Privacy Policy
This Privacy Policy explains how LOUGAO, LLC handles personal information when you use Sandpi websites, hosted applications, and related services.
Scope and who we are
Sandpi is operated by LOUGAO, LLC, a Delaware limited liability company. Our registered office is 651 N Broad St, Suite 201, Middletown, DE 19709, United States. You can contact us at contact@sandpi.ai.
This policy applies to the Sandpi websites, hosted web and native applications, and related services that we operate (the “Service”). It does not govern a self-hosted Sandpi deployment operated by you or another organization. The operator of that deployment is responsible for its own privacy practices.
Third-party services that you connect to Sandpi have their own privacy practices. This policy does not replace the policies or terms of your coding-agent provider, identity provider, source host, MCP server, package registry, or other integration.
Information you provide
We receive account information such as your name, email address, identity-provider identifier, authentication status, and profile details. We also process subscription choices, support requests, feedback, and other information you send to us.
When you use Sandpi, you may provide code, repositories, files, prompts, images, instructions, environment configuration, credentials, schedules, network rules, terminal input, browser activity, and other material (collectively, “Customer Content”). Customer Content may include personal information about you or others.
Workspaces, agents, and connected services
Sandpi processes Customer Content to create and operate persistent Environments, Workspaces, backups, coding-agent Sessions, Automations, terminals, and the shared Environment Browser. Native coding-agent history and Browser profile data may be stored in the persistent Workspace associated with your Environment.
Coding-agent and egress credentials are processed so Sandpi can connect services you select. Sandpi is designed to encrypt persisted credentials and materialize them into a running Environment only when needed, but you and agents running in that Environment may be able to access its connected credentials.
Prompts, files, tool inputs, and other Customer Content may be sent to a coding-agent provider or another integration at your direction. Those providers process the information under the terms that apply to your connected account or integration.
Information collected automatically
We collect operational data such as IP address, request time, browser and device details, application version, referring URL, authentication and security events, resource identifiers, runtime status, usage measurements, error reports, and diagnostic logs.
We use Google Analytics to understand visits and engagement. When enabled, Microsoft Clarity helps us understand page rendering and interactions such as clicks, scrolls, pointer movement, and session playback. These providers may receive identifiers, device and browser details, approximate location derived from IP address, page URLs, and interaction data. See our Cookie Notice for more information and available choices.
How we use information
We use information to:
- provide, operate, maintain, and secure the Service;
- authenticate users and manage Environments, Sessions, subscriptions, quotas, credentials, backups, and Automations;
- process instructions and connect coding-agent and third-party services that you choose;
- monitor reliability, investigate errors, prevent fraud and abuse, and enforce our terms;
- understand and improve performance, usability, capacity, and product features;
- respond to support requests and communicate with you; and
- comply with law and protect rights, safety, and security.
We may create aggregate or de-identified information and use it for reliability, capacity planning, analytics, research, and product improvement where permitted by law.
Legal bases
Where applicable law requires a legal basis, we process personal information as needed to perform our contract with you, pursue our legitimate interests in operating and securing the Service, comply with legal obligations, and protect users and the public. We may rely on consent for certain processing. When we do, you may withdraw consent at any time without affecting earlier processing.
How we disclose information
We disclose information to vendors and service providers that help us provide cloud infrastructure, sandbox execution, storage, databases, authentication, security, analytics, communications, customer support, and payment processing. They may process information only to provide services to us or as otherwise allowed by their terms and applicable law.
We also disclose information to coding-agent providers and other integrations at your direction; to professional advisers; when required by law or legal process; to protect the rights, safety, and security of Sandpi, our users, or others; and in connection with a merger, financing, acquisition, reorganization, or sale of assets. We may disclose information with your consent or as you otherwise direct.
Payments
If you purchase a subscription, our payment processor, Stripe, collects payment and billing details under its own privacy policy. We receive and retain records such as Stripe customer and subscription identifiers, selected plan, transaction status, renewal dates, and limited billing contact information. We do not receive your full payment-card number.
Data retention
We retain information for as long as reasonably needed to provide the Service, maintain security and auditability, comply with law, resolve disputes, and enforce agreements. Retention varies by data type, product setting, backup policy, and the status of your account and resources.
You can delete many Environments, Sessions, schedules, backups, and files through the Service. Deletion from active systems may not immediately remove information from backups, security records, payment records, or logs retained for a limited period. Data held by a connected provider is subject to that provider’s retention practices.
Security
We use technical and organizational measures designed to protect information, including encryption, access controls, workload isolation, network controls, logging, and operational safeguards. No service can guarantee absolute security.
You are responsible for securing your devices, accounts, repositories, API keys, provider credentials, connected services, network policies, and Environment access. Contact us promptly at contact@sandpi.ai if you believe your Sandpi account or Environment has been compromised.
International processing
We and our service providers may process information in the United States and other countries where we or they operate. Those countries may have privacy laws different from those where you live. Where required, we use appropriate safeguards for international transfers.
Your choices and rights
You can update some account and product settings in the Service, manage or delete resources, disconnect integrations, and control cookies through your browser. Depending on where you live, you may have rights to request access, correction, deletion, or portability of personal information; object to or restrict certain processing; withdraw consent; or appeal a decision about a privacy request.
Submit a request to contact@sandpi.ai. We may need to verify your identity or authority and may retain information where permitted or required for security, legal compliance, or legitimate business purposes. You will not be discriminated against for exercising a privacy right provided by applicable law.
If Customer Content contains another person’s information, the customer that controls the Environment is responsible for providing required notices and responding to that person’s request. We may direct the request to the relevant customer.
Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact contact@sandpi.ai.
Changes to this policy
We may update this Privacy Policy as the Service and law evolve. We will post the updated policy and change its effective date. If a change is material, we will take reasonable steps to provide additional notice.
Contact
Questions or privacy requests may be sent to contact@sandpi.ai or to LOUGAO, LLC, 651 N Broad St, Suite 201, Middletown, DE 19709, United States.