Legal
Privacy Policy
Effective 2026-07-21 · sleepy.data-lifecycle.d011.v1
Sleepy is code-blind in its canonical executor/job topology: your client owns the model, source, candidate generation, evaluation, and raw evidence. The hosted service stores only source-free scheduling state and authenticated result projections.
What Sleepy does not collect
- Sleepy does not store your LLM provider API keys.
- Sleepy does not execute your repository, tests, benchmarks, or candidate code on the hosted service.
- The canonical hosted control plane does not receive target source, candidate source, diffs, prompts, model responses, provider payloads, raw benchmark samples, correctness output, local paths, or environment variables.
- Sleepy has no managed-source mode, crash-reporting SDK, or third-party product analytics.
Account and workspace data
When you sign in, Sleepy stores Google OpenID Connect identity fields needed to run the workspace: provider, subject identifier, email address, email verification status, display name, and timestamps. Sleepy also stores workspace names, roles, quotas, usage counters, browser session hashes, and workspace API key hashes.
Browser session cookies and workspace API keys are shown or sent to you as plaintext once. Sleepy stores only hashes for those credentials.
Source-free control-plane data
Canonical executor/job runs store tenant-scoped run and command identifiers, lifecycle and lease state, bounded capability and policy digests, quota counters, candidate reservation identifiers, exact command receipts, source-free decision projections, source-free attestation identities, and opaque cryptographic digests that bind commands to exact local source snapshots and evidence. Those digests are not used for learning. Raw measurements and replay artifacts stay in the client-owned durable store.
Sleepy uses hosted data only to operate the workspace, schedule and resume runs, enforce quotas, return exact receipts, secure the service, and provide source-free status. Sleepy performs no cross-workspace or shared learning from source, prompts, hashes, lessons, candidates, measurements, outcomes, or exported evidence. There is no opt-in exception.
Legacy hosted runs created before the code-blind cutover are quarantined and export-only. They cannot be resumed or used for new processing or shared learning, and they remain covered by the deletion command below.
The explicitly selected, end-of-life MCP compatibility adapter can carry source and prompt payloads through an MCP session and is outside this code-blind product claim. It is not the canonical sleepy.run workflow.
Telemetry
The Sleepy client can send optional low-cardinality usage telemetry: command, evaluator type, language, provider name, duration, generation count, convergence flag, Sleepy version, and platform. It does not send source, paths, run or workspace IDs, source-derived hashes, fitness scores, prompts, responses, provider payloads, raw errors, or API keys.
You can disable telemetry with SLEEPY_NO_TELEMETRY=1, sleepy config set telemetry false, or command-specific --no-telemetry flags where available.
Service logs and operations
Sleepy and Google Cloud process closed operational fields needed for security and reliability. Application logs expire within 14 days, low-cardinality workspace-free metrics within 30 days, and source-free security/audit records within 90 days. Operational telemetry does not contain source, paths, prompts, diffs, provider payloads, raw errors, emails, source-derived hashes, or high-cardinality run/workspace correlators.
Website analytics
If you choose “Allow analytics” in the website prompt, Sleepy loads Google Analytics 4 to measure aggregate website visits and page use. Google may process standard browser and device information, page path and referrer information, and approximate location derived from IP address under its own privacy terms. Sleepy sends no query parameters in its page-view location and disables Google advertising signals. It does not send source code, prompts, run data, workspace contents, API keys, or account credentials to Google Analytics. Choosing “No thanks” prevents the Google Analytics tag from loading; you can clear the sleepy.analytics-consent.v1 local-storage setting in your browser to choose again.
Subprocessors
Sleepy uses Google Cloud in us-central1 for hosting, Cloud SQL, secret storage, monitoring, and backups; Google OAuth and, when enabled, GitHub OAuth for sign-in; and GitHub for releases and public support issues. Your model provider is selected and contacted by your client-owned executor under your provider relationship. Sleepy does not proxy provider calls or silently fall back across providers.
Retention and deletion
Active source-free control-plane records remain while a run is active and are automatically purged no later than 30 days after the run becomes terminal. Browser sessions expire within 30 days; one-use OAuth state expires within 15 minutes. Workspace API-key hashes remain until expiry, revocation, or workspace closure. Source-free daily billing aggregates may remain for 13 months.
From the authenticated workspace dashboard, “Delete workspace” immediately tombstones the workspace, revokes browser sessions and API keys, cancels active runs, and denies further access. Online records are purged within 24 hours. The command returns a policy-versioned source-free deletion receipt retained for one year.
Cloud SQL backups and point-in-time recovery expire through a fixed seven-day rotation; a restore must reapply the separately preserved tombstone before accepting traffic and re-purge restored data. Application logs, metrics, and security records expire on the 14/30/90-day schedule above. This policy does not claim selective deletion inside immutable backup or append-only segments before their fixed expiry.
Security
Sleepy uses HTTPS, platform-managed secret storage, managed database backups, hashed bearer credentials, atomic tenant-scoped commands, and a pinned fail-closed OCI sandbox on the client. No internet service is risk-free. Review source-free receipts and keep client-owned exports according to your own policy.
Changes and contact
This policy may change as Sleepy moves from private alpha toward paid tiers. Material changes will be reflected on this page with a new effective date.
Data questions or deletion requests: privacy@sleepy.run. See also Support and Service status.