Last updated August 6, 2026
This Privacy Policy explains how MANTEON PTE. LTD. ("Company," "we," "us," "our") collects, uses, discloses, and protects personal data when you visit sourceindex.dev, request access to, or use SourceIndex (the "Services").
We are registered in Singapore at 160 Robinson Road, #14-04 Singapore Business Federation Center, Singapore 068914.
This Privacy Policy is incorporated into our Terms of Service. If you want to know how your source code is handled specifically, see Section 3 of this policy and Sections 3, 4, and 5 of the Terms of Service.
If you do not agree with this Privacy Policy, please do not use the Services.
The short version, in plain terms:
This summary is not a substitute for the full policy below.
| Data | When | Why |
|---|---|---|
| Email address | Access request; support; correspondence | To issue an access key and communicate with you |
| Name, company or organisation (if provided) | Access request | To evaluate and prioritise beta requests |
| Project type, coding agent used, approximate repository size | Access request | To assess fit for the private beta and plan capacity |
| Content of your emails and support messages | When you contact us | To respond and resolve issues |
| Feedback, bug reports, and survey responses | If you choose to provide them | To improve the Services |
| Data | Description |
|---|---|
| Access key identifier | The identifier of the key used for a request (not the key itself in plain form) |
| Operational metadata | Request timestamps, request counts, token counts, inference cost, repository size, and language distribution |
| Diagnostic data | Where a request fails: error codes, stack traces, and limited technical context, which may incidentally include file paths |
| Technical data | IP address, user agent, client version, and similar information sent automatically when your client or browser connects to us |
Operational metadata does not include the content of your source code.
When you visit sourceindex.dev we may collect IP address, browser and device information, referring URL, pages viewed, and similar information. See Section 11.
We do not knowingly collect special categories of personal data (such as health, biometric, or political data), payment card details (the Services are currently free), or government identifiers.
Source code is not usually personal data, but it may contain personal data — for example, author names in comments, email addresses in configuration files, or personal data embedded in test fixtures. This section explains how source code is handled. It mirrors, and is subject to, Sections 3, 4, and 5 of the Terms of Service.
(a) We do not store it. Source code you submit ("Customer Code") is not written to any persistent storage system under our control. It exists on our infrastructure only transiently in memory for the duration of a request, and is discarded once the response is returned.
(b) We do not train on it, and no one here reads it. We do not use Customer Code to train, fine-tune, or evaluate any model. No SourceIndex personnel reads or reviews Customer Code in the ordinary course of providing the Services. We do not sell, license, or publish it.
(c) It is processed by third-party cloud providers. To generate results, we transmit Customer Code to model-inference services operated by Amazon Web Services and Microsoft. Those providers state that they do not use customer prompts or responses to train their models. However, a provider may retain prompt and response content for a limited period for abuse-monitoring, safety, and service-reliability purposes under its own published policies, which may include limited review by authorised personnel of that provider. Those policies are set by the provider, may change without notice to us, and are outside our control. We make no representation or warranty regarding the data handling practices of any third-party provider. If this matters to you, review their published policies before submitting code.
(d) The index stays on your machine. The index generated for your repository, including the .sourceindex/ directory, is written to and stored on your own device. We do not host, mirror, or retain a copy. Deleting that directory deletes the index; no request to us is needed.
(e) We do not filter secrets. The Services do not detect, redact, or filter credentials, API keys, tokens, certificates, or personal data present in the files you index. You are responsible for excluding such material. If you believe secrets or personal data were submitted in error, contact us at [email protected] — but note that, because we do not retain code, there is generally nothing on our side to delete, and any deletion request for retained provider-side data would need to be directed to that provider.
(f) You are responsible for your basis to submit. Where Customer Code contains personal data, you act as the controller of that data and we act as your processor. You are responsible for having a lawful basis for submitting it and for giving any notices required to the individuals concerned. If you require a data processing agreement, contact us.
We use personal data to:
We do not use your personal data or your source code to train any machine learning model.
We do not use personal data for automated decision-making producing legal or similarly significant effects.
If you are in the EEA or UK, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Services under our Terms of Service | Performance of a contract (Art. 6(1)(b)) |
| Evaluating access requests | Performance of a contract / steps prior to entering a contract (Art. 6(1)(b)) |
| Quota enforcement, cost accounting, abuse prevention, security | Legitimate interests (Art. 6(1)(f)) — operating a sustainable and secure service |
| Diagnostics and product improvement | Legitimate interests (Art. 6(1)(f)) |
| Service communications | Performance of a contract / legitimate interests |
| Marketing communications, non-essential cookies | Consent (Art. 6(1)(a)), where required |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object at any time — see Section 10.
We do not sell personal data. We share it only as follows.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Amazon Web Services | Cloud hosting and model inference | Customer Code (transient), technical data |
| Microsoft | Model inference | Customer Code (transient) |
| Cloudflare | Website and API delivery, DNS, security, serverless hosting, and storage of access requests | Technical data, IP address, access request details |
| Google (Google Workspace and Google Sheets) | Access request intake, record-keeping, and email | Email address, access request details, correspondence |
| Resend | Transactional email notifications | Email address, access request details |
We maintain a current list of sub-processors and will update this policy before adding or replacing one.
We are based in Singapore. Our website and API gateway run on Cloudflare's global edge network, and our sub-processors operate principally in the United States; AWS model inference uses cross-region routing and may process requests in AWS regions outside the United States. Where personal data is transferred out of the EEA, the UK, or Singapore, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and contractual commitments requiring recipients to provide a standard of protection comparable to that required under the Singapore Personal Data Protection Act 2012.
You may request a copy of the relevant safeguards by contacting us.
| Data | Retention |
|---|---|
| Customer Code | Not retained by us. Transient in memory only. Provider-side retention is described in Section 3(c) |
| Local index | Held only on your device; we never receive a copy |
| Access request details | For the duration of the beta programme and up to 12 months after, unless you ask us to delete them sooner |
| Access key and associated account records | For as long as your key is active, and up to 12 months after revocation |
| Operational metadata | Up to 24 months, for capacity planning and cost analysis |
| Diagnostic data | Up to 7 days |
| Support and email correspondence | Up to 24 months |
| Website analytics | Up to 14 months |
We may retain data for longer where required by law or where reasonably necessary to establish, exercise, or defend legal claims.
We use technical and organisational measures appropriate to the nature of the data, including encryption in transit (TLS), access controls and least-privilege access to production systems, and a design in which source code is never written to persistent storage under our control.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you transmit data to us at your own risk. If we become aware of a personal data breach affecting you, we will notify you and any relevant regulator as required by applicable law.
Depending on where you live, you may have the right to:
To exercise any of these, email [email protected]. We will respond within the period required by applicable law (generally 30 days). We may need to verify your identity before acting.
Note on source code: because we do not retain Customer Code, a deletion request will generally have nothing to act on with respect to your code. Your index is on your own machine and you can delete it yourself at any time by removing the .sourceindex/ directory.
We use only cookies strictly necessary to deliver and secure the website. We do not use analytics, advertising, or cross-site tracking cookies. You can block cookies in your browser, though parts of the site may not function.
The SourceIndex command-line client does not use cookies.
The Services are not directed to children and are intended for users aged 18 and over, or the age of majority in your jurisdiction. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
We comply with the Singapore Personal Data Protection Act 2012 ("PDPA"). We collect, use, and disclose personal data only for the purposes set out in this policy, or as permitted or required by law. You may withdraw consent to our collection, use, or disclosure of your personal data at any time by contacting our Data Protection Officer, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent may mean we can no longer provide the Services to you.
Data Protection Officer
Email: [email protected]
MANTEON PTE. LTD., 160 Robinson Road, #14-04 Singapore Business Federation Center, Singapore 068914
You may lodge a complaint with the Personal Data Protection Commission of Singapore at www.pdpc.gov.sg.
Controller. For personal data described in Section 2, MANTEON PTE. LTD. is the controller.
Processor. Where Customer Code contains personal data, you are the controller and we act as processor on your instructions. See Section 3(f). A data processing agreement is available on request at [email protected].
Supervisory authority. You have the right to lodge a complaint with your local data protection authority.
We do not sell personal information and we do not share personal information for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act as amended.
If you are a resident of California, Colorado, Connecticut, Virginia, or another state with comparable legislation, you may have rights to know, access, correct, delete, and appeal, and to be free from discrimination for exercising those rights. To exercise them, email [email protected].
Under California's "Shine the Light" law, California residents may request information about disclosures of personal information to third parties for direct marketing purposes. We do not make such disclosures.
We may update this Privacy Policy from time to time. The updated version will be indicated by a revised "Last updated" date and takes effect on posting. Where changes are material — for example, adding a new category of sub-processor that processes source code — we will give notice by email to the address associated with your access key before the change takes effect.
For any question about this policy, or to exercise your rights:
MANTEON PTE. LTD.
160 Robinson Road, #14-04 Singapore Business Federation Center
Singapore 068914
Singapore
Data Protection Officer / General enquiries: [email protected]