[Pintle]

Privacy Policy

Pintle Ltd

Last updated: 25 June 2026 · Version 1.0

1. Who we are and what this policy covers

Pintle Ltd (“Pintle”, “we”, “us”) runs an API for engineering agent skills: filing Linear issues from incident threads, drafting GitHub pull requests and updating Notion pages. It runs only when a system you control calls it. The prompts behind each skill live in your repository. The log of each run is saved to storage you name before we confirm the run. The credentials a run uses arrive with the request and are discarded when it ends.

Registered at 22 Lower Baggot Street, Dublin 2, D02 Y243, Ireland.

We handle personal data in two different situations, and different rules apply to each:

Whose dataOur roleWhat applies
Part APeople who visit this website, ask about the service or write to usController: we decide why and how the data is usedThis policy
Part BWhat you send with each run, our seven-day copy of the run log, the prompt folder we fetch from your repository during a run, the tokens in the request, your issue index and recorded match decisions, and the account, key, credit and invoice records that come with having an account.Set out in B.1, because it depends on the dataThis policy and the data processing agreement we sign with each customer

If the data processing agreement (“DPA”) and this policy ever disagree about Part B, the DPA wins.

2. Part A: this website and our contact with you

This part covers the personal data we collect for our own purposes: running this website, answering requests, and staying in touch with people who are or might become customers.

A.1 What we collect

What you give us. When you send the form on this site, we collect what you type into it, such as your name, email address, phone number or company, and the fact that you agreed to be contacted. If you email or talk to us, we keep that correspondence and any contact details in it.

What is collected automatically. Our web server records the IP address a request came from, the browser used, the pages requested, the page you came from and the time. These logs exist to keep the site running and secure.

We don’t ask for sensitive data (the “special categories” in Article 9 GDPR) through this website, so please don’t send any through the form.

A.2 Why we use it, and what allows us to

WhyWhatLegal basis (GDPR Art. 6)
Answering your request and working out whether the service fitsWhat you sent in the form, our correspondenceArt. 6(1)(b): steps you asked for before a contract
Looking after customers, billing and supportContact details, correspondenceArt. 6(1)(b): carrying out a contract
Keeping the site running, secure and free of abuseServer logsArt. 6(1)(f): our legitimate interest in running a secure service
Contacting you about the serviceEmail address, companyArt. 6(1)(f): our legitimate interest in business-to-business marketing. You can object at any time
Meeting tax, accounting and legal dutiesBilling and contract recordsArt. 6(1)(c): a legal obligation

Where we rely on legitimate interest, we have weighed that interest against your rights, and you can ask to see the assessment.

A.3 How long we keep it

A.4 Your rights

If you are in the EEA or the UK, you can ask to see your data, correct it, have it deleted, limit or object to how we use it, get a copy you can take elsewhere, and withdraw consent where we rely on it. Write to [email protected] and we will answer within one month.

You can also complain to a data protection authority. If you are in the EEA, that can be the authority where you live or work.

3. Part B: data inside the service

Two kinds of data pass through Pintle, and we treat them differently. The first is yours and short-lived: the incident thread, issue text, diff and tokens you send for one run. We hold them for that run and a seven-day support window. The second is ours and small: account, key and credit records for the people who signed up. This part covers both, in that order.

B.1 What we handle, and in what role

For everything inside a run we are your processor and act only on what the request tells us to do. For account data we are the controller. Nothing inside a run is used for anything other than completing that run and saving its log where you told us to.

We hold no long-lived credential to any of your tools, and we won’t accept one. Every token arrives with a run and leaves with it.

We keep no memory between runs. Two runs share nothing unless your input or your prompt folder makes them.

We read nothing in your repository beyond the one folder you point to, at the commit you pinned.

B.2 What we do with it

Everything runs in Dublin. The API, the run logs, the issue index, and the account and invoice records run on cloud infrastructure in Dublin. The embedding search and the match classifier run on cloud GPU capacity we control in Dublin. We have no second location.

One hosted model provider, at its EU endpoint. The planner’s text generation goes to one hosted model provider at its EU endpoint, under zero-retention and no-training terms. It receives the prompt folder and input of the run it is serving, and nothing from any other run or customer. The provider is named on our subprocessor list, and our about page says when this step moves onto capacity we control.

Your run log leaves before we answer. The run log is streamed to the storage or webhook you named while the run is happening. You get a 200 only after your storage has confirmed the last line. Our own copy is for support and replay. We keep it seven days, then delete it.

Tokens end with the run. Tokens live in memory for the run, are hidden in logs and traces, and are wiped when the run ends, whether it worked or failed.

Match decisions stay with you. When a person settles a proposal, we record the candidate ids the model offered and the id the person chose. We never record the thread text. Those pairs are kept for your account only, never pooled with another customer’s, and deleted with the account.

B.3 AI models: where they run and what they learn from

Where models run. Models run in two places. The embedding search and the match classifier run on cloud GPU capacity we control in Dublin. The planner’s text generation goes to one hosted model provider at its EU endpoint, under zero-retention and no-training terms. It receives the prompt folder and input of the run it is serving, and nothing from any other run or customer. The provider is named on our subprocessor list. From Q1 2027, incident triage and PR drafting run on a fine-tuned open-weight planner on the same GPU capacity in Dublin. The other skills follow by Q3 2027, and from then the hosted provider is opt-in per key.

Training. We don’t train any model on your run inputs, run logs or prompt folders, and the hosted provider is bound not to either. There is one narrow exception. When a person settles a proposal, we record the candidate ids the model offered and the id the person chose, never the thread text. Those pairs are kept for your account only, never pooled across customers, used only to tune your matching, and deleted with the account.

Where a person decides. The model proposes and a person decides. Below a confidence of 0.85 Pintle files nothing. It returns ranked candidates as a proposal and stops, and the approval step in your own pipeline sends it to a named person. Above the threshold it files an issue or drafts a pull request, and a person still merges, closes and assigns. This service never takes a decision with a legal or similarly significant effect on a person automatically.

B.4 Where the data is kept

All processing and storage is on cloud infrastructure in Dublin, Ireland. The embedding search and the match classifier run on cloud GPU capacity we control in Dublin.

The one exception is the planner’s text generation. It runs at the EU endpoint of a single hosted model provider under zero-retention terms. The provider is named on our subprocessor list.

The permanent home of your run logs is the storage you named, wherever you put it. We don’t choose it, and we keep no copy beyond seven days.

The suppliers that handle data in the service are named on our subprocessor list, which comes with the data processing agreement and which we send to anyone who asks: write to [email protected].

B.5 How long we keep it, and what deleting can’t remove

What you send with a run, and our copy of the run log: seven days after the run ends, then deleted. The copy in your storage is the record.

Tokens in the request: for the length of the run. Never written to disk.

Your prompt folder: for the length of the run.

Your issue index and recorded match decisions: while the account is open, and thirty days after it closes.

Account, key, credit and invoice records: while the account is open and six years after, because an Irish company keeps its books that long.

B.6 Requests from people whose data is in the service

The account data we control is contact data for your employees acting for you. If one of them writes to us, we answer directly: access, correction, deletion and objection, within thirty days. Personal data inside a run, such as a name in an incident thread or an author on a diff, is data you control and we process. A request about it goes to you, and we help within the seven days we hold a copy. After that we have nothing left to act on.

For everyone

4. Moving data between countries

Pintle Ltd is a company in Ireland, inside the EEA. Section B.4 says where the data in the service is kept. If any personal data we control ever has to leave the EEA, for example because a supplier named on our subprocessor list handles it elsewhere, it is protected by the European Commission’s Standard Contractual Clauses or another safeguard the GDPR accepts. You can ask us for a copy.

5. Security

We protect data in line with the risk. That includes encryption in transit and at rest, access limited to the people and systems that need it, each customer’s data kept separate from every other’s, and a log of every access to production systems.

If a personal data breach affects you, we tell you without undue delay, and at the latest within 36 hours of finding out, with the information you need to meet your own reporting duties.

6. Children

The service is sold to businesses and is not meant for children. We don’t knowingly collect personal data from anyone under 16.

7. Changes to this policy

We may update this policy. If a change matters, we email customers at least 30 days before it takes effect. The version number and date at the top of this page change every time.

8. Contact

Privacy questions and anything else: [email protected]
By post: Pintle Ltd, 22 Lower Baggot Street, Dublin 2, D02 Y243, Ireland

← Back

Your request has been received.

Expect a message from Pintle. It goes to the address you gave.