LAST UPDATED · JULY 9 2026
Privacy Policy
This Privacy Policy explains how The Termi Protocol (“Termi Protocol,” “we,” “us,” “our”) collects, uses and protects personal data when you visit termiprotocol.com, create an account, or use our services (together, the “Service”). It is written to address the EU/UK GDPR, Türkiye’s KVKK, and the CCPA/CPRA (California).
Termi Protocol is an independent product and is not affiliated with, endorsed by, or sponsored by any third-party AI provider. All product names, logos and trademarks are the property of their respective owners and are used only to indicate tools you can connect yourself (BYOK). We do not sell model APIs. We provide a local 3D simulation that visualizes the 2D workflows of AI coding agents you run.
1. Who is responsible for your data (Controller)
The data controller (KVKK: veri sorumlusu) is Ercaap Mobile App Yazilim ve Teknolojileri Limited Sirketi, Fenerbahce Mah. Igrip Sok. No:13 Ic Kapi No:1, Kadikoy / Istanbul / Turkiye. Trade registry: Istanbul Ticaret Sicili Mudurlugu (file no 1107323). MERSIS 0339072519900001. Tax office: Kadikoy V.D., VKN 3390725199. For any privacy question or to exercise your rights, contact support@termiprotocol.com.
2. Local Simulation & The Local-First Principle (what we never receive)
We do not sell, resell, host, or provide any AI model APIs. The Termi Protocol is a 3D simulation that visualizes the 2D workflows of AI coding agents (the file reads, code writes, commands and git steps that happen in the terminal). You run the agents on your machine or with keys you supply (BYOK). Your source code, files, terminal sessions, prompts, AI outputs and credentials stay on your device and flow directly to the AI provider you chose. We only receive the high-level workflow events needed to drive the 3D visualization.
3. Information we collect (website & account)
- Account & sign-in. When you create an account we process your email address and an encrypted password, or (if you choose “Continue with Google”) the name, email, profile picture and Google account identifier that Google returns. Authentication is handled by Supabase on our behalf.
- Profile & gamification. Your username/display name, avatar, and game progress (XP, level, league, daily usage statistics such as token/cost totals) used to power the leaderboard and your stats. Your username and rank may be shown publicly on the leaderboard.
- Anonymous usage analytics. Via Amplitude we collect basic, page-level usage on every visit: which pages you open and leave, sessions, device/browser type, language, and approximate location derived from your IP. A random identifier is stored on your device so repeat visits can be counted as one unique visitor; this identifier is not linked to your name. This baseline runs for all visitors, as described in “Cookies & consent” below.
- Detailed product analytics & Session Replay (with your consent). If you accept analytics in the cookie banner, Amplitude additionally records detailed interactions (clicks, form interactions, file downloads) and Session Replay, a reconstruction of your interactions (mouse movement, clicks, navigation) that helps us diagnose issues and improve UX. Text you type and form inputs are masked by default, and passwords are never captured. When you are signed in, your analytics events are associated with your account ID.
- Infrastructure & security. Our host/CDN Cloudflare processes connection data (IP address, request metadata, approximate location, and bot/threat signals) to deliver, secure and measure the site.
- Payments. If you make a purchase, our third-party payment processor handles your card/billing details securely and directly. We do not receive or store full card numbers; we keep your purchase/license status and a processor customer reference.
- Communications. If you join a waitlist, contact us or send feedback, we keep your email and message.
4. How we use information & our legal bases
- To provide the Service: create and secure your account, run the leaderboard, deliver your purchase. Legal basis: performance of a contract.
- Analytics, Session Replay & product improvement. Legal basis: your consent (where required), otherwise our legitimate interest in understanding and improving the Service.
- Security, fraud and abuse prevention (including bot mitigation). Legal basis: legitimate interests / legal obligation.
- Communications you requested (product updates, protocol releases, support). Legal basis: consent or legitimate interest.
5. Cookies, local storage & consent
We use essential cookies/local storage to keep you signed in and remember preferences. We also use Amplitude for analytics: a baseline of anonymous, page-level statistics (including a random device identifier used only to count unique visitors) runs for all visitors under our legitimate interest in measuring and improving the site. Session Replay and detailed interaction analytics run only if you accept them in the cookie banner, and you can withdraw consent at any time by declining or clearing the site’s local storage. You can also block cookies/storage in your browser; essential functionality will still work.
6. Who we share data with (processors / third parties)
We do not sell your personal data. We share it only with service providers who process it on our instructions:
- Supabase: authentication & database (account, profile, usage). Hosted in the EU (eu-central-1).
- Google: “Sign in with Google” (only if you choose it).
- Amplitude: product analytics & Session Replay.
- Cloudflare: hosting, CDN, security and traffic analytics.
- Payment processor: secure processing of one-time Lifetime Pass purchases.
We may also disclose data if required by law or to protect our rights, users and the Service.
7. International data transfers
Some processors (e.g. Amplitude, Cloudflare, our payment partner, Google) are based in or transfer data to the United States and other countries. Where data leaves the EEA/UK/Türkiye, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and equivalent mechanisms.
8. Data retention
We keep account and profile data for as long as your account exists, and delete or anonymise it within a reasonable period after you close it (unless we must retain some records for legal, tax or security reasons). Analytics and Session Replay data are retained for a limited period in line with Amplitude’s settings. Waitlist/contact data is kept until you ask us to delete it or it is no longer needed.
9. Your rights
Depending on where you live (GDPR, KVKK, CCPA/CPRA), you may have the right to: access your data; correct it; delete it; export/port it; object to or restrict processing; withdraw consent; and, under the CCPA, to know, delete, correct and opt out of “sale”/“sharing” (we do not sell or share in that sense). To exercise any right, email support@termiprotocol.com. You may also lodge a complaint with your supervisory authority, in Türkiye the Kişisel Verileri Koruma Kurulu (KVKK), in the EU your local Data Protection Authority.
10. Security
We use encryption in transit (HTTPS), reputable processors, access controls and other measures to protect your data. No method of transmission or storage is 100% secure, but we work to protect your information and to notify you and regulators of breaches where required.
11. Children
The Service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
12. Changes
We may update this policy as the product evolves through its protocols. Material changes will be reflected by the “Last updated” date above and, where appropriate, notified to you.
13. Contact
Privacy questions or requests: support@termiprotocol.com.