Privacy Policy
What we collect, where it goes, how long we keep it, and the rights you have over it.
Last updated: 11 July 2026
Who we are
Pier is built and operated by Alphabench LLP, a limited liability partnership incorporated in India (“we”, “us”). We are the Data Fiduciary for the personal data described in this policy under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”). For any privacy question or to exercise your rights, contact us at hello@piercode.com.
What we collect, and why
- Account data: your email address, a securely hashed password (or your Google account id if you sign in with Google), and account settings. Used to provide the Service and to send transactional email.
- Service content: when the Pier agent works on a task, the prompts it builds (which can include slices of your code, file contents, and command output) pass through our servers to the model platform you selected on a Pier subscription. With your own API key, the CLI calls the provider directly and these prompts never reach us. Synced conversation threads are stored so you can resume sessions across devices; see “The Pier CLI” below for what is sent and how to turn syncing off.
- Billing data: subscription status, transaction amounts, and payment metadata from our payment processors. Card numbers are handled entirely by the processor and never touch our servers.
- Website analytics: only if you accept the cookie banner; detailed below.
We collect no more than the Service needs (the DPDP Act’s data-minimisation principle): we do not log your IP address in our application records, we store only hashes of passwords and access tokens, and your prompts and stored data are never used to train any model by Alphabench.
Cookies, analytics & advertising on this website
The website sets two kinds of first-party cookies: a session cookie when you sign in, and a cookie remembering your cookie-consent choice. Neither tracks you.
The optional tools below load only after you accept the cookie banner. Declining (or ignoring) the banner keeps them all off, and you can change or withdraw your choice at any time via “Cookie preferences” in the footer. Withdrawal takes effect immediately for session replay and on your next page load for the rest.
Google Analytics
- Purpose:
- Aggregate traffic and usage statistics.
- Data:
- Pseudonymous usage events, approximate location, device/browser.
- Where:
- United States
- Their policy:
- https://policies.google.com/privacy
Meta (Facebook) Pixel
- Purpose:
- Measuring the effectiveness of our advertising on Meta platforms.
- Data:
- Page views and conversion events (sign-up, checkout, purchase), device/browser identifiers, IP address.
- Where:
- United States
- Their policy:
- https://www.facebook.com/privacy/policy/
X (Twitter) Pixel
- Purpose:
- Measuring the effectiveness of our advertising on X.
- Data:
- Page views and conversion events, device/browser identifiers, IP address.
- Where:
- United States
- Their policy:
- https://x.com/en/privacy
OpenReplay
- Purpose:
- Session replay to debug usability issues.
- Data:
- Interaction recordings with typed input, on-screen email addresses, and numbers obscured before anything is sent. Sessions are linked to an internal account id, never to your email.
- Where:
- United States
- Their policy:
- https://openreplay.com/privacy.html
The Pier CLI
The CLI is open source. You can read exactly what it collects and sends in the source code at github.com/alphabench/pier.
The CLI runs locally on your machine. When the agent works on a task, it sends the model the context that task needs: your instructions, relevant slices of code and command output, your working directory path, operating system, and git branch. Where that data goes depends on how you use Pier:
- On a Pier subscription: requests call an endpoint we host, so they pass through our servers on the way to the model platform you selected. This is the only case in which your prompts travel through Alphabench.
- With your own API key: the CLI calls the provider directly from your machine. Your prompts never touch our servers.
By default the CLI also syncs your conversation threads (including the code and command output they contain) to our servers so you can resume sessions across devices. You can turn this off at any time by running the CLI with the --local flag or setting threadSync: false in your Pier config; threads then stay only on your machine. The CLI contains no analytics or crash reporting, and API keys you bring are stored only on your machine.
Model platforms & other processors
Alphabench does not build models. We route your prompts to the model platform you select, and we rely on a small set of processors to run the Service. The table below lists each one, what it receives, and where it processes data. Some of them process data outside India, including in the United States and, for DeepSeek models, in China. If a provider’s location matters for your project, choose your model accordingly; the model picker always shows which platform a model runs on.
Sarvam AI
- Purpose:
- Model inference for Sarvam models.
- Data:
- Prompts, including code and tool output the agent reads for your task.
- Where:
- India
DeepSeek
- Purpose:
- Model inference for DeepSeek models and the Pier Hybrid router's backbone.
- Data:
- Prompts, including code and tool output the agent reads for your task.
- Where:
- China
OpenRouter
- Purpose:
- Model inference for models you select via OpenRouter.
- Data:
- Prompts, including code and tool output the agent reads for your task.
- Where:
- United States
Fireworks AI
- Purpose:
- Model inference for models hosted on Fireworks.
- Data:
- Prompts, including code and tool output the agent reads for your task.
- Where:
- United States
Exa
- Purpose:
- Web search and page fetching when the agent uses web tools.
- Data:
- Search queries and fetched URLs from your session.
- Where:
- United States
Razorpay
- Purpose:
- Payment processing for INR plans.
- Data:
- Payment details, email, transaction amounts. Card numbers never touch our servers.
- Where:
- India
Dodo Payments
- Purpose:
- Payment processing for international (USD) plans.
- Data:
- Payment details, email, transaction amounts. Card numbers never touch our servers.
- Where:
- United States
Google (Sign-In)
- Purpose:
- Optional sign-in with your Google account.
- Data:
- Your Google account email and identifier, received from Google when you choose this sign-in method.
- Where:
- United States
GitHub
- Purpose:
- Optional repository access for remote execution, via a GitHub App you install.
- Data:
- Repository access through short-lived tokens; we store your GitHub username and installation id, never your GitHub tokens.
- Where:
- United States
Amazon SES
- Purpose:
- Transactional email (confirmation, password reset, billing).
- Data:
- Your email address and the message content.
- Where:
- India (ap-south-1, Mumbai)
Railway and Supabase
- Purpose:
- Hosting for our API server and database.
- Data:
- All service data described in this policy is processed and stored on this infrastructure.
- Where:
- United States
Each platform processes data it receives under its own data and compliance policies. The data we store is never used to train any model by Alphabench, and we never sell your personal data.
How long we keep data
We keep personal data only as long as it serves the purpose it was collected for, then erase it on a schedule:
| Data | Kept for |
|---|---|
| Account (email, sign-in method, settings) | Until you delete your account. |
| Conversation threads synced by the CLI | Until you delete the thread or your account. Disable syncing anytime with local mode. |
| Per-request processing logs (prompt and response bodies) | Content is erased after 30 days; the remaining metadata (timestamps, token counts, costs) is deleted after 12 months. |
| Web search queries made through the agent | Query content erased after 30 days. |
| Transactional email log | Recipient address erased after 90 days. |
| Billing and payment records | Retained as required by Indian tax and accounting law (up to 8 years), even after account deletion. Personal details inside raw payment-provider events are erased after 90 days. |
| Website analytics (only if you accepted cookies) | Per the retention settings of each tool, listed above. |
Your rights
Under the DPDP Act (and, where applicable, the EU/UK GDPR or CCPA), you have the right to:
- Access: request a copy of your personal data and a summary of how it is processed. You can download your data from your account page.
- Correction: have inaccurate or incomplete data corrected or updated.
- Erasure: delete your account and personal data from your account page. Billing records we are legally required to keep are retained in anonymised form.
- Withdraw consent: as easily as you gave it, at any time (for example via “Cookie preferences” in the footer, or the marketing-email toggle in your account).
- Nominate: designate another person to exercise these rights on your behalf in the event of death or incapacity. Email us to record a nominee.
- Grievance redressal: raise a complaint with us (below) and, if unresolved, with the Data Protection Board of India.
Grievance officer
Vatsal Pandya, Alphabench LLP, is the grievance officer for the Service. Reach him at grievance@piercode.com. We acknowledge grievances within 7 days and aim to resolve them within 30 days. For product bugs or feature requests (as opposed to privacy grievances), you can also open a public issue on GitHub.
Security & breach notification
Passwords and access tokens are stored only as one-way hashes, transport is encrypted with TLS, and access to production data is restricted and logged. In the event of a personal data breach we will notify the Data Protection Board of India and affected users as required by the DPDP Act.
Children
The Service is for users aged 18 and above. We do not knowingly process the personal data of children; if you believe a child has created an account, contact us and we will delete it.
Trademarks & affiliation
Pier is an independent product built and operated by Alphabench LLP. It is not affiliated with, endorsed by, or sponsored by any model provider. “Pier”, “Sarvam AI”, and any related marks are the property of their respective owners and are referenced here only to describe the underlying technology.