Privacy Policy

Last updated: August 8, 2026

Who we are

RocketBench is operated by RocketBench, Inc. (“RocketBench,” “we,” “our”), 700 N Colorado Blvd, Suite 353, Denver, CO 80206. We process tickets you tag in your project-management tool (Linear, Jira, GitHub, etc.) and deliver working code back as a pull request.

What we collect

To deliver the service, we collect:

  • Account info — your email, name, and (if provided) company.
  • OAuth credentials — when you connect Linear, GitHub, Slack, or Jira, we receive an access token (and refresh token where applicable) scoped to the permissions you authorized. We never receive your password.
  • Ticket content — the title, description, comments, labels, and attachments of any ticket you tag for us to work on.
  • Code context — the contents of source files we read while working on a ticket, plus the diffs we produce.
  • Operational telemetry — request logs, pipeline stage events, error traces, and performance metrics. No third-party analytics tracking is enabled on authenticated dashboard pages.
  • Payment metadata — handled by Stripe. We never see or store full card numbers.

How we use it

  • Run your tagged tickets through our pipeline (specification, code generation, review, delivery).
  • Post results back to your PM tool (PRs, comments, status updates).
  • Improve product quality (we may review pipeline outputs internally for accuracy and safety; we do not train third-party models on your data).
  • Bill, support, and communicate with you about your account.
  • Detect and prevent abuse (rate limits, fraud, terms violations).

Subprocessors

We rely on a small number of trusted vendors to operate the service. Current subprocessors:

  • Anthropic, OpenAI, Google — large language model inference. Ticket and code content is sent to one or more of these providers as part of pipeline processing. None train on our API traffic by default per their commercial terms.
  • Railway — application hosting (Postgres, Redis, workers).
  • Vercel — frontend hosting + analytics.
  • Tigris — object storage for review artifacts and baselines.
  • Mailgun — transactional email (magic links, delivery notifications).
  • Stripe — payment processing.
  • Cloudflare — Turnstile bot protection on signup + CDN.
  • ScaleKit — OAuth connection broker for board integrations (Asana, Monday.com, ClickUp). Holds the provider tokens for those connections.
  • Sentry — error monitoring. Error reports may incidentally include account or request identifiers.
  • Amazon Web Services — signed release distribution for the WordPress companion plugin (no customer data).

We’ll update this list before adding a new subprocessor that receives customer data.

Data retention

Account and ticket data is kept while your account is active. After account closure, we delete identifying account info within 30 days and anonymize operational logs within 90 days. Payment records are retained as required by tax law (typically 7 years). Encrypted artifacts in object storage are deleted within 30 days of account closure.

Security

OAuth tokens and other secrets are encrypted at rest using authenticated symmetric encryption (Fernet / AES-128-CBC + HMAC-SHA256). All transport is TLS 1.2+. We follow least-privilege principles on employee data access. We don’t (yet) hold a SOC 2 attestation — if you need one for procurement, reach out and we’ll discuss.

Cookies

We use a small number of strictly-necessary cookies:

  • trial_session — keeps you signed in to the trial dashboard. HttpOnly, Secure, SameSite=Lax, 14-day expiry.
  • portal_session — keeps you signed in to the customer portal (app.rocketbench.com). HttpOnly, Secure, 30-day expiry.
  • rb_oauth_state and rb_portal_oauth_state — short-lived (10 min) CSRF protection during OAuth installs on the trial and portal surfaces respectively.

Marketing pages may set Vercel Analytics first-party cookies for aggregate visit metrics. No cross-site tracking.

Your rights (including GDPR and CCPA)

First, the headline: we do not sell your personal information, and we do not share it for cross-context behavioral advertising. There is nothing to opt out of on that front.

Depending on your jurisdiction (GDPR, CCPA/CPRA, and similar laws), you may have the right to:

  • Know and access — get a copy of the personal data we hold about you and how we use it.
  • Correct — fix inaccurate account information.
  • Delete — have your personal data removed (details below).
  • Port — receive your data in a usable format.
  • Not be discriminated against for exercising any of these rights — same service, same price.

How to make a request: email hello@rocketbench.comfrom the address on your account (that’s how we verify it’s you — we may ask a follow-up question if anything looks off). An authorized agent may submit on your behalf with your written permission. Every request is handled by a person; we aim to respond within 30 days and will complete requests within 45 days at the latest.

Data deletion

Ask for deletion (or close your account) and we remove your account information, ticket content, code context, and stored artifacts on the timelines in “Data retention” above — identifying account info within 30 days, operational logs anonymized within 90.

Two honest carve-outs:

  • What the law makes us keep — billing and tax records (retained per tax law), plus minimal records needed for security and fraud prevention.
  • What lives in your own tools— tickets, comments, and pull requests we created in your Linear, GitHub, Asana, or other connected tools belong to those accounts and stay under your control there. Deleting your RocketBench data doesn’t reach into your tools; revoking a connection immediately cuts our access.

Children

RocketBench is not directed to children under 16. We do not knowingly collect data from children.

International transfers

Our infrastructure is hosted in the United States. By using RocketBench from outside the US, you consent to your data being processed there.

Changes

We’ll post any material changes to this policy on this page and update the “Last updated” date. For significant changes that affect how we use existing customer data, we’ll also notify you by email.

Contact

Questions about this policy or our handling of your data: hello@rocketbench.com or write to us at the address above.