Back to Home

Privacy Policy

Last Updated: 1 October 2026

1. Data We Collect

When you use nstantcode, we collect the following information:

  • Account information: name, email address, and authentication details when you sign up
  • Usage data: feature usage, AI request metadata, timestamps, session information and MCP client names, versions, tool names, project identifiers, outcomes and request durations. Some records are associated with your account
  • Payment information: payment and billing details needed to process purchases through our payment providers. Card payments are handled by the payment provider
  • Technical data: browser type, device information, and IP address for security and analytics

Hosted project content: we store and process project source files, metadata, file history, uploaded assets and the configuration needed to provide cloud development environments, previews and publishing. Managed project databases contain the data you or your application store in them. Project checkouts can also be synchronized to private GitHub repositories. nstantcode therefore has access to hosted project content; it does not use a zero-upload architecture for these projects.

2. How We Use Your Data

We use the collected data to:

  • Provide and maintain project editing, file history, cloud sandboxes, previews, databases, publishing and authorized MCP connections
  • Process payments and manage access to purchased features
  • Send important service updates and security notices
  • Measure usage, diagnose failures, improve reliability and understand how features and connected clients are used

3. Third-Party Services

We use external services where needed to deliver the platform and the integrations you choose:

  • AI providers: prompts, relevant source files and conversation context when you use built-in AI features. Processing by each provider is governed by its applicable terms and privacy policy
  • Payment providers: payment and billing information needed to process purchases
  • Infrastructure, authentication, analytics and development services: account, technical, usage and project data needed to operate the platform. Private project checkout mirrors can be hosted on GitHub

4. Data Security & Retention

Public connections to nstantcode use HTTPS. Account authentication and project-ownership checks restrict access to hosted project operations, and the remote MCP connector requires OAuth authorization. Protect your account credentials and review the access granted to connected clients. Project environment settings and database content may contain sensitive information; include only the data needed for your project.

We retain your account data for the duration of your account and maintain hosted project content to provide the service. You may request deletion at any time by contacting us. Upon account deletion, we remove your personal data within 30 days, except as required by law. Your request can also identify hosted projects, project history, private checkout mirrors and databases to be addressed. Disconnecting an AI client does not delete your nstantcode account or projects; information already received by an external service is subject to that service’s retention and deletion rules.

5. Your Privacy Rights

You have the right to:

  • Access: request a copy of the personal data we hold about you
  • Correction: request correction of inaccurate personal data
  • Deletion: request deletion of your personal data and account
  • Portability: request your data in a machine-readable format

6. Contact

For privacy-related questions or to exercise your rights, contact us at:

7. Connected AI Clients and MCP

When you authorize a client such as ChatGPT, Claude or Codex to connect to https://nstantcode.com/mcp, the connector lets it access supported operations on projects owned by your connected account. Depending on the tools used, it can read and edit source files, run sandbox commands, inspect or change project databases and environment settings, operate a sandbox browser and publish supported apps.

Requested data and tool results are returned to the connected client. They can include source content, project details, database records, browser screenshots, command output and environment values that may contain secrets. The client’s provider processes the conversation and these results under its own terms and privacy policy. Only connect clients you trust and avoid placing unnecessary personal data or secrets in content you ask them to inspect.

The remote nc_* project connector does not call nstantcode’s internal AI coding model to reason about your request. Built-in AI features are a separate flow and can send prompts and project context to the selected AI provider. You can disconnect the integration in your AI client; this does not remove copies of data already returned to that provider.

8. Previews and Published Content

Preview links and published sites make the application’s served content accessible to people who can open those links. Publishing can expose content and data that your application makes available. Review source changes, application access controls and client-visible configuration before sharing a preview or publishing. Keep secrets out of browser code, public assets and other content served to visitors.