What stays in your repository, what reaches Pathmode, and what changes when you connect a workspace.
Last updated: September 4, 2026
Pathmode Oy (Business ID: FI35979677) ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at pathmode.io (the "Service").
By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.
When the Pathmode MCP server runs without an API key, it reads and writes intent.md on your machine and makes no requests to Pathmode. We receive no file contents, repository paths, usage signals, or telemetry from that mode. Your coding agent may still process the file under its own provider's settings; that is a separate data flow controlled by the agent you choose.
The keyless MCP server operates on your filesystem. Pathmode does not receive the contents of intent.md, your local repository path, your Git remote, tool arguments, or a record of which local tools you run. Files remain under your own filesystem and version-control policies.
If you choose to sign in with Google, we receive your email address and name from Google's authentication service. We do not access or store your Google password.
We use the information we collect to:
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
We share information with trusted service providers who help us operate our Service:
All service providers are bound by data processing agreements and are required to protect your information.
These providers apply only to the Pathmode features that use them. The deterministic keyless preflight does not send repository data to Pathmode, Google, PostHog, or another Pathmode service provider.
The Pathmode MCP (Model Context Protocol) server runs on your machine and exposes tools to AI coding agents such as Claude Code, Codex, Cursor, and Windsurf. Its data flow depends on the mode you choose:
intent.md or create and update workspace records. Those requests are subject to the same authentication, workspace authorization, and access controls as the public API and web application.We may disclose your information if required by law, court order, or government regulation, or to protect our rights, property, or safety.
We implement industry-standard security measures to protect your information:
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
Depending on your location, you may have the following rights regarding your personal information:
You can request a copy of all personal data we hold about you. Contact us at privacy@pathmode.io to request your data export.
You can update your account information at any time through your account settings.
You can request deletion of your account and all associated data. Data will be permanently removed within 30 days of your request. Contact us at privacy@pathmode.io.
You can export your workspace data in machine-readable format. Contact us for assistance with data export.
You can object to certain processing of your personal data. Contact us to discuss your concerns.
Where we rely on your consent, you can withdraw it at any time. This will not affect the lawfulness of processing before withdrawal.
We retain your personal information for as long as necessary to:
When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal purposes.
Repo-local files created in keyless mode are not stored by Pathmode and are therefore outside our retention and deletion process; you control them through your filesystem and version control. If you connect and sync an intent, the connected workspace copy is retained under this policy.
Your information may be transferred to and processed in countries other than your country of residence. Our primary data storage is in AWS EU regions (via Supabase). Product analytics are processed on PostHog's EU instance. Some processing may occur in other regions through our sub-processors (e.g., Google Cloud Platform for AI inference).
We ensure appropriate safeguards are in place for international data transfers, including standard contractual clauses and compliance with applicable data protection laws.
Our Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child under 16, please contact us immediately at privacy@pathmode.io.
We may update this Privacy Policy from time to time. We will notify you of any changes by:
You are advised to review this Privacy Policy periodically for any changes. Changes are effective when posted on this page.
Pathmode integrates with third-party productivity tools so that intents and evidence in your workspace can be linked to issues, tickets, and conversations in the tools your team already uses. The sections below describe what data flows between Pathmode and each integration.
Pathmode offers two ways to integrate with Jira: an API token (Basic-auth) integration configured in your workspace settings, and a Forge app ("Pathmode for Jira") installed from the Atlassian Marketplace. The data flows are:
read:jira-work scope. The Basic-auth integration uses your API token's permissions.Linear, GitHub, Slack, Notion, and Google Analytics integrations are optional and follow the same principles: we store only the mapping information and credentials required to make linked calls, never the underlying content of issues, PRs, messages, or analytics events beyond what each workspace member explicitly imports as evidence.
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
For more information about our security practices, visit our Trust Center.
For information about the terms and conditions of using our Service, please review our Terms of Service.
This Privacy Policy is designed to comply with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable privacy laws.