This Privacy Policy forms a legally binding part of the WhoseDev Terms of Service. By creating an account, launching the desktop application, integrating plugins, or interacting with our web mirror, you confirm that you have read, understood, and agreed to the data practices outlined below.
1. Who We Are & Data Controller
WhoseDev is an advanced AI assisted development platform engineered, owned, and operated by AnotiAI. AnotiAI serves as the primary Data Controller for account details, subscription information, and technical diagnostics processed across the WhoseDev platform.
- Legal Registration & Entity Location: AnotiAI is legally registered and headquartered in Dubai, United Arab Emirates (UAE).
- Data Protection Office Contact: For inquiries regarding data processing, supervisory inquiries, or privacy compliance, contact our team directly at ask@anotiai.com.
2. Detailed Data Collection Categories
To operate an intelligent development environment, we collect specific categories of data necessary for authentication, service delivery, performance optimization, and subscription management.
a. Account Information & Authentication Infrastructure
- Primary Account Credentials: User email address, registered username, and linked workspace/organization identifiers.
- Authentication Tokens & Session Management: Identity verification, OAuth single sign-on tokens (e.g., GitHub, Google SSO), and session keys are secured using Firebase Authentication and cached for fast session validation using high performance Redis clusters.
- Security Integrity: Your raw passwords are never saved in plain text. Authentication keys are encrypted in transit and at rest and are strictly isolated from AI execution layers.
b. Local Editor Preferences & Workspace Metadata
- Environment Settings: Configuration files, editor theme preferences, font formatting, extension setups, and hotkey bindings are stored locally on your machine or optionally synced to your account.
- Metadata Isolation: System telemetry captures non-sensitive metadata (such as project programming language tags, file extension counts, and framework types) to optimize model prompting. Actual source code file contents are never collected or stored centrally unless cloud backup or cloud completion features are manually invoked.
c. AI Prompts, Context & Model Inputs
- Transient Memory Handshake: When invoking cloud based AI completions, the designated prompt snippet, active code selection, and relevant context files are sent to the target LLM API over encrypted TLS channels.
- Zero Cloud Logging: Context transmitted for cloud completions is processed transiently in server memory to construct the completion stream and is purged immediately following completion generation.
- Local On-Device Isolation: Prompts dispatched to local models (e.g., Ollama) remain 100% on your local hardware and never leave your machine network interface.
d. Payment, Billing & Payment Processing
- Stripe Integration: All subscription processing, payment collection, invoicing, and card management are executed directly through Stripe. AnotiAI never holds, processes, or stores raw credit card numbers or banking security codes on our servers.
- Billing Records: AnotiAI retains high level subscription transaction details (such as renewal dates, active plan tiers, payment status, and billing email addresses) for financial accounting and tax requirements.
e. Telemetry, Diagnostics & Performance Metrics
- System Diagnostics: Application crash logs, performance latency benchmarks, memory utilization stats, and operating system build numbers.
- IP Anonymization: User IP addresses are truncated or anonymized at the gateway level before being recorded in operational analytics, preventing tracking to specific physical addresses.
3. AI Processing Architecture (Local Ollama vs. Cloud LLMs)
WhoseDev features a multi-model architecture that grants developers granular control over where and how their code is processed:
Mode A: Local On-Device AI Execution (Ollama Integration)
When you select a local model execution provider (such as Ollama or local Llama / Mistral instances), WhoseDev communicates directly with localhost ports on your local computing hardware. In this mode:
- 0% of your source code, project files, or prompt text is transmitted over the internet.
- No telemetry or prompt monitoring is performed by AnotiAI or third party cloud infrastructure.
- Execution continues uninterrupted even when completely disconnected from the internet.
Mode B: Integrated Cloud LLM Providers
When you opt to route requests through state-of-the-art cloud providers (such as OpenAI, Anthropic, Google Gemini, or DeepSeek), the following privacy safeguards are enforced:
- Client-Side PII & Secret Masking: Prior to transmission, WhoseDev scans prompts and context blocks to automatically redact hardcoded secrets, API tokens, passwords, private keys, and identifiable email addresses.
- Strict No-Training Commitments: We maintain enterprise agreements with third-party model providers ensuring that prompts, context blocks, and generated outputs routed through WhoseDev are never used to train base AI models.
- Transient In-Memory Streams: Cloud providers process prompts transiently in memory to generate real-time token streams, after which data blocks are immediately dropped.
4. How We Use Information & Communications
We utilize collected non sensitive information strictly for legitimate operational purposes:
- Core Platform Operations: Providing code completion, context indexing, extension management, and workspace synchronization.
- Account Administration & Billing: Processing recurring subscriptions, issuing tax invoices through Stripe, and notifying users of renewal milestones.
- Service Communications & Security Alerts: Sending essential administrative notifications, critical bug alerts, patch notes, and security advisories.
- Opt-In Marketing & Newsletters: If you elect to subscribe to our newsletter or feature announcements, we send periodic update emails. You can exercise your right to opt out at any time by clicking the "Unsubscribe" link in any email header or contacting ask@anotiai.com. We enforce zero tolerance for unsolicited spam.
5. Compliance Roadmap & User Acknowledgment (GDPR, CCPA, HIPAA, SOC 2)
We are actively implementing formal technical and operational frameworks to satisfy global regulatory standards. Please note the active development status across key compliance frameworks:
EU GDPR Compliance
In Progress / Coming SoonFormal GDPR Data Protection Impact Assessments (DPIA) and formal EU representative designations are in active development.
SOC 2 Type II Alignment
In Progress / Coming SoonInternal security controls and continuous monitoring systems are operating while third-party audit readiness is ongoing.
Health Data & HIPAA Framework
In Progress / Coming SoonWhoseDev is not currently certified for processing Protected Health Information (PHI). Business Associate Agreements (BAAs) are coming soon.
California Consumer Privacy (CCPA/CPRA)
In Progress / Coming SoonAutomated consumer request portals and CPRA privacy toggles are currently undergoing final rollout.
7. Data Ownership, Retention Lifecycle & Deletion
- 100% IP Ownership: You retain exclusive, unencumbered ownership of all original source code, prompts, project files, and generated AI responses.
- Self-Service Account Deletion: You can initiate full account termination directly within WhoseDev account settings or by submitting a written request to ask@anotiai.com.
- 90-Day Purge Lifecycle: Upon confirming account deletion, all personal credentials, synced project settings, and session records are immediately deactivated. Complete purging from encrypted cold storage backups takes place within 90 days.
8. Technical & Organizational Security Measures
We employ comprehensive defense-in-depth measures to safeguard user data:
- Encryption Standards: All transit data utilizes TLS 1.3 transport security. Data stored at rest is encrypted using AES-256 standards.
- Zero Exposure Local Execution: Ollama local workflows run completely isolated on local loopback adapters, guaranteeing zero internet network exposure.
- Automated Secret Masking: Continuous client-side regex engines detect and scrub environment keys before remote transmission.
9. User Rights & Data Protection Controls
Regardless of your physical location, AnotiAI provides tools to inspect, export, correct, or delete your platform records. You can exercise these privacy rights by emailing ask@anotiai.com.
11. Detailed Age Eligibility & Children's Privacy (COPPA & GDPR)
Protecting the online privacy of children and young developers is paramount. WhoseDev enforces strict age limits and user eligibility standards across all platforms and services:
a. General Age Minimum (13 Years Old)
WhoseDev is strictly intended for individuals who are at least 13 years of age (or the minimum legal age of digital consent in their jurisdiction). We do not knowingly market to, collect, or solicit personal information from children under 13 in compliance with the Children's Online Privacy Protection Act (COPPA) in the United States and global privacy standards.
b. International Regulations & Digital Age of Consent (13-16 Years Old)
Under Article 8 of the EU GDPR and UK GDPR, the legal age of digital consent varies between 13 and 16 depending on the specific member state or country (e.g., 16 in Germany, 13 in the UK). If a user is above 13 but under the legal age of digital consent in their country, they may only use WhoseDev under the direct supervision and express consent of a parent or legal guardian who accepts these Terms and Privacy Policy on their behalf.
c. Mandatory Account Purge for Underage Discovery
If AnotiAI discovers or is alerted by a parent or guardian that an account was registered by a child under 13 (or under the applicable legal age of digital consent without authorized parental consent), we will take immediate operational steps to:
- Immediately terminate and disable the corresponding user account.
- Permanently delete all stored personal credentials, authentication keys, and workspace metadata from active databases within 24 hours.
- Ensure no collected details are transferred to third party processors or stored long term.
d. Parent & Guardian Parental Inquiry Contact
If you are a parent or legal guardian and believe your child under the age of 13 has provided personal details to WhoseDev, please contact our Privacy Officer immediately at ask@anotiai.com with the subject line "Underage Account Review" for swift account termination and data purge.
e. Educational Institutions & Coding Programs
When WhoseDev is deployed in schools, coding bootcamps, or educational programs involving students under 16, the educational institution assumes responsibility for obtaining appropriate parental consents and providing institutional authorization prior to account provision.
12. Governing Law, Jurisdiction & Dispute Resolution
This Privacy Policy, along with all associated data handling practices, shall be governed by and interpreted under the laws of Dubai, United Arab Emirates (UAE). Any legal proceedings arising from this policy shall fall under the jurisdiction of the competent courts of Dubai, UAE.
13. Revisions & Policy Updates
We reserve the right to revise this Privacy Policy as our features evolve or compliance obligations change. Material revisions will be communicated via email notifications or prominent update banners within WhoseDev. Continued use following update publication constitutes acceptance of the modified policy.
14. Contact Information & Privacy Office
For questions, privacy requests, or supervisory inquiries, contact our dedicated team at:
Entity: AnotiAI (WhoseDev Privacy Division)
Email Direct: ask@anotiai.com
Jurisdiction: Dubai, United Arab Emirates (UAE)
15. Offline Execution & Local Isolation Guarantees
- Core code editor features, local terminal commands, and Ollama model connections run completely offline without an active internet connection.
- When operating in offline or local mode, zero telemetry packets, prompts, or sensitive keys exit your local device.