Legal
Privacy Policy
Trenchcoat records how AI agents are used. That means the data you send us can be sensitive, so this page says plainly what we store, what we refuse to store, and how you control the difference.
Last updated 11 August 2026
Who we are
Trenchcoat is operated by Pando. We provide a hosted service that ingests telemetry from AI coding agents and presents it as analytics. You can reach us at support@pando.codes.
Account data
When you create an account we store your email address, a display name, and an avatar URL. If you sign in with Google, those three values come from your Google profile — we request only your email address and basic profile, never access to your Google account contents, and we do not ask for offline access, so we hold no Google refresh token. Passwords, when you use one, are handled by our authentication provider and are never visible to us.
Telemetry you send us
Everything else we hold is telemetry your agent sends through an API key you create. You choose how much that key is allowed to record, and the limit is enforced when the data arrives, not when it is displayed — data above your key's level is never written down in the first place.
| Capture level | What it records |
|---|---|
| read:sessions | Conversation metadata only — timing, model, token counts, cost. No content of any kind. |
| read:events | Which skills, subagents, MCP servers, tools and commands ran, by name, plus error diagnostics. |
| read:prompts | Your prompts and the assistant’s responses, verbatim. |
| read:full | Everything above, plus tool arguments, shell commands, file paths and raw API request bodies. |
A narrower level is not a display preference. If you grant read:sessions, your prompts are not stored anywhere in our systems, and no setting we could later change would recover them.
What we drop regardless of your settings
Some fields are discarded on arrival at every capture level, including the unrestricted one. These are identity fields that describe the person or machine rather than the work — the operating system user, the process owner, and the email address your agent reports. There is no configuration that turns this off.
Who else processes your data
We keep this list short deliberately.
- Supabase — hosts our database and handles authentication. All account and telemetry data lives there.
- Vercel — hosts the application and this site, and therefore processes request logs.
- Anthropic — generates the plain-language session summaries shown in the dashboard. Session content is sent to Anthropic's API for that feature only.
- Google — only if you choose to sign in with Google, and only to authenticate you.
We do not sell your data, and we do not use your telemetry or prompt content to train models.
Who can see your data
Your data is scoped to your account at the database level. Other customers cannot query it. If you share a session or dashboard with a team, the people in that team can see what you shared — sharing is always an action you take, never a default.
Retention, export and deletion
We keep your telemetry until you delete it or close your account; we do not currently expire it on a schedule. Email us at support@pando.codes to request a copy of your data or to have your account and its telemetry deleted, and we will action it. Revoking an API key stops new data arriving immediately but does not remove what has already been recorded.
Cookies
The application sets cookies to keep you signed in. That is what they are for; we do not run advertising or cross-site tracking cookies.
Changes
If we change what we collect or who processes it, we will update this page and its date. While Trenchcoat is in beta, the product moves quickly — if a change narrows your privacy rather than widens it, we will tell account holders directly rather than relying on you noticing this page.