Privacy Policy

Last updated: April 25, 2026

This Privacy Policy explains how Paddi (“we,” “us,” or “our”) collects, uses, stores, and protects your information when you use our platform at about.paddi.app and the Paddi application (collectively, the “Service”). Paddi is an AI PM Agent that helps product managers analyze requirements, prioritize decisions, generate specifications, and coordinate code delivery.

By using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.


Information We Collect

Account Information

When you create an account, we collect your name, email address, and authentication credentials. If you sign up through a third-party service (such as Google or GitHub), we receive basic profile information from that provider as authorized by you.

Content You Provide

In the course of using Paddi, you may input or submit the following types of content:

  • Requirements and feedback: Text descriptions, user feedback, and other product requirements you enter manually or through the conversational interface.
  • Business goals and prioritization settings: Strategic objectives and weighting criteria you configure to guide the Agent’s prioritization logic.
  • Documents and files: Any supplementary materials you upload to provide context for the Agent’s analysis.

Third-Party Integration Data

Paddi connects to external services you authorize to enhance its analysis capabilities. The data accessed through these integrations is processed solely to deliver the Service’s core functionality:

  • GitHub: When you connect a GitHub repository, the Agent accesses your codebase — including source code, file structures, and dependency information — to provide code-aware analysis, assess implementation complexity, and identify edge cases. Access is limited to the repositories you explicitly authorize.
  • Sentry: When you configure a Sentry webhook, Paddi receives issue event data (such as error titles, severity levels, occurrence counts, and affected user counts) to automatically surface production signals as structured requirements.
  • Code Agents (via Claude Managed Agents): When you initiate a code delivery session, your confirmed specification and relevant code context are transmitted to execute code modifications and submit pull requests on your behalf.

We only access integration data within the scope of permissions you grant, and only for the purposes of providing the Service.

Usage Data

We automatically collect technical data when you use the Service, including your IP address, browser type and version, device information, pages visited, timestamps, and interaction patterns. This data helps us maintain, secure, and improve the Service.

Cookies and Similar Technologies

We use cookies and similar technologies for essential functions such as authentication and session management, remembering your preferences, and analyzing usage patterns to improve the Service.

You can configure your browser to refuse cookies, though this may limit certain functionality. We use the following types of cookies:

  • Essential cookies (session): Required for authentication and core functionality.
  • Preference cookies (persistent): Store your settings and preferences.
  • Analytics cookies (persistent): Help us understand how the Service is used so we can improve it.

How We Use Your Information

We use the information we collect to:

  • Provide and operate the Service: Process your requirements, run the Agent’s analysis and prioritization, generate specifications, and coordinate code delivery.
  • Improve the Service: Analyze usage patterns, diagnose technical issues, and develop new features.
  • Communicate with you: Send service-related notifications, respond to your inquiries, and share product updates (which you can opt out of at any time).
  • Ensure security: Detect and prevent fraud, abuse, and unauthorized access.
  • Comply with legal obligations: Meet applicable legal requirements and enforce our terms.

AI Processing

Paddi uses AI models provided by third-party providers to power its core functionality, including requirement analysis, prioritization, specification generation, and code delivery coordination. When the Agent processes your data:

  • Your input content (requirements, feedback, business goals) and authorized integration data (code context, error reports) are sent to AI model providers for processing.
  • We instruct our AI providers not to use your data to train their models.
  • The Agent’s reasoning process — including which data sources it referenced and how it reached its conclusions — is made transparent and traceable to you within the Service.

How We Share Your Information

We do not sell your personal information. We may share your data in the following circumstances:

  • Service providers: We work with third-party providers for hosting, analytics, authentication, AI model inference, and other infrastructure services. These providers process data on our behalf under contractual obligations to protect your information.
  • Third-party integrations you authorize: When you connect GitHub, Sentry, or other services, data flows between Paddi and those platforms as necessary to deliver the functionality you requested. These services are governed by their own privacy policies.
  • Legal requirements: We may disclose your information if required by law, regulation, legal process, or governmental request.
  • Business transfers: In the event of a merger, acquisition, or asset sale, your information may be transferred. We will notify you before your data becomes subject to a different privacy policy.
  • With your consent: We may share your information for other purposes with your explicit consent.

Data Storage and Security

Your data is processed on servers located in Japan. Information may also be processed in other jurisdictions where our service providers operate. We take reasonable technical and organizational measures to protect your data, including encryption in transit and at rest, access controls, and regular security reviews.

No method of transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security.


Data Retention

We retain your personal data and content for as long as your account is active or as needed to provide the Service. When you delete your account, we will delete or anonymize your data within a reasonable timeframe, except where retention is required by law or necessary to resolve disputes.

Usage data is generally retained for a shorter period unless needed for security or service improvement purposes.


Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Request a portable copy of your data
  • Withdraw consent where processing is based on consent

To exercise any of these rights, contact us at [email protected]. We will respond within a reasonable timeframe in accordance with applicable law.


Children’s Privacy

Paddi is designed for professional use and is not intended for anyone under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected such information, we will take steps to delete it promptly. If you believe a child has provided us with personal data, please contact us.


Third-Party Links

The Service may contain links to third-party websites or services that we do not operate. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any information.


Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or a prominent notice within the Service, and update the “Last updated” date above.

We encourage you to review this policy periodically for any changes.


Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us: