Privacy Policy
Last updated: October 4, 2026
DeerDawn ("we", "our", "us") respects your privacy. This policy explains how we handle data.
1. Data Minimization and Scope
Our architecture is designed to minimize what we keep. What DeerDawn stores is the structured context needed to brief your AI tools — task, decisions, open questions, paths — plus a short note, written by DeerDawn, of where each stored fact came from. We do not keep conversation text.
Sending and storing are different, and this section says both. Over the MCP connection itself, a connected client receives only the result of the tool you or the client asks DeerDawn to run.
Separately, if you install the DeerDawn server for Claude Code, its setup adds an end-of-session (Stop) hook to your Claude Code settings. When a session ends, that hook reads that session's transcript from your machine, removes secrets from it (see below), and sends it to be turned into structured context. The transcript itself is not retained after extraction. This is how your brief stays current without you writing it by hand — and it is a capture you can remove: delete the DeerDawn entries under hooks in ~/.claude/settings.json, and nothing is read or sent at the end of a session.
Two other local captures exist and both are narrower. Shell commands run by your agent are captured as runnable commands for the project, on eligible plans, with secrets removed. A local context file — CLAUDE.md, AGENTS.md or .cursorrules — is read and imported only when you ask for it; DeerDawn offers, and does not import one unless you confirm or have turned that on yourself.
2. No Training on Customer Data
We do not use customer data, project context, imported source content, or conversation excerpts to train machine learning models. Your data is used solely to provide the context-sync service you have contracted for.
To power context extraction and matching, project context and conversation excerpts are sent to our LLM subprocessor (OpenAI) via its API under terms that prohibit training on API data and provide limited retention. Processing therefore involves this disclosed third-party subprocessor (see our DPA) rather than remaining solely within DeerDawn's own systems.
3. Data We Collect
We collect and process the following categories of data:
- Account and billing information: Email address, organization name, authentication identifiers, subscription status, and payment metadata. Payment card details are processed by Stripe and are not stored by DeerDawn.
- Context data: Project names, current tasks, goals, open questions, recent decisions, tech-stack notes, file paths, and imported source metadata — those you submit directly, and those extracted from conversations captured by the end-of-session hook described in section 1. The conversation text itself is processed and not kept.
- Connection and authorization data: MCP client registrations, granted OAuth scopes, token metadata, connection status, and revocation events. OAuth credentials are stored encrypted or one-way hashed as appropriate.
- Technical and security data: IP addresses, request IDs, timestamps, setup and sync events, error codes, rate-limit events, and administrative audit records. We redact credentials and avoid placing customer context in application logs.
- Usage information: Feature usage and aggregate analytics used to operate the service, diagnose failures, prevent abuse, and improve onboarding. This includes, for every tool call an AI client makes on your account (reads such as recalling a brief included), one record per day of which tool was called and from which client (for example ChatGPT, Claude or Claude Code). That record never contains the call's arguments, your project context, or what the tool returned.
Redaction before anything leaves your machine. Every local capture path — the end-of-session transcript, captured shell commands, and an imported context file — is run through secret redaction on your own machine first: private keys, API keys and tokens, credentials in a connection string, and values assigned to names like PASSWORD, SECRET or API_KEY are replaced with [REDACTED] before the request is made. The server applies the same redaction again when it writes to your brief. Pattern matching is not a guarantee, so it does not replace your own judgement: you should still not keep secrets, payment details, or unnecessary personal data in project context. DeerDawn provides export and deletion controls in the dashboard.
4. How We Use and Share Data
We use these categories only to provide, secure, support, bill for, and improve DeerDawn; comply with law; and communicate about the service. We do not sell customer context or use it for advertising profiles.
When you connect Claude, ChatGPT, Codex, or another MCP client, that provider may receive the tool output you requested. Its handling of that output is governed by its own terms and privacy policy. You can disconnect a client or revoke its authorization at any time.
Our service providers process limited data on our behalf, including Clerk for authentication, Stripe for billing, OpenAI for context extraction and matching, Resend for service email, PostHog and Google for analytics where enabled, and infrastructure, database, caching, monitoring, and security providers. We may also disclose data when required by law, to protect users or the service, or as part of a corporate transaction subject to appropriate safeguards.
5. Analytics, Cookies & Tracking
Our websites use the following analytics and advertising tools, which set cookies or similar identifiers:
- PostHog: product analytics including autocapture of clicks/inputs/pageviews, heatmaps, and session replay (with input fields masked) to understand and improve the product
- Google Analytics (GA4): aggregate website usage measurement
- Google Ads: advertising conversion measurement
You can limit or block these tools through your browser settings or by contacting us. We are rolling out a consent control for visitors in regions where prior consent is required; where that applies, non-essential analytics and advertising will be gated on your choice.
6. Data Retention and Deletion
On a free workspace, context entries older than 90 days stop appearing in the brief we deliver to your AI tools. They are filtered on the way out, not deleted — they stay stored and come back in full if you upgrade. Paid workspaces receive context without that window. On every plan, deletion happens when you delete something, when a workspace TTL you set expires, or when you delete your account.
OAuth authorization requests expire after 10 minutes, authorization codes after 60 seconds, and access and refresh grants no later than 90 days unless revoked earlier.
Deleting your account removes active workspace data, API keys, OAuth grants, connected-service credentials, and owner-scoped audit records from the primary database as part of the deletion transaction. Encrypted backups age out on their normal cycle, no later than 30 days, unless a narrow legal obligation requires longer retention.
While an account is active, security and administrative audit records may be retained for up to one year. Operational logs are retained only as long as reasonably necessary for reliability, fraud prevention, and security investigations. Legal holds may temporarily override these periods where required by law.
7. Your Controls and Rights
You can view and edit context, export account data, delete projects, revoke connected MCP clients and API keys, or permanently delete your account from DeerDawn settings. Depending on where you live, you may also have rights to access, correct, delete, restrict, or object to processing and to receive a portable copy. We will verify requests before acting on them.
8. Security and Restricted Data
We use HTTPS for MCP and OAuth traffic, encrypt sensitive credentials at rest, apply scoped authorization and tenant isolation, redact sensitive logs, and audit successful MCP writes. No system is perfectly secure. Do not place passwords, private keys, authentication tokens, payment-card data, health records, or other regulated or unnecessary sensitive personal data in DeerDawn context.
9. International Processing and Children
DeerDawn and its service providers may process data in the United States and other countries with appropriate contractual safeguards. The service is for users 18 and older and is not directed to children.
10. Contact
For privacy requests, contact [email protected]. Report security concerns to [email protected].
DeerDawn Inc.
1209 Orange Street
Wilmington, DE 19801