Privacy Policy
Last updated October 3, 2026. Draft, pending legal review.
Ahena is operated by Cao-Tech LLC (“we”, “us”). Ahena connects, configures, verifies and maintains the third-party services your applications use, such as Supabase, Cloudflare, Resend, Stripe, Firebase, OpenAI, Anthropic and Ollama. This policy explains what information Ahena handles when you use the website at ahena.io, the dashboard at app.ahena.io, the API at api.ahena.io, the ahena command-line tool and its MCP server.
Information we handle
Account information
Your name and email address. If you set a password, we store only a salted hash of it (scrypt), never the password itself. We record when your email address has been verified by a sign-in provider, and when you last used each sign-in method.
GitHub and Google sign-in
If you sign in with GitHub or Google, we receive:
- your account identifier at that provider;
- your email address, and whether the provider has verified it;
- your display name.
From GitHub we request the read:user and user:email scopes, and from Google openid, email and profile. We use the access token the provider issues only once, to read that information, and we don't store it. We don't request access to your repositories or any other Google data.
Provider connections and credentials
When you connect a provider, you give Ahena an API key, token or service-account key for it, plus non-secret settings such as a project reference or account ID. Secrets you store with ahena env set are handled the same way.
These credentials are encrypted before they're stored, with AES-256-GCM using per-secret data keys, which are themselves encrypted with a master key held separately from the database. Ahena decrypts a credential only to call the provider it belongs to, and only for an action you requested or a check you ran. Credential values aren't shown back in the dashboard, API or MCP. Listings show only a masked hint, such as the last four characters.
Project and stack information
Organizations, members and roles; projects and environments. The contents of your ahena.config.ts and ahena.lock that the CLI shares with Ahena, which describe the services your app uses and are designed to contain no secrets. The Stack Graph built from them, and the plans you create, approve and apply, with each operation's outcome.
Information read from your providers
To check and configure your services, Ahena reads from your provider accounts what an action needs. For example:
- project and service status;
- authentication settings such as redirect URLs;
- storage buckets and CORS rules;
- DNS records;
- email domains and webhooks;
- payment account readiness, products and prices;
- registered mobile apps;
- available AI models.
Doctor results and the live values Ahena tracks for drift detection are stored with your project. Values that look like secrets are redacted before storage. For databases it reads structure (table names, migrations and row-level security settings), not the rows in your tables. Ahena doesn't read your application's end-user data, email contents or payment transactions. To check AI providers it lists models with your key, and never sends prompts.
Diagnostics run on your machine
Some Doctor checks run in the CLI on your computer, such as checking that environment files aren't committed to Git. The CLI sends Ahena only the result and the file locations it found, never file contents or the credentials themselves.
MCP and AI agents
The Ahena MCP server runs on your computer. When an AI agent uses it, Ahena receives the resulting API requests, such as reading your Stack Graph, creating or applying a plan, or running Doctor. These are labelled as coming from MCP in your activity log. Ahena doesn't receive your conversations or prompts with the AI agent; those stay between you and your agent's provider.
Activity and audit logs
Ahena records security-relevant actions, with who did them, when and through which client: sign-ins and sign-in failures, connections, configuration changes, plan approvals and outcomes, membership changes and similar events. The audit log is append-only and tamper-evident, and it records names of secrets and resources, never their values.
Cookies and sessions
The dashboard uses only cookies it needs to work, all of them HttpOnly:
- a session cookie, for up to 14 days or until you sign out;
- a short-lived cookie, lasting 10 minutes, that ties a GitHub or Google sign-in to your browser;
- a short-lived cookie, lasting 10 minutes, used while connecting a sign-in method to an existing account.
We don't use advertising or analytics cookies. Our hosting provider may set cookies it needs for security and abuse prevention. The CLI stores its sign-in token in a file on your computer that only your user account can read.
Security and service logs
Our servers log each request's method, path, status, timing and a request ID, but not request bodies, headers, query strings or credentials. We use your IP address to rate-limit sign-in attempts and provider operations. Our hosting provider also processes IP addresses and request metadata to deliver and protect the service.
Billing information
Ahena doesn't currently charge for anything or collect payment information. If we add paid plans, payments will be handled by a payment processor. We'll update this policy beforehand to describe what we receive, which we expect to be limited to billing contact details, plan and payment status, not full card numbers.
How we use information
We use information to:
- provide Ahena: sign you in, show your stack, run the checks and changes you ask for, and generate integration code;
- keep accounts and connected services secure, and prevent abuse;
- keep audit records;
- communicate with you about your account and the service;
- fix problems;
- comply with the law.
Ahena acts on your provider accounts only as you direct, within the permissions you granted and the approval rules described in our Terms. We don't sell your information or use it for advertising. Ahena doesn't use your data to train machine-learning models.
Service providers
We use these providers to run Ahena:
- Cloudflare: hosting of the website, dashboard and API; DNS; network security; and request logs.
- Supabase: hosting of Ahena's database, in the United States. It stores the information described above, with credentials encrypted.
- GitHub and Google: only if you choose to sign in with them.
The providers you connect (Supabase, Cloudflare, Resend, Stripe, Firebase, OpenAI, Anthropic and others) are your own vendors, under your own agreements with them. Ahena communicates with them on your instructions. Their handling of your data is governed by their own policies.
Retention
We keep account, project and connection information while your account or organization exists.
- Sign-in attempts expire after 10 minutes and are cleaned up after that.
- Sessions end when they expire or you sign out.
- Request logs are kept for the limited period our hosting provider allows.
- Audit records are kept for security, integrity and legal reasons for as long as that's necessary, including after the account or organization they describe is deleted. They contain identifiers and event details, not credentials.
Deleting your account
You can disconnect providers, which deletes the credentials Ahena stored for them, and you can remove members and sign-in methods yourself. To delete your account or an organization, email us at privacy@ahena.io. We'll then delete:
- your account and sign-in methods;
- organizations you are the only owner of, with their projects, connections and stored credentials;
- Doctor results and plans.
We keep audit records as described above. Deleting data in Ahena doesn't delete anything in your provider accounts or revoke keys you created there. Revoke those with the provider.
Security
Measures include:
- encryption in transit (HTTPS) and of stored credentials;
- hashed passwords and session tokens;
- role-based access within organizations;
- approval steps for billable, destructive and production changes;
- rate limiting;
- a tamper-evident audit log.
No system is completely secure, and we don't hold any third-party security certification. If you believe you've found a vulnerability, please contact us.
International users
Cao-Tech LLC is based in the United States, and Ahena's database is hosted there. Our hosting network operates worldwide. If you use Ahena from outside the United States, your information is processed in the United States. Depending on where you live, you may have rights to access, correct, delete or export your personal information, or to object to certain processing. Contact us to exercise them.
Children
Ahena is a tool for software developers and isn't directed to children. Don't use Ahena if you're under 16. If we learn we've collected information from a child, we'll delete it.
Changes
We'll update this policy when Ahena changes how it handles information, and change the date above. For material changes we'll give notice in the dashboard or by email before they take effect.
Contact
Cao-Tech LLC · privacy@ahena.io