Privacy policy

SensCheck Governance — Core (the SDK, CLI, MCP and adapter packages, and the Cursor / Agent Plugin), published by TEKNOLED-G LIMITED ("we", "us").

_Last updated: 2026-10-02. DRAFT: have this reviewed by counsel before relying on it._

Short version

SensCheck Governance — Core runs entirely on your machine or in your own infrastructure. We do not collect, receive, store or sell any data from your use of it. There are no accounts, no telemetry, no analytics and no network calls made by the software.

What the software does with data

ComponentReadsWritesSends off your machine
@senscheck/governance-core, -mcp, adaptersthe effects, policies and provider responses you pass inreceipts only to the sink you configure (memory, console/stderr, or a file you choose)nothing
@senscheck/governance-clifiles in directories you point it at (audit), your senscheck.config.json, receipt files you name (explain)senscheck.config.json, an example file and a .gitignore entry (init)nothing
Plugin (skills, rule, commands)whatever your AI agent already has access to in your projectwhatever edits you ask the agent to makenothing by itself. See below

Receipts can contain identifiers such as principal IDs, effect IDs, verbs and resource names (for example file paths). They do not include effect parameters. You control where they are stored; protect them like any log.

AI agents and third parties

The plugin consists of instructions (skills, a rule and commands) that your AI coding agent (Cursor, ChatGPT/Codex or another) follows. Any data your agent sends to its model provider is governed by that provider's terms and privacy policy, not by us. We do not receive it.

If you choose to connect SensCheck Core to optional commercial services (for example a hosted policy or identity provider), those services have their own privacy terms.

Our websites and repository

The source code is hosted on GitHub. GitHub processes data about visitors and contributors under GitHub's own privacy statement. If you email us (for example to report a vulnerability), we use the information you send only to respond and act on your message, and keep it no longer than needed.

Your rights

Because we hold no personal data from your use of the software, there is nothing for us to export or delete. For anything we hold from correspondence, contact us to ask for access, correction or deletion; you may have rights under laws such as the GDPR/UK GDPR.

Children

The software is a developer tool and is not directed at children.

Changes

We will post changes in this file; the history is in the repository.

Contact

TEKNOLED-G LIMITED. security@teknoledg.com