Privacy policy
1. Who we are
This policy explains how Styx (“we”, “us”) handles personal information. We are responsible for the information described here. Questions, requests and complaints go to hello@heystyx.com.
This policy covers the Styx desktop app, the Styx account service it signs in to, and this website (heystyx.com).
2. What stays on your computer
Styx is a desktop app. The following is stored only on your computer, and we have no access to it:
- your projects, their files, branches and worktrees, and the changes your agents make;
- your agent sessions and conversations;
- the credentials you connect for deploy and server targets (Vercel, AWS, Google Cloud, Supabase, GitHub, SSH). These are kept in your operating system's keychain;
- the approvals and audit log that record what your agents asked for and what you allowed;
- your settings and preferences.
When you use an AI coding agent through Styx (Claude Code, Codex, Gemini CLI, Cursor), the agent runs on your computer under your own account with that provider, and talks to that provider directly. What those providers do with your data is governed by your agreement with them, not by this policy. The same applies to the cloud and hosting services your agents deploy to.
3. Your Styx account
Signing in is optional: Styx works for one project without an account. If you sign in with GitHub or Google, we receive and keep:
- your email address, name and profile picture link, as provided by GitHub or Google;
- which of the two you signed in with, and your ID with that provider;
- your plan and when it ends;
- when your account was created and when you last used Styx.
We never see your GitHub or Google password. We use this information to sign you in, to apply your plan on every computer you use, and to contact you about your account. Keeping it is necessary to provide the account you asked for.
When git on your computer has no name and email set, Styx uses your account name and email to sign the commits it makes. This happens on your computer.
Sign-in codes expire within minutes. The tokens that keep you signed in expire on their own, and signing out revokes all of them.
4. Usage counts
Styx sends a daily count of these events, and nothing else:
- the app was opened;
- setup was finished;
- a project was added;
- an agent was started;
- a message was sent to an agent;
- an access request was approved;
- a deploy was run;
- an agent's work was landed on the main branch;
- the walkthrough was shown, finished or skipped;
- an agent could not start, with one of six fixed reasons: its program is not installed, it would not launch, it is not signed in, it is out of date, it reported an error, or it closed straight away;
- Styx crashed: a window, one of its helper processes, or the app itself (noticed the next time you open it).
With the counts, Styx sends its version number, your operating system (macOS or Windows), and an install id: a random code your copy of Styx makes the first time it runs. The install id is not made from your computer, your name or anything else about you, and on its own we cannot tell who it belongs to. While you are signed in, the counts are also tied to your account.
This lets us see how many people use Styx and which parts they reach. The counts never include a project, file, path, branch, command, prompt, the text of a message or anything your agents produce: the app is built so that it cannot attach them. Our server does not store your IP address with them. You can turn counts off at any time in Styx under Settings › Account › Send usage counts. We keep them for six months and then delete them, and an install we have not heard from in six months is forgotten. We rely on our legitimate interest in understanding how Styx is used; you can object by turning them off.
Feedback
If you send feedback from the app, we receive your message, your email address if you type one (or your account's, if you are signed in), Styx's version, your operating system and your install id. We use it to read and answer what you wrote and to improve Styx, and keep it for a year. Nothing from your projects is attached.
If you tick Include diagnostics when you send feedback (it is off unless you do), we also receive the last part of Styx's own log file, so we can see what went wrong. Passwords, keys and tokens are masked before it leaves your computer. The log can include the names and folders of your projects and the names of the agents you use, but never the contents of your files or anything your agents wrote. It is kept with your feedback, for a year.
5. This website
Hosting
heystyx.com is hosted on Google Cloud. Like any web server, it records each request (IP address, browser, page and time) to keep the service running and secure. These logs are kept for 30 days.
Download counts
The Download button goes through our server, which adds one to a daily count and sends you on to the file. The count records only where the click came from: a short tag in the link (such as ?from=hn) or the name of the website you came from. No cookie is set, and your IP address and browser are not stored with it.
Analytics and cookies
We use Google Analytics, loaded through Google Tag Manager, to understand which pages and links bring people to Styx. It records the pages you view, the parts of the page you reach, clicks on download and outside links, where you came from (including campaign tags in links), your approximate location (country and city, derived from your IP address, which Google Analytics does not store), and your device and browser type.
- Before you choose, and if you decline, no analytics cookies are set. Google receives cookieless signals without identifiers, which it uses only to estimate totals.
- If you accept, Google Analytics sets the cookies
_gaand_ga_VT0TQG7CF8, which last up to two years. Google Analytics keeps event-level data for two months.
You can change your choice at any time: . The site also stores two settings in your browser (not cookies): your light or dark theme, and your cookie choice.
6. Who else handles your information
| Service | What for | Where |
|---|---|---|
| Google Cloud (Google LLC) | Runs the account service and its database, and hosts this website | United States |
| Google Analytics (Google LLC) | Website analytics, as described above | United States |
| GitHub and Google | Sign-in, if you choose it. Their own privacy policies cover what happens on their side | United States |
| Product Hunt | Our Product Hunt badge and card on this site load their images from Product Hunt, which sees your IP address when they do | United States |
| GitHub | The skills catalogue in the app is fetched from GitHub, which sees your IP address when it is loaded | United States |
We don't sell personal information, and we don't share it for advertising.
7. International transfers
Our account service and database run in the United States. Where your information moves across borders, it is protected by our providers' data processing terms, including standard contractual clauses where the law requires them.
8. How long we keep it
| Information | Kept for |
|---|---|
| Your account | Until you ask us to delete it |
| Usage counts and download counts | Six months |
| Feedback you send | One year |
| Install id, version and operating system | Six months after we last hear from that install |
| Sign-in codes and tokens | Until they expire or you sign out |
| Website server logs | 30 days |
| Google Analytics event data | Two months |
9. Your rights
You can ask us to show you the personal information we hold about you, correct it, delete it, give you a copy, or stop using it. You can withdraw consent to cookies at any time. Turning off usage counts stops them at once. To delete your account and its usage counts, email hello@heystyx.com from the address on your account; we will do it within 30 days and confirm when it's done.
If you are unhappy with how we handle your information, please tell us first. You can also complain to your data protection authority: in South Africa, the Information Regulator; in the UK, the Information Commissioner's Office; in the European Union, the authority where you live.
10. Children
Styx is a tool for software developers and isn't meant for anyone under 16.
11. Security
Everything between the app, the website and our servers is encrypted in transit. Our service secrets are held in Google Secret Manager, and access to account data is limited to named administrators. No system is perfectly secure; if we learn of a breach that affects you, we will tell you and the relevant authorities as the law requires.
12. Changes
When we change this policy we update the date at the top. If a change matters, for example we start collecting something new, we will say so on this site and in the app before it takes effect.
13. Contact
Styx. hello@heystyx.com