Back to HomeEffective Date: June 9, 2025 | Last Updated: August 13, 2026
Privacy-First & Local-AI Architecture

WhoseDev Privacy Policy

At AnotiAI, privacy is fundamental to our software engineering principles. This Privacy Policy details the exact operational mechanics of how WhoseDev (a platform developed and managed by AnotiAI) collects, handles, isolates, and protects your information. Whether utilizing local on-device models via Ollama or connecting to cloud infrastructure, your source code, environment context, and prompts remain private and secure under your direct control.

💡 Core Privacy Guarantees

  • Zero Model Training on Your Private Source Code
  • 100% Local AI Execution Support (Ollama On-Device Isolation)
  • Real-Time Client-Side Secret & PII Redaction
  • Complete Ownership & Self-Service 90-Day Purge Lifecycle

This Privacy Policy forms a legally binding part of the WhoseDev Terms of Service. By creating an account, launching the desktop application, integrating plugins, or interacting with our web mirror, you confirm that you have read, understood, and agreed to the data practices outlined below.

1. Who We Are & Data Controller

WhoseDev is an advanced AI assisted development platform engineered, owned, and operated by AnotiAI. AnotiAI serves as the primary Data Controller for account details, subscription information, and technical diagnostics processed across the WhoseDev platform.

  • Legal Registration & Entity Location: AnotiAI is legally registered and headquartered in Dubai, United Arab Emirates (UAE).
  • Data Protection Office Contact: For inquiries regarding data processing, supervisory inquiries, or privacy compliance, contact our team directly at ask@anotiai.com.

2. Detailed Data Collection Categories

To operate an intelligent development environment, we collect specific categories of data necessary for authentication, service delivery, performance optimization, and subscription management.

a. Account Information & Authentication Infrastructure

  • Primary Account Credentials: User email address, registered username, and linked workspace/organization identifiers.
  • Authentication Tokens & Session Management: Identity verification, OAuth single sign-on tokens (e.g., GitHub, Google SSO), and session keys are secured using Firebase Authentication and cached for fast session validation using high performance Redis clusters.
  • Security Integrity: Your raw passwords are never saved in plain text. Authentication keys are encrypted in transit and at rest and are strictly isolated from AI execution layers.

b. Local Editor Preferences & Workspace Metadata

  • Environment Settings: Configuration files, editor theme preferences, font formatting, extension setups, and hotkey bindings are stored locally on your machine or optionally synced to your account.
  • Metadata Isolation: System telemetry captures non-sensitive metadata (such as project programming language tags, file extension counts, and framework types) to optimize model prompting. Actual source code file contents are never collected or stored centrally unless cloud backup or cloud completion features are manually invoked.

c. AI Prompts, Context & Model Inputs

  • Transient Memory Handshake: When invoking cloud based AI completions, the designated prompt snippet, active code selection, and relevant context files are sent to the target LLM API over encrypted TLS channels.
  • Zero Cloud Logging: Context transmitted for cloud completions is processed transiently in server memory to construct the completion stream and is purged immediately following completion generation.
  • Local On-Device Isolation: Prompts dispatched to local models (e.g., Ollama) remain 100% on your local hardware and never leave your machine network interface.

d. Payment, Billing & Payment Processing

  • Stripe Integration: All subscription processing, payment collection, invoicing, and card management are executed directly through Stripe. AnotiAI never holds, processes, or stores raw credit card numbers or banking security codes on our servers.
  • Billing Records: AnotiAI retains high level subscription transaction details (such as renewal dates, active plan tiers, payment status, and billing email addresses) for financial accounting and tax requirements.

e. Telemetry, Diagnostics & Performance Metrics

  • System Diagnostics: Application crash logs, performance latency benchmarks, memory utilization stats, and operating system build numbers.
  • IP Anonymization: User IP addresses are truncated or anonymized at the gateway level before being recorded in operational analytics, preventing tracking to specific physical addresses.

3. AI Processing Architecture (Local Ollama vs. Cloud LLMs)

WhoseDev features a multi-model architecture that grants developers granular control over where and how their code is processed:

Mode A: Local On-Device AI Execution (Ollama Integration)

When you select a local model execution provider (such as Ollama or local Llama / Mistral instances), WhoseDev communicates directly with localhost ports on your local computing hardware. In this mode:

  • 0% of your source code, project files, or prompt text is transmitted over the internet.
  • No telemetry or prompt monitoring is performed by AnotiAI or third party cloud infrastructure.
  • Execution continues uninterrupted even when completely disconnected from the internet.

Mode B: Integrated Cloud LLM Providers

When you opt to route requests through state-of-the-art cloud providers (such as OpenAI, Anthropic, Google Gemini, or DeepSeek), the following privacy safeguards are enforced:

  • Client-Side PII & Secret Masking: Prior to transmission, WhoseDev scans prompts and context blocks to automatically redact hardcoded secrets, API tokens, passwords, private keys, and identifiable email addresses.
  • Strict No-Training Commitments: We maintain enterprise agreements with third-party model providers ensuring that prompts, context blocks, and generated outputs routed through WhoseDev are never used to train base AI models.
  • Transient In-Memory Streams: Cloud providers process prompts transiently in memory to generate real-time token streams, after which data blocks are immediately dropped.

4. How We Use Information & Communications

We utilize collected non sensitive information strictly for legitimate operational purposes:

  • Core Platform Operations: Providing code completion, context indexing, extension management, and workspace synchronization.
  • Account Administration & Billing: Processing recurring subscriptions, issuing tax invoices through Stripe, and notifying users of renewal milestones.
  • Service Communications & Security Alerts: Sending essential administrative notifications, critical bug alerts, patch notes, and security advisories.
  • Opt-In Marketing & Newsletters: If you elect to subscribe to our newsletter or feature announcements, we send periodic update emails. You can exercise your right to opt out at any time by clicking the "Unsubscribe" link in any email header or contacting ask@anotiai.com. We enforce zero tolerance for unsolicited spam.

5. Compliance Roadmap & User Acknowledgment (GDPR, CCPA, HIPAA, SOC 2)

We are actively implementing formal technical and operational frameworks to satisfy global regulatory standards. Please note the active development status across key compliance frameworks:

EU GDPR Compliance

In Progress / Coming Soon

Formal GDPR Data Protection Impact Assessments (DPIA) and formal EU representative designations are in active development.

SOC 2 Type II Alignment

In Progress / Coming Soon

Internal security controls and continuous monitoring systems are operating while third-party audit readiness is ongoing.

Health Data & HIPAA Framework

In Progress / Coming Soon

WhoseDev is not currently certified for processing Protected Health Information (PHI). Business Associate Agreements (BAAs) are coming soon.

California Consumer Privacy (CCPA/CPRA)

In Progress / Coming Soon

Automated consumer request portals and CPRA privacy toggles are currently undergoing final rollout.

Explicit User Acknowledgment & Voluntary Waiver: By establishing an account or utilizing WhoseDev, you acknowledge and agree that formal compliance certifications (including GDPR, HIPAA, SOC 2, and CCPA) are currently In Progress / Coming Soon and are not yet fully active or certified. You voluntarily consent to use WhoseDev with full awareness of this current compliance roadmap status.

6. Third-Party Integrations & Service Providers

We do not sell, rent, or trade user data to advertisers or data brokers. Third-party data sharing is restricted strictly to necessary sub-processors required to deliver platform functionality:

  • Authentication & Infrastructure: Firebase (Google Cloud Infrastructure) for authentication identity and Redis for caching active user session tokens.
  • Payment Processing: Stripe for PCI-DSS compliant subscription billing and payment processing.
  • Selected Cloud LLM APIs: OpenAI, Anthropic, Google Gemini, and DeepSeek for routing user initiated cloud prompts.

7. Data Ownership, Retention Lifecycle & Deletion

  • 100% IP Ownership: You retain exclusive, unencumbered ownership of all original source code, prompts, project files, and generated AI responses.
  • Self-Service Account Deletion: You can initiate full account termination directly within WhoseDev account settings or by submitting a written request to ask@anotiai.com.
  • 90-Day Purge Lifecycle: Upon confirming account deletion, all personal credentials, synced project settings, and session records are immediately deactivated. Complete purging from encrypted cold storage backups takes place within 90 days.

8. Technical & Organizational Security Measures

We employ comprehensive defense-in-depth measures to safeguard user data:

  • Encryption Standards: All transit data utilizes TLS 1.3 transport security. Data stored at rest is encrypted using AES-256 standards.
  • Zero Exposure Local Execution: Ollama local workflows run completely isolated on local loopback adapters, guaranteeing zero internet network exposure.
  • Automated Secret Masking: Continuous client-side regex engines detect and scrub environment keys before remote transmission.

9. User Rights & Data Protection Controls

Regardless of your physical location, AnotiAI provides tools to inspect, export, correct, or delete your platform records. You can exercise these privacy rights by emailing ask@anotiai.com.

10. Cookies, Storage & Local Analytics

WhoseDev uses essential local storage keys and secure browser session tokens strictly for authentication and preference retention. We do not place third-party advertising cookies, cross-site trackers, or behavioral profiling scripts on your devices.

11. Detailed Age Eligibility & Children's Privacy (COPPA & GDPR)

Protecting the online privacy of children and young developers is paramount. WhoseDev enforces strict age limits and user eligibility standards across all platforms and services:

a. General Age Minimum (13 Years Old)

WhoseDev is strictly intended for individuals who are at least 13 years of age (or the minimum legal age of digital consent in their jurisdiction). We do not knowingly market to, collect, or solicit personal information from children under 13 in compliance with the Children's Online Privacy Protection Act (COPPA) in the United States and global privacy standards.

b. International Regulations & Digital Age of Consent (13-16 Years Old)

Under Article 8 of the EU GDPR and UK GDPR, the legal age of digital consent varies between 13 and 16 depending on the specific member state or country (e.g., 16 in Germany, 13 in the UK). If a user is above 13 but under the legal age of digital consent in their country, they may only use WhoseDev under the direct supervision and express consent of a parent or legal guardian who accepts these Terms and Privacy Policy on their behalf.

c. Mandatory Account Purge for Underage Discovery

If AnotiAI discovers or is alerted by a parent or guardian that an account was registered by a child under 13 (or under the applicable legal age of digital consent without authorized parental consent), we will take immediate operational steps to:

  • Immediately terminate and disable the corresponding user account.
  • Permanently delete all stored personal credentials, authentication keys, and workspace metadata from active databases within 24 hours.
  • Ensure no collected details are transferred to third party processors or stored long term.

d. Parent & Guardian Parental Inquiry Contact

If you are a parent or legal guardian and believe your child under the age of 13 has provided personal details to WhoseDev, please contact our Privacy Officer immediately at ask@anotiai.com with the subject line "Underage Account Review" for swift account termination and data purge.

e. Educational Institutions & Coding Programs

When WhoseDev is deployed in schools, coding bootcamps, or educational programs involving students under 16, the educational institution assumes responsibility for obtaining appropriate parental consents and providing institutional authorization prior to account provision.

12. Governing Law, Jurisdiction & Dispute Resolution

This Privacy Policy, along with all associated data handling practices, shall be governed by and interpreted under the laws of Dubai, United Arab Emirates (UAE). Any legal proceedings arising from this policy shall fall under the jurisdiction of the competent courts of Dubai, UAE.

13. Revisions & Policy Updates

We reserve the right to revise this Privacy Policy as our features evolve or compliance obligations change. Material revisions will be communicated via email notifications or prominent update banners within WhoseDev. Continued use following update publication constitutes acceptance of the modified policy.

14. Contact Information & Privacy Office

For questions, privacy requests, or supervisory inquiries, contact our dedicated team at:

Entity: AnotiAI (WhoseDev Privacy Division)

Email Direct: ask@anotiai.com

Jurisdiction: Dubai, United Arab Emirates (UAE)

15. Offline Execution & Local Isolation Guarantees

  • Core code editor features, local terminal commands, and Ollama model connections run completely offline without an active internet connection.
  • When operating in offline or local mode, zero telemetry packets, prompts, or sensitive keys exit your local device.
Talk to WhoseDev