Data processing
SiliCode · Last updated 30 August 2026
This page explains which third parties can receive inputs you submit to SiliCode, what is transmitted, and how to ask for a data-processing addendum (DPA). It supplements the Privacy Policy.
Who can receive your inputs
A run sends the specification, relevant conversation history, coding-style preferences, and — when the mode requires it — project source to the model serving that run:
- OpenRouter — most pipeline and feature LLM calls (generation, reflection, titles, search-agent routing).
- Anthropic — agentic author, project, debug, and optimize modes talk to the Anthropic API directly.
- Exa — only if you turn on Exa Search for that run; the query is sent to Exa.
Tools that stay on our infrastructure (Icarus Verilog, Yosys, Verilator, the RAG service) process source inside our environment. The RAG service is part of the same deployment.
What is transmitted
Whatever the selected run needs: your prompt, prior turns in that chat, attached files the agent reads, and tool results. We do not send your billing card details to model providers. We do not send other customers’ projects.
Provider retention and training
We do not train SiliCode models on customer content. OpenRouter and Anthropic API products, as we understand their current terms, are not used to train the provider’s foundation models by default. A provider may retain prompts for abuse monitoring for a limited period under their own policy. We do not control a provider’s logs; if you cannot send a specification to a third-party API, do not submit it here.
Our retention and deletion
Chats persist until you delete them. Project workspaces idle for 30 days (24 hours if never attached to a chat) are removed. Account deletion is via support. See the Privacy Policy for the full list.
Encryption
Connections to SiliCode and to subprocessors listed here use TLS in transit. Encryption at rest depends on the host; contact us if you need it confirmed for a business deployment.
Subprocessors
- OpenRouter (LLM routing)
- Anthropic (agent mode)
- Stripe (payments in USD, billing portal)
- PostHog, EU-hosted (product analytics and masked session replay; off if you opt out)
- Sentry (error reporting; request bodies and secrets are scrubbed; off if unset)
- Exa (optional web search on a run)
- Our SMTP provider (signup codes, waitlist and support email)
- Google and GitHub (only if you use social login, for identity assertion)
Data-processing addendum
Business customers who need a signed DPA can request one at [email protected]. This page is the description of processing we will attach; we do not generate a DPA from the product itself.