01 Who we are and what this covers
attribut.ai is operated by Alta Labs LLC ("Alta Labs," "attribut," "we," "us," or "our"), a limited liability company organized in South Dakota, USA. This Privacy Policy explains what information we handle, why we handle it, who we share it with, and the rights you have over it.
attribut.ai is a business product. Most people who use it do so as part of an organization — their employer or team — that has signed up for the service. Throughout this policy we call that organization the Customer, and the individuals who use the product on the Customer's behalf Authorized Users. For much of the data that flows through attribut.ai, the Customer decides what is collected and why; we process it on their instructions. We explain where that distinction matters as we go.
We've tried to write this the way one adult talks to another — clearly, without burying the important parts in legalese. Where the law requires specific language, we include it, but we'd rather you actually understand this than be impressed by it.
This policy applies to information we handle through:
- the attribut.ai website and marketing pages;
- your account and dashboard;
- the connectors and integrations you authorize (such as Anthropic, GitHub, and OpenTelemetry); and
- our communications with you.
02 Our metadata-only commitment
This is the most important thing to understand about attribut.ai, so we're putting it first.
We record metadata, not content. attribut.ai analyzes metadata about how AI coding agents and developer tools are used — things like usage events, session and device state, token counts, model and tool identifiers, and timestamps. We do not collect, store, or have access to the content of your prompts, your conversations with AI models, or the responses those models generate. Our connectors are built to ingest signals about how tools are used — never what was written, asked, or generated.
In plain terms: we can tell that a coding session happened, roughly how large it was, which tools were involved, and when — but we cannot read the code you wrote, the questions you asked, or the answers you received, because we never receive them in the first place. This is a deliberate design choice, not a setting you have to find and switch on.
If we ever change this — if a future feature would require collecting content — we would tell you clearly and ask for the permission the law requires before doing so.
03 Information we collect
We collect the following categories of information.
Account and contact information. When an Authorized User signs up or is invited, we collect information needed to create and secure the account — typically name, work email address, organization, and authentication identifiers. Authentication is handled through our identity provider; we receive the profile and session information needed to log you in and keep you logged in safely.
Connector and telemetry metadata. When a Customer connects a data source, we ingest metadata about AI-tool and developer-tool usage. This includes usage events, session and device state, token counts, model and tool identifiers, repository and organization identifiers (where applicable), and timestamps. As described in Section 2, this is metadata only — it does not include prompt or response content.
Website and product usage data. Like most online services, we automatically collect technical information when you visit our site or use the dashboard — IP address, browser and device type, pages viewed, referring pages, and similar log data — through cookies and similar technologies (see Section 8).
Communications. If you email us, request support, or sign up for updates, we keep the content of those messages and our replies so we can help you and maintain a record.
04 How we collect information
We collect information in three ways:
- Directly from you — when you create an account, configure the product, contact us, or sign up for communications.
- Through connectors and integrations you authorize — when a Customer connects a source such as Anthropic, GitHub, or OpenTelemetry, that source sends us the usage metadata described above. Connecting a source is an explicit, authorized action — for example, installing our GitHub App or providing the credentials a connector needs. You can disconnect a source at any time, which stops further ingestion from it.
- Automatically — through cookies, server logs, and similar technologies when you use our website and dashboard.
05 How we use information
We use the information we collect to:
- provide and operate the service — authenticate users, run connectors, process telemetry, and show you analytics in your dashboard;
- secure the service — detect, prevent, and investigate fraud, abuse, and security incidents;
- support you — respond to questions and troubleshoot problems;
- improve the service — understand how the product is used so we can make it better and build new features;
- communicate with you — send service notices, security alerts, and (where you've opted in) product updates;
- handle billing — if and when paid plans apply (see our Terms of Service); and
- create aggregated and de-identified data — as described in Section 10, including for our Economic Lab.
We do not use prompt or response content for any of these purposes, because we don't have it.
06 Legal bases for processing (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or another region with similar laws, we process your personal data on the following legal bases:
- Performance of a contract — to provide the service to the Customer and its Authorized Users.
- Legitimate interests — to secure and improve the service, and to create and use aggregated and de-identified data (Section 10). Where we rely on legitimate interests, we've weighed them against your rights and believe our use is consistent with your reasonable expectations; you can object (see Section 13).
- Consent — for non-essential cookies and optional marketing communications. You can withdraw consent at any time.
- Legal obligation — to comply with applicable law.
For much of the connector metadata, the Customer is the controller and Alta Labs is the processor; in that arrangement, the Customer is responsible for establishing the legal basis for the processing they instruct us to perform.
09 Data retention
We keep personal data only as long as we need it for the purposes described in this policy, then delete it or anonymize it.
- Account data is kept for as long as the account is active, and for a reasonable period afterward to meet legal, security, and record-keeping needs.
- Connector and telemetry metadata is retained according to the Customer's configuration and our data-warehouse lifecycle, after which it is deleted or aggregated/anonymized.
- Aggregated and de-identified data (Section 10) is not personal data and may be retained indefinitely.
When a Customer's relationship with us ends, we delete or de-identify their personal data within a reasonable period, subject to any legal retention obligations and to the survival of aggregated and de-identified data.
10 Aggregated and de-identified data (the Economic Lab)
We create aggregated, de-identified, and anonymized data from the information processed through attribut.ai, and we use it to understand and write about how AI is changing software development. We call this work our Economic Lab. It's modeled on how companies like Ramp use aggregated, anonymized customer data to publish economic insights.
Here is exactly what that means and, just as importantly, what it does not:
- The data we use for this is always aggregated or de-identified — combined and stripped of identifiers so that it does not identify you, any Authorized User, or any Customer.
- We commit to maintaining this data in de-identified or aggregated form, and we will not attempt to re-identify it, except as permitted by law to test that our de-identification actually works.
- Any benchmarks, statistics, trends, or insights we publish reflect aggregated patterns only. They are never tied back to an individual, an Authorized User, or a Customer.
- Because of this, aggregated and de-identified data is not personal information under laws like the CCPA/CPRA, and is outside the scope of the GDPR.
We use this data to operate, secure, evaluate, and improve attribut.ai; to conduct research; to develop new products and features; and to produce and publish industry benchmarks and insights. Our right to create and use aggregated and de-identified data survives the end of any account or contract.
11 Data security
We protect information using technical and organizational measures appropriate to its sensitivity — including encryption in transit and at rest, access controls, and the security features of our cloud infrastructure. Our metadata-only design is itself a security measure: the most sensitive material — your prompts and the model's responses — never reaches us, so it cannot be exposed through us.
No system is perfectly secure, and we can't guarantee absolute security, but we work hard to protect your information and to respond quickly if something goes wrong.
12 International data transfers
We are based in the United States, and we process and store information there and in other countries where our service providers operate. If you are outside the United States, your information will be transferred to and processed in the United States.
Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on an appropriate transfer mechanism — such as the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) — to protect that data.
13 Your privacy rights
Depending on where you live, you have rights over your personal data. We honor these rights for everyone where we reasonably can.
If you are in the EEA, UK, or Switzerland (GDPR), you have the right to access, correct, delete, restrict, or object to our processing of your personal data; to data portability; to withdraw consent; and to lodge a complaint with your local data protection authority.
If you are a California resident (CCPA/CPRA), you have the right to know what personal information we collect and how we use and disclose it; to access and delete it; to correct it; to opt out of any "sale" or "sharing" of it; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.
Because attribut.ai is a business product, much of the data we hold is processed on a Customer's instructions. If your request concerns that data, we may direct you to the Customer, or act on the Customer's instruction to fulfill it. To make a request, contact us at [email protected]. We'll verify your identity before acting, and we won't charge you for a reasonable request.
15 Children's privacy
attribut.ai is a business product intended for use by adults in their professional capacity. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us at [email protected] and we'll delete it.
16 Changes to this policy
We may update this policy from time to time. When we make material changes, we'll update the "last updated" date below and, where appropriate, give you additional notice. Your continued use of attribut.ai after a change takes effect means you accept the updated policy.
17 Contact us
If you have questions about this policy or how we handle your information, reach us here: