Privacy
Privacy notice
What Pact does, and does not do, with your data.
Last updated 7 October 2026 · Applies to the preview build
The short version
When you run a job, the job text, the files you attach and the result are sent to and kept by the Pact server so you can come back to them. There are no accounts yet: your runs are tied to an id your browser generates. Nothing is sold, and nothing is used for advertising.
What is stored, and where
- Jobs and results. The text you type, the plan Pact made, which tools ran (names, timings, counts), the progress lines, and the result. Stored on the Pact server.
- Files. Uploaded files are checked, read on the server to extract their text and tables, and kept with that extracted text so the agent can use them. They are not sent to an outside service to be read.
- Links and repositories. Kept as text with the run. A page is fetched only when a reader provider is configured; a repository is read only when a GitHub token is configured.
- Your browser id. A random id in your browser's local storage, sent with each request to scope your runs and files. Clearing site data creates a new one; the old runs stay on the server but are no longer reachable from that browser.
What goes to third parties
Only when the operator of this deployment has configured the provider, and only what the job needs:
- Language models (Claude, Gemini and open-weight models, through their API providers). The job, a brief, and the evidence gathered for it (file text, page text, search snippets) are sent to plan the work and write the result. The result shows which model did the work.
- Web search providers. The search query derived from your job.
- Page reading providers. The URL to read.
- GitHub. The repository and file paths to read.
Provider credentials belong to the deployment, never to you, and are never shown or stored with a run. If a provider is not configured, the related step is skipped and reported as unavailable.
What we do not collect
The site uses no analytics, advertising trackers or third-party cookies. Server logs record run ids, tool names, durations and error codes, not the contents of jobs or files. Typefaces are bundled with the site and served from the same origin.
Retention and deletion
Runs and files are kept until deleted. There is no delete button yet; it arrives with accounts. Until then, ask us and we will remove them, or run your own deployment, where .pact-data holds everything and can be emptied at any time.
When this changes
Accounts, a hosted database, or new providers will change where data lives. This notice is updated before any of that ships; the date at the top tells you which version you are reading.
Contact
Questions about this notice can be sent to us on X at @runpactfamily. See also the terms of use.