ProductIntegrationsPricingFAQFeedbackX

Privacy Policy

Effective date: August 23, 2026

Ceraph is operated by Ike Studios LLC. This policy describes how Ike Studios LLC handles your data.

1. Information We Collect

When you use Ceraph, we collect information necessary to provide the service:

  • Account information (name and email) from the provider you sign in with — GitHub, Google, or an email magic link
  • Your subscription tier, checked against your authentication token to unlock Pro features
  • A bounded set of relevant React Native source files and app configuration when you use an authenticated Pro code-aware planning feature
  • Pending Pro seat invitations and seat assignments, including the invited email address and the account providing access
  • Identifiers for any optional chat connector you link (Slack, Discord, or Google Chat user IDs) for message delivery
  • Payment information (processed by Stripe — we never see or store card numbers)

2. How We Use Your Information

We use collected information to:

  • Authenticate you and verify your subscription tier to unlock Pro features
  • Manage your subscription and billing
  • Send Pro seat invitations and manage access purchased for other users

Agentic flow testing itself runs locally: the package drives your app on your own device or simulator and delivers the results to your coding agent. Your app binary, test credentials and data, camera media, recordings, screenshots, and structured UI snapshots are not sent to us.

3. Data Storage and Security

Ceraph builds, runs, and drives your app locally on your own device or simulator. When you use an authenticated Pro code-aware planning feature, Ceraph sends a bounded set of relevant React Native source files and app configuration to our servers and temporarily caches them under your account. Our servers also hold your account information, subscription and billing status, pending Pro seat invitations and assignments, and the authentication token that links them.

Project-owned test hooks, media fixtures, and recorded-run evidence live under your project's local .ceraph/ directory. Videos, structured UI snapshots, screenshots, and redacted manifests are written to the ignored .ceraph/recorded-runs/ workspace. Generated runs older than seven days are removed locally before a new run starts. The evidence never leaves your machine and is surfaced to your coding agent through the MCP.

Chat platform tokens are encrypted at rest using AES-256-GCM when encryption keys are configured.

4. Third-Party Services

We use the following third-party services to operate Ceraph:

  • GitHub, Google — OAuth sign-in
  • Stripe — payment processing and subscription management
  • Supabase — database hosting
  • Resend — transactional and magic-link email delivery
  • Slack, Discord, Google Chat — optional chat notification delivery

5. Data Retention

We retain your account information and active Pro seat assignments for as long as your account is active. Pending invitation data is removed when the invitation is accepted, revoked, or expires. You can delete your account from Settings or by contacting us. Stripe may retain transaction records as required for payment processing, tax, fraud prevention, and legal compliance.

Cached project source and app configuration become eligible for routine deletion after 30 days without use; cleanup may complete after that point. App bundles, test credentials and data, camera media, screenshots, recordings, and structured UI snapshots remain on your machine — under your project's .ceraph/ directory and Ceraph's local ~/.ceraph/ directory — and are yours to keep or delete.

6. Your Rights

You can:

  • Review your connected accounts and subscription in Settings
  • Delete your account from Settings or by contacting us
  • Request a copy of your stored data by emailing us
  • Opt out of non-essential communications at any time

7. Contact

For privacy-related questions, contact us at privacy@ceraph.dev.