CAMINO / PRIVACY
Privacy
Last changed 8 October 2026.
It is written to describe what Camino actually does, as accurately as we can, while the product is small and in early use. It will be reviewed before Camino is offered widely.
Camino helps you plan and build a product one step at a time, and checks the evidence that each step is done. To do that it stores what you put into it. This page says what that is, where it goes, and how to have it removed. It is written under Australia's Privacy Act 1988 and the Australian Privacy Principles.
What we store
- Your account — your email address and a display name. If you sign in with GitHub, the email and name GitHub gives us.
- Your projects — plans, steps, the evidence you submit, any files you upload as evidence, the verifier's verdicts, questions you ask about a step and the answers, your answers in a new idea's interview and in the conversation about channels, and the coach's questions and proposals, blockers, decisions and post-mortems.
- Readings you paste on a distribution channel — the number you say it shows, the dates, the verifier's verdict and reasons, and a fingerprint (a SHA-256) of the screenshot or export. The screenshot or export itself is sent to the verifier to be checked and is not kept. A reading showing your customers' names or email addresses is refused, so crop it to totals first.
- Payments Stripe tells us about, if you connect Stripe — your webhook's signing secret, encrypted with a key kept apart from the database; and for each payment, Stripe's ids for the event and the payment, whether it was live or a test, the amount and currency, when it was paid, the invoice number, the payer's initials, the channel tag, and the network address the delivery came from. Stripe's message also carries your customer's details; only their initials are kept.
- Your plan, if you pay for one — which plan, the date it is paid until, its status as Stripe reports it, and Stripe's ids for your customer record and subscription. Your card, billing address and tax details stay with Stripe; Camino never receives them.
- A history of what happened in each project — who did what and when. This is how the overview knows where you were.
- What catch-up found, not what it read. Catch-up runs on your computer, reads your repository there, and sends short facts about the files each step mentions to be judged. Your repository is not uploaded and files that hold secrets are never opened. A project linked to its repository on GitHub can also be caught up from Camino's server, which then reads the same files through GitHub, as the next item says; what is sent to be judged and what is kept are the same either way. For each step, the verdict, its one-line reason and the names of the files it cited are kept, with the commit and branch read, so you can review them and attest the steps you agree are done. A reason is the judge's own sentence and can quote a line it was shown, with anything shaped like a key cut out; the rest of what was sent about your files is not kept. A step you attest keeps that reason as its evidence. What the call cost is kept against your project, as for every model call.
- A link to your repository on GitHub, if you connect one. Connecting asks GitHub, with your permission, which repositories you administer that have Camino's GitHub App installed. That list, with your GitHub username and number, is kept for ten minutes for you to pick from, and deleted when you link or within a day; then the project's link: the repository's name and GitHub's numbers for it and for the App's installation, its default branch, whether it is private, who linked it and their GitHub username and number, and when. The sign-in GitHub gives us for this is used only for those questions and revoked at GitHub as soon as it has answered, every token it gave included; none of it is stored. Installing the App lets it read the repositories you choose, never change them. Camino reads a linked repository only when the person who linked it catches up from GitHub: first whether they still administer it, then the latest commit on its default branch, its list of files, its recent commit subjects, and the files catch-up opens, which that person is shown, every one, before anything is judged. Files that hold secrets are never fetched. What is read is held only while that pass runs, and none of it is stored. Unlinking, or deleting the project, removes the link; uninstalling the App on GitHub ends its access at once.
- What you share before an interview — a spec, a brief or notes you paste or upload as text on Shape, kept with the project, with anything shaped like a key or a password cut out first. When the interview starts it is sent once to the model to find what it says about each topic, and what it found, with the words it quoted, is kept and shown to you; the interview is sent that, not the documents. Each piece can be removed until the interview starts. Code is shared the same way from your computer, by Camino's command line or MCP server: facts about the repository (its shape, its manifests and tables, the names of its settings and of the files that hold secrets, its recent commit subjects, the start of its README, its pages), never its other files, and never a file that holds secrets; anything shaped like a key is cut out on your computer and again when it arrives. What the call cost is kept against your project, as for every model call.
- Research runs, if you start one — the passes you approved, the searches made in your brief's words, the pages read, each finding with the page it came from and the words on it that say so, the pages a search listed but nobody opened, and the report, kept with the project. Anthropic makes the searches and reads the pages, as the list below says. What the run cost is kept against your project, as for every model call.
- Invitations — the email address an owner of a project invited, who invited it and when, and whether it was accepted, declined or withdrawn. The people in that project can see the address. Nobody joins a project without accepting, and anybody but the person who created a project can leave it.
- Your email, if you joined the waitlist while the website offered it, and where you came from if you told us. The website no longer takes sign-ups; the addresses on the list are kept until you ask us to remove yours.
- Ordinary technical records — the hosting provider sees IP addresses and request details as part of serving the site, and PostHog receives your browser's IP address with each page view it counts.
Why
To run the product: to show you your projects, to check your evidence, to answer your questions about a step, to interview you about a new idea and about where to find customers, and to let the people you invite work with you. And to email you, if you are in a project, a weekly summary of it. The summary is on by default, because it is about work you are part of, and every one has a one-click way to stop it. We do not sell your information, and Camino does not use your content to train models.
Where it is kept
Everything is stored by Supabase in Tokyo, Japan, and the app's code that reads your projects runs on Vercel in Tokyo, Japan. Japan is outside Australia, and we are telling you so because the Privacy Act asks us to be clear when personal information goes overseas. The check that you are signed in runs in one of Vercel's regions around the world, normally the one nearest you, which may also be outside Australia. Some of the services below are in the United States.
Who else sees it
These services process information on our behalf. Each receives only what it needs for the job described.
| Service | What it does with your information | Where |
|---|---|---|
| Supabase | Stores everything in your projects, and your account. | Tokyo, Japan |
| Vercel | Runs the web app. Your requests and the pages sent back pass through it. | Tokyo, Japan, where the app's code runs. A request first reaches Vercel at its location nearest you, anywhere in the world, and the check that you are signed in runs in one of Vercel's regions around the world, normally the one nearest you. Vercel is a United States company and may also process information in the United States. |
| Anthropic | Judges evidence against a step's check, checks readings pasted on a distribution channel, answers questions about a step, asks the questions in a new idea's interview and in the conversation about choosing channels, drafts a brief from the interview and any research report you paste, assesses that brief, argues it with you, writes the steps only your brief can supply when you agree the plan, and, if you run catch-up, judges how far your repository already is. If you run research on a brief, it also searches the web in your brief's words and reads the pages it finds, so those sites see Anthropic's requests, not yours. Receives the step's or channel's text and whatever you submitted, pasted, asked or answered, the parts of your brief a research run looks into, and for catch-up the short facts it sends about your repository's files: whether each is there, its length, and its first lines with anything shaped like a key cut out. | United States |
| Stripe (Link) | Takes payment for Camino's plans, as the seller on your receipt, and tells Camino which plan you bought and the date it is paid until. It receives what you type into its checkout; Camino receives only its ids for your customer record and subscription, and those dates. | United States, and wherever Stripe processes payments |
| Resend | Sends email: the weekly digest. Receives your address and the email's contents. | United States |
| Sentry | Records errors so they can be fixed: what failed, where in the code, and the address of the page or request without its query. Set to send no request body, cookie, credential or account details. | United States |
| PostHog | Counts a handful of product moments — signing in, creating a project, a step being verified — against your account id, and which pages are viewed, with project names and anything else in a page's address but the part that chooses what it shows taken out. No page titles and no session recording. Like any analytics a browser sends to, it receives your browser's IP address with each page view. | United States |
Sentry, PostHog and Resend are only used when they have been switched on; until then nothing is sent to them. Stripe sees you only if you buy a plan.
How long we keep it
For as long as your account exists. A project's history is designed so that nobody — including you — can quietly edit it while you are using Camino; that is what makes it worth trusting. It does not mean it is kept forever: deleting a project removes all of it, history included.
Seeing, correcting and deleting it
You can ask to see what we hold about you, to have it corrected, or to have your account or any project deleted. Write to the address at the bottom of this page. Deleting a project removes its plans, steps, evidence, verdicts, conversations and history, and we remove any files you uploaded to it at the same time. A waitlist address is removed on request, and every weekly email has a one-click way to stop.
If something goes wrong
If we have a data breach likely to cause you serious harm, we will tell you and the Office of the Australian Information Commissioner, as the law requires. If you are unhappy with how we have handled your information, tell us first; if that does not resolve it, you can complain to the OAIC.
Questions, corrections or deletion requests: no contact address has been set yet.