Privacy Policy
Last updated: March 4, 2026
Nocetic Limited ("we", "us", "our") operates Dispatch, a multi-agent AI development platform available as a native macOS application and at dispatch.codes (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information.
By using Dispatch, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
Account Information
When you create an account, we collect your name, email address, and authentication credentials (via Firebase Auth). If you sign in with a third-party provider (Google, GitHub), we receive profile information from that provider.
Usage Data
We collect anonymized usage analytics to improve the Service, including feature usage patterns, session duration, and performance metrics. We do not collect your code or AI agent outputs.
Crash Reports
When the application encounters an error, you may choose to send a crash report. Crash reports include the error message, stack trace, your user ID, browser/platform information, and any optional notes you provide. These reports are stored in our database and used solely to diagnose and fix issues.
Payment Information
Payment processing is handled by third-party providers (e.g., Stripe). We do not store credit card numbers. We may receive limited billing information such as the last four digits and expiration date for display purposes.
Communication Channel Data
When you connect messaging channels (Telegram, Discord, Slack, WhatsApp), we store the necessary tokens and identifiers to maintain the connection. Messages sent through channels are processed transiently and not stored on our servers.
2. Local-First Architecture
Dispatch is designed with a local-first architecture. Your source code, project files, and development environment remain on your local machine. We do not have access to your code repositories or local project files.
The built-in AI Chat feature routes requests through our server (dispatch.codes) for usage tracking and billing purposes. We process prompt and completion token counts and the model used, but do not store the content of your conversations. Autonomous AI agents (Ralph, Flowly) run locally on your machine and communicate directly with AI providers.
3. How We Use Your Information
- To provide, maintain, and improve the Service
- To process your transactions and manage your subscription
- To send transactional emails (account verification, password reset, billing)
- To send product updates and changelog notifications (you can opt out)
- To detect, prevent, and address technical issues and abuse
- To comply with legal obligations
4. AI Provider Data
Dispatch supports multiple AI providers (Anthropic, OpenAI, Google, etc.). AI interactions are handled in two ways:
- Built-in Chat — requests are routed through our API proxy for usage tracking and credit billing. We record token counts and model identifiers but do not store conversation content.
- Local agents (Ralph, Flowly) — these run on your device and communicate directly with AI providers using your own API keys. We do not intercept or process these communications.
Each AI provider has its own privacy policy governing how they handle your data. We encourage you to review those policies.
5. Real-Time Sync (CRDT)
Dispatch offers optional real-time collaboration via CRDT (Conflict-free Replicated Data Types). When enabled, project data such as Kanban tasks and settings are synced between your devices through our relay server (relay.dispatch.codes). The relay forwards encrypted binary data between authenticated peers and does not inspect or store document contents beyond transient message delivery.
6. Data Sharing
We do not sell your personal information. We may share information with:
- Service providers — hosting (Vercel), authentication (Firebase), payment processing (Stripe), and analytics services that help us operate the Service
- Legal requirements — when required by law, regulation, legal process, or governmental request
- Business transfers — in connection with a merger, acquisition, or sale of assets
7. Data Retention
We retain your account information for as long as your account is active. Usage analytics are retained in anonymized form. If you delete your account, we will delete your personal data within 30 days, except where we are required by law to retain it.
8. Security
We implement industry-standard security measures including encrypted data transmission (TLS), secure authentication (Firebase Auth with OAuth 2.0), and access controls. However, no method of electronic transmission or storage is 100% secure.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Data portability
- Withdraw consent at any time
To exercise these rights, contact us at [email protected].
10. Cookies
Our website uses essential cookies for authentication and session management. We use analytics cookies (which can be opted out of) to understand how visitors use our site. The desktop application does not use cookies.
11. Children's Privacy
The Service is not intended for users under 16 years of age. We do not knowingly collect personal information from children under 16.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance.
13. Contact
If you have questions about this Privacy Policy, contact us: