Privacy Policy
Last updated August 13, 2026
Digg (“Digg,” “we,” “us”) helps developers turn their approved AI-coding sessions into training data they are paid for. We are built for the most privacy-sensitive audience there is, so privacy is the product, not an afterthought. This policy explains what we collect, how it is protected, and the controls you have. It works together with our Terms of Service.
The core promise
Secrets, personal data, and your username in file paths are removed on your own machine, before anything is uploaded. When a batch reaches our servers, an independent re-scan removes anything the on-device filter missed. We store and serve only the redacted form, and every session shows you a counts-only summary of exactly what was removed.
What we collect
- Account data, your email and a decentralized identifier when you sign in, plus an embedded wallet address created for payouts. Used to credit and pay you.
- Captured coding sessions (redacted), for repositories you have consented to, the prompts, agent reasoning, tool calls, edits, and outcomes of your AI-coding sessions, after on-device redaction. This is the data you can view, share, delete, and earn from.
- Outcome signals, whether tests passed, a build succeeded, or a change was committed, so a session can carry a verified result.
- Redaction metadata, counts only (e.g. “3 secrets, 2 PII, 1 path removed”), never the removed values.
- Product telemetry, an anonymous device id and basic usage events (such as when capture starts and stops, and when a session uploads), used to operate and improve the Service. This is never tied to the contents of your sessions.
- Payout details, your wallet address, and identity/tax information where required to move money (see Payments & compliance).
What we never collect or send
- Raw secrets or API keys, raw PII, or your OS username, these are stripped before upload.
- Sessions from repositories you have not consented to capture.
- Anything from outside your AI-coding sessions, no keystrokes in other apps, no browsing, no files the agent never touched.
How we use your data
- To show you your own sessions and let you share or publish the ones you choose.
- To license consented, redacted sessions to AI labs and applied-AI teams as training data. You receive 70% of the revenue. Every licensed record carries provenance and rights metadata, never your identity.
- To calculate the points you earn for sellable sessions and attribute your share when your data is licensed.
- To operate, secure, and improve the service, and to meet legal and tax obligations.
Who we share it with
- Data buyers receive only redacted, provenance-stamped sessions you have consented to license, attributed to an anonymous contributor id, never your email or identity.
- Service providers we rely on to run the product (cloud hosting, database, payment and KYC/AML providers), under contract and only as needed.
- Legal, where required by law, or to protect rights, safety, and the integrity of the service.
We do not sell your personal information, and we do not attach your identity to licensed data.
Your controls
- See everything, every captured session appears on your sessions page with its redaction summary.
- Delete, hard-delete any session (and its events) at any time. Right to be forgotten, per session.
- Share on your terms, sessions are private by default; you choose unlisted-link or public (Discover) per session, and can revoke either.
- Pause or remove, pause capture, or remove the daemon and its local data, from the command palette; uninstalling the extension stops capture.
- Access & portability, request a copy or deletion of your account data by emailing support@digg.sh.
Payments & compliance
You keep 70% of the revenue when your data is licensed, withdrawable as USDC on Base (from $0.10). Crypto payouts may be gated behind identity verification (KYC/AML) and sanctions screening, and tax details may be collected before money moves, according to your jurisdiction.
Data retention
We keep redacted sessions while your account is active or as needed to provide the service and honor licenses already granted. Deleting a session removes it and its events from our systems. Account data is retained as required for legal, tax, and accounting purposes.
Security
Redaction runs on your device; transport is encrypted; access is scoped and least-privilege; secrets and keys are held in a managed secret store. No system is perfectly secure, but data-minimization (on-device redaction, counts-only manifests) means the most sensitive data never leaves your machine in the first place.
Your regional rights
Depending on where you live (e.g. the EEA/UK under GDPR, or California under the CCPA/CPRA), you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to certain uses. Consent to capture is explicit and revocable. Contact us to exercise any of these rights.
Children
Digg is for professional developers and is not directed to anyone under 18.
Changes
We may update this policy as the product evolves. Material changes will be reflected by the “Last updated” date above and, where appropriate, an in-product notice.
Contact
Questions or requests: support@digg.sh.