage, diagnostics, logs, crash data, performance metrics, agent events, security events, and approximate location derived from IP address.
- Billing data, such as plan, seat count, credit balance, transaction identifiers, billing status, and limited customer and payment metadata received from Stripe. Stripe processes full payment-card details; Hoplite does not store complete card numbers.
- Communications, such as support requests, survey responses, feedback, and records of service or product communications.
3. Sources of Personal Data
We collect Personal Data directly from you; automatically from your browser, device, and use of the Service; from your organization and other workspace members; and from connected services and vendors, including identity providers, GitHub, Stripe, model providers, sandbox providers, issue trackers, messaging services, analytics providers, and security services.
4. How we use Personal Data
We use Personal Data to:
- provide, operate, maintain, and improve the Service;
- authenticate users, manage accounts and workspaces, and enforce permissions;
- execute agent requests, provision development environments, connect integrations, and return outputs;
- process subscriptions, usage, credits, taxes, payments, refunds, and billing support;
- respond to support requests and send transactional, security, service, and product communications;
- monitor reliability, diagnose errors, analyze feature performance, prevent fraud and abuse, and protect users and the Service;
- comply with law, enforce agreements, and establish or defend legal claims; and
- create aggregated or de-identified information that we may use for lawful business purposes where it cannot reasonably identify you.
Where applicable law requires a legal basis, we process Personal Data to perform our contract with you, pursue legitimate interests such as operating and securing the Service, comply with legal obligations, and, where required, with your consent.
5. AI model processing
To perform agent requests, Hoplite may send prompts, instructions, code, files, repository context, tool results, outputs, and related metadata to model providers selected or enabled for your workspace. Hoplite does not use Customer Content to train or fine-tune machine-learning models.
Model providers process data under their applicable business or API terms and privacy commitments. Their retention practices can vary by provider, model, account configuration, and law. Unless we expressly agree otherwise in writing, we do not represent that model-provider processing is subject to zero data retention. Do not submit data that the applicable provider terms do not permit.
6. Cookies and similar technologies
We use cookies, local storage, and similar technologies where necessary to keep you signed in, remember preferences, secure the Service, and provide requested features. Our browser product analytics captures only explicitly modeled events and may use first-party cookies or local storage to maintain anonymous identity and session continuity. We associate analytics with a user profile only after sign-in. Browser settings may let you block or delete these technologies, but doing so can prevent authentication, analytics continuity, or other features from working.
7. How we disclose Personal Data
We may disclose Personal Data in the following circumstances:
- Service providers and subprocessors. We use vendors for cloud hosting, databases, development sandboxes, model inference, authentication, analytics, error monitoring, email, support, payment processing, and security. They may process data only to provide services to us and under contractual restrictions.
- Connected services. We exchange data with services you direct us to connect, such as GitHub, issue trackers, messaging services, and model providers.
- Your organization and collaborators. Workspace administrators and members may access account details, Customer Content, agent activity, billing or usage data, and shared work according to their roles.
- Legal and safety disclosures. We may disclose data to comply with law or legal process, enforce agreements, protect rights and safety, investigate abuse, or secure the Service.
- Business transfers. We may disclose data in connection with financing, due diligence, a merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.
- With your direction or consent. We disclose data when you instruct us to do so or otherwise consent.
8. No sale or behavioral advertising
We do not sell Personal Data or share it for cross-context behavioral advertising, as those terms are defined by applicable U.S. state privacy laws. We do not use Customer Content to advertise to you.
9. Data retention
We retain Personal Data for as long as reasonably necessary to provide the Service, maintain account and transaction records, comply with legal obligations, resolve disputes, enforce agreements, protect security, and support legitimate business operations. Retention depends on the data's nature, sensitivity, purpose, workspace settings, contractual commitments, and legal requirements.
When data is no longer needed, we delete or de-identify it. Deletion from active systems and backups may occur on different schedules, and residual copies may remain until backups are overwritten. Connected services retain data under their own policies. You may request account or Personal Data deletion by contacting support@hoplite.sh; we may need to verify your identity and may retain information where law or legitimate needs permit.
10. Security
We use administrative, technical, and organizational measures designed to protect Personal Data, including access controls, encryption in transit, credential protections, logging, and infrastructure isolation where appropriate. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for securing your account, connected services, secrets, repositories, and local systems.
11. International data transfers
Hoplite is based in the United States, and we and our service providers may process Personal Data in the United States and other countries whose laws may differ from those where you live. Where required for a transfer, we use measures designed to provide appropriate safeguards, which may include approved contractual terms or another lawful transfer mechanism. Contact support@hoplite.sh to request information about safeguards relevant to your data.
12. Your choices and privacy rights
You may update certain account information and communication preferences through the Service. You can disconnect integrations, subject to workspace permissions. Service, security, billing, and legal notices are necessary communications, but product email may include an unsubscribe mechanism where appropriate.
Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of Personal Data; to object to or restrict processing; to withdraw consent; or to appeal a denied request. To exercise a right, email support@hoplite.sh. We may verify your identity and authority, and applicable law may allow or require us to deny or limit a request. Authorized agents may submit requests where local law permits. We will not discriminate against you for exercising a privacy right. If you are in the EEA or United Kingdom, you may also complain to the data-protection authority where you live or work or where you believe a violation occurred.
13. Children
The Service is not directed to children, and you must be at least 18 years old to use it. We do not knowingly collect Personal Data from children under 13. If you believe a child has provided Personal Data, contact us so we can investigate and take appropriate action.
14. Changes to this Policy
We may update this Policy as our Service and practices change. We will post the revised Policy and update its effective date. If changes materially affect how we use Personal Data, we will provide additional notice when required by law.
15. Contact us
For privacy questions or requests, contact support@hoplite.sh or write to Carbon Copy Markets Inc., 2810 North Church Street, Wilmington, DE 19802, United States.