Admas
ProductPricingCompareSupportStatus
Open Admas ↗

Privacy

Privacy Notice

Effective August 28, 2026 · Version privacy-2026-08-28

Plain-language summary. Admas processes account information and the project material needed to provide an autonomous engineering workspace. Secrets and OAuth tokens use dedicated encrypted storage and are excluded from chat, source exports, and account exports. We do not sell personal information.
ScopeData collectedHow usedProvidersPublic projectsRetentionYour rightsSecurityContact

1. Scope and controller

This Notice describes personal information processed by the operator of Admas for the website, account, autonomous engineering workspace, billing, support, and integrations. It does not govern a third party’s own service or a generated application you operate. For privacy questions or requests, contact [email protected].

The data controller is the Admas operator identified on your applicable order, invoice, checkout receipt, or other written commercial record. When you build an application for other people, you—not Admas—normally determine how that application collects and uses their data and are responsible for your own privacy notices, permissions, and legal bases.

2. Information we collect

  • Account and profile: email, authentication identifiers, display name, company, consent choices, role, sign-in and security events.
  • Project content: prompts, messages, attachments, screenshots, source code, generated output, project names, files, decisions, approvals, previews, and exports.
  • Operation and safety: tool calls, commands, run state, work logs, errors, audit events, usage measures, IP address, browser and device information, abuse and security signals.
  • Billing: plan, credit balance, coupons, checkout and subscription identifiers, charges, invoice state, and cancellation status. Payment card details are handled by our payment provider and are not stored by Admas.
  • Integrations: connected-service identifiers, project references, scopes, status, and encrypted access or refresh tokens. Secret values and tokens are stored in protected server-side facilities and are not intentionally placed in chat or source.
  • Communications: support requests, product feedback, and marketing preferences.
  • Public sharing: share-link identifiers, access and revocation state, preview content, and basic access records needed to deliver and secure a shared preview.
  • Public Projects: the title, description, category, tags, creator display name, sanitized source release, verified preview, publication consent and version, license, safety-scan outcome, remix count, reports, and moderation state for a project you explicitly publish.

If you choose Sign in with Google, Google provides Admas with a stable Google Account identifier, verified email address, and basic profile information such as your name and profile image when available. Admas uses this information only to create, authenticate, secure, and display your Admas account. Admas does not receive your Google password or request access to Gmail, Drive, Calendar, contacts, or other Google services.

Do not submit sensitive personal data, production credentials, regulated records, or information you lack authority to use. If your project requires regulated data, obtain written confirmation that the service and your configuration are suitable before submitting it.

3. Sources

We receive information from you, your browser and device, authorized team members, connected providers, payment and authentication providers, automated project activity, and safety or fraud-prevention services.

4. How we use information

We process information to provide and secure the service; authenticate accounts; carry out instructions; operate model and tool workflows; preserve project history; create previews and exports; meter usage; process subscriptions and coupons; provision approved resources; provide support; prevent abuse and fraud; comply with law; and improve reliability and user experience.

Depending on location, legal bases may include performing our contract, your consent, compliance with legal duties, and legitimate interests such as security, fraud prevention, service improvement, and customer support. You may withdraw consent prospectively where consent is the basis.

We do not use secret values or OAuth tokens for model training. We do not sell personal information or share it for cross-context behavioral advertising. If our practices change, we will update this Notice and provide legally required choices.

5. AI and automated processing

Project content may be sent to selected language-model providers to generate or evaluate output. Provider-neutral routing can change the model used. We configure provider access and retention controls where available, but provider terms and technical behavior also apply. Admas does not use automated processing to make legal, employment, credit, housing, insurance, education, medical, or similarly significant decisions about you.

We do not intentionally use Customer Content to train a generalized Admas model unless we first provide a separate notice and obtain any consent required by law. Model providers may process submitted content under their enterprise or API terms and configured retention controls. Do not submit material that your selected provider is not permitted to process.

6. Service providers and disclosures

We disclose only what is reasonably necessary to providers supporting language models, isolated execution, hosting, databases, authentication, payments, communications, monitoring, security, and support. We may also disclose information to professional advisers, a successor in a business transaction, or authorities when required by law or reasonably necessary to protect rights, safety, and service integrity.

When you connect your own Supabase or another service, Admas sends authorized requests to that provider. Disconnecting stops future Admas access and removes stored authorization, but does not delete data held in your provider account.

If you create a public or read-only share, anyone with the link may be able to view the shared preview until it expires or is revoked. Search engines or recipients may copy material outside Admas. Review the preview and remove confidential information before sharing it.

7. Public Projects and remixes

Projects remain private unless the owner deliberately selects Public & Remixable and completes the publication confirmation. When you publish, we make the public metadata, sanitized source release, and linked verified preview available to anyone. We may index that information in Explore, expose it to search engines, and process downloads, remixes, abuse reports, and moderation actions to operate and protect the public directory.

Before release, Admas classifies paths and scans eligible source for credential patterns and unscannable material. The scanner is a safety control, not a guarantee. It processes project source for the purpose of deciding whether publication is allowed. The public release is a separate immutable copy and is designed to exclude credentials, secret values, connected-service tokens, private runtime bindings, conversation history, work logs, billing data, and private workspace metadata.

A remix creates a new private project for the remixer from the sanitized public release. It does not copy the publisher’s credentials, connected services, private history, billing, or runtime bindings. We record the source release, remixer account, resulting project identifier, and timestamp to provide the feature, prevent abuse, maintain counts, and resolve disputes.

Unpublishing prevents future delivery through Admas public routes, but it does not delete copies already downloaded or remixed and cannot remove material independently retained by recipients, caches, archives, or search engines. We may retain publication acceptance, content hashes, reports, moderation evidence, and transaction records after unpublishing or account deletion where reasonably necessary for security, legal claims, compliance, and enforcement.

8. International transfers

Admas and its providers may process information in countries other than yours. Where required, we use recognized safeguards for cross-border transfers. Contact us for information relevant to your jurisdiction.

9. Retention

We retain account and project information while the account or project is active and for a limited period afterward for recovery, security, dispute resolution, and legal compliance. Work logs and audit evidence may be retained longer than transient runtime caches. Encrypted integration tokens are removed when the connection or project is deleted, subject to backups and legal holds.

Managed database service may enter a transfer window after the paid period before scheduled deletion. Payment, tax, fraud, and transaction records may be retained for legally required periods. Deletion from active systems may take time to propagate through protected backups, which are isolated and expire on schedule.

10. Your choices and rights

Profile controls let you update information and marketing consent. You may download an account summary, export projects, disconnect integrations, cancel subscriptions, and request or initiate eligible account deletion. Account deletion can be blocked until projects are removed, subscriptions end, checkouts close, or administrator access is transferred.

Depending on location, you may request access, correction, deletion, portability, restriction, objection, or withdrawal of consent, and may appeal or complain to a regulator. Email [email protected]. We may verify identity and retain information when an exception applies.

An authorized agent may submit a request where local law allows. We may require signed authority and verification of the account holder. We respond within the period required by applicable law and explain any lawful denial or extension. You may appeal a denied request by replying to the decision.

11. Browser storage

Admas uses cookies or local storage necessary for authentication, session continuity, security, project drafts, and interface state. We do not currently describe an advertising-cookie program. Browser controls may clear storage, but disabling necessary storage can prevent sign-in or workspace continuity.

12. Security

We use measures designed to protect information, including access controls, tenant policies, isolated execution, encrypted transport, protected secret storage, redaction, signed requests, audit evidence, and limited credential exposure. No system is perfectly secure. Protect your account, use least-privilege provider authorizations, keep backups, and report suspected incidents promptly.

We maintain incident-response procedures and will notify affected people or authorities of a personal-data breach when applicable law requires it. Security measures reduce risk but cannot guarantee that every attack, defect, or unauthorized act will be prevented.

13. Children

Admas is not directed to anyone under 18, and we do not knowingly collect personal information from children. Contact us if you believe a child provided information.

14. Changes

We may update this Notice. We will post the effective date and provide additional notice for material changes when required.

15. Contact

Email privacy and data-rights requests to [email protected]. Include the account email and the request type, but never send passwords, payment card data, or secret keys.

Admas

Autonomous software engineering in a durable workspace.

TermsPrivacyAcceptable useRefundsSupportStatus

© 2026 Admas.