Privacy
Reinstate website privacy notice
Reinstate does not receive coding-agent sessions, source code, storage credentials, or encryption passphrases through this website. The site collects an email address only when someone submits the waitlist form, and analytics loads only when the operator explicitly configures it.
Last updated:
What this notice covers
This notice covers visits to reinstate.dev and information submitted through its waitlist. It does not change the local-first data flow of the Reinstate CLI. The CLI encrypts supported session data on the developer's device and sends ciphertext to storage that the developer configures and controls.
Waitlist information
If you join the waitlist, the site processes the email address you provide, a submission timestamp, and the source label web. The information is used to manage early access and send relevant project or release updates. It is not sold.
Depending on the production configuration, waitlist records are stored in a managed libSQL/Turso database or a private GitHub Gist. The site may use Resend to notify the maintainer of a new signup. These services process information under their own terms and privacy practices.
Optional site analytics
No analytics script is emitted unless a Plausible script URL is configured at build time. When enabled, the site can record page views and events from a fixed, reviewed taxonomy: command copies, getting-started entry, integration and storage-guide views, security-document views, repository and release-download clicks, RSS subscriptions, issue-report and contribution links, and successful waitlist submissions.
Plausible's automatic capture of outbound links and file downloads is deliberately left off, because it would transmit destination addresses as event properties. Clicks that leave the site are instead reported through the reviewed taxonomy above, as a controlled event name and a controlled label, without the address.
Event properties contain only a controlled event name, the current path without its query string, a controlled placement label, and—when they can be resolved—a controlled referral channel label and a controlled campaign identifier. Reinstate's event code does not send form values, email addresses, coding-agent content, source code, repository names, bucket names, credentials, passphrases, or link query parameters. The deployed Plausible service can still process ordinary request information according to its configuration and privacy policy.
The referral channel label is chosen from a fixed, reviewed list and describes where a visit came from, not who made it. Two independent lists are used: AI answer engines (ChatGPT, Perplexity, Microsoft Copilot, Google Gemini, and Google AI features) and marketing channels (X, LinkedIn, Dev.to, Hacker News, GitHub, newsletters, and paid placements on X or Meta). A referrer that matches neither list produces no label at all.
The campaign identifier exists so that a marketing test can tell its own variants apart. It is not read through from the address bar: an incoming utm_content value is compared against a fixed allowlist of campaign identifiers held in the site's source code, and only an exact match is recorded. Any other value is discarded and nothing is transmitted. Adding a campaign identifier requires a reviewed change to that list.
Infrastructure logs
Hosting, content-delivery, security, and email providers may create routine operational logs when they serve a request or prevent abuse. Those records can include request time, requested URL, user agent, IP-derived network information, response status, and diagnostic data. They are used for availability, security, and troubleshooting—not to inspect coding-agent work.
Retention and deletion
Waitlist records are kept while they are needed for early-access and project communications, legal obligations, or abuse prevention. Operational-log retention is controlled by the configured providers. You may ask to access, correct, or delete a waitlist record by contacting the maintainer privately at the email address in the project's security policy from the address concerned.
Verify the implementation
The website and CLI are open source. You can inspect thewebsite implementation, review the security overview, and report a vulnerability through the project's security policy.
Changes to this notice
Material changes will update the date above and the public repository history. Analytics or data-processing configuration should not be enabled in production without reviewing this notice for accuracy.