This Privacy Policy describes how Midware Networks LLC ("Cycle," "we," "us") collects and uses personal data when you visit cycle.sh or use the Cycle platform (the "Service"). Cycle is a business tool: our customers are companies, and most personal data we handle belongs to the people who work in those companies' workspaces.
Questions or requests: privacy@cycle.sh.
1Two roles we play
- For account, billing, and website data, Cycle decides how and why the data is processed (we act as the data controller). That is what this policy covers.
- For the content our customers process through the Service — repository contents, NetSuite File Cabinet files and SDF objects, and query results — we act on our customer's instructions under our Terms of Service, which contain our data-processing commitments (Section 9 of the Terms). If your data appears in a customer's workspace (for example, you are a developer whose commits are synced), the workspace owner controls that data — contact them first; we will support their instructions.
2Information we collect
Account and profile. Name, email address, profile image, and workspace membership. Authentication is passwordless: we store passkey public keys (WebAuthn), one-time codes sent by email, and/or the account identifiers provided by the sign-in provider you choose (Google, GitHub, GitLab, or Bitbucket). We do not store passwords.
Billing. Billing contact, company name, billing address, and tax ID, processed with Stripe. Card numbers are held by Stripe, not by us. We store Stripe customer and subscription identifiers and payment status.
Connections. Credentials and certificates for the NetSuite accounts and Git repositories a workspace connects. These are stored encrypted at rest and are used only to operate the connection.
Operational records. Deployment and synchronization history and logs — including commit identifiers, commit titles, and committer names from connected repositories — configuration (branch mappings and other workspace settings), sync issue records, and webhook delivery records (which can include committer emails contained in the payload).
Customer code and files. The code and customizations the Service synchronizes live in your Git repository and your NetSuite account — not with us. We process file contents to operate synchronization and deployments, and may keep temporary copies (caches) to compute and compare changes; these are transient operational copies, not a system of record.
Session and security. IP address, browser/user-agent, approximate location (country) and network (ASN) for sessions, and anti-abuse signals from Cloudflare Turnstile.
Support and email. Messages you send us, and delivery/engagement metadata for transactional email we send.
Cookies. We use only cookies that are necessary for the Service to work (session/authentication, security). We do not use advertising or third-party analytics cookies. If that changes, we will update this policy and, where required, ask for consent.
3What we do NOT do
- We do not sell personal data, and we do not share it for advertising.
- We do not use your content or your data to train AI or machine-learning models (and will not without prior written permission from the customer).
- We do not read or modify our customers' NetSuite business records on our own initiative. Automated operations cover File Cabinet contents and SDF objects — including installing and automatically updating the Cycle Components in the account (a source-code file plus the script and deployment records that register it), as authorized in the Terms (Sections 3.2 and 3.3) — and anything else happens only at the customer's direction.
4How we use information
To provide and operate the Service (including executing the workflows customers configure); to secure it (authentication, abuse prevention, audit); to bill and manage subscriptions; to send transactional and service email (delivered via Amazon SES); to provide support; to improve the Service using aggregated, anonymized usage information; and to comply with law.
5AI assistants (MCP)
Customers can connect their own AI assistant to the Cycle MCP server. When they do, data the assistant reads — including query results from the customer's NetSuite account — flows to the customer's AI provider under the customer's own agreement with that provider. Cycle does not send customer content to AI providers on its own initiative.
7Where data is processed
Cycle is operated from the United States, and data is stored on infrastructure in the United States (primarily the New York region). If you use the Service from outside the U.S., you are transferring data to the U.S., where laws may differ from those of your jurisdiction.
8Security
We maintain commercially reasonable safeguards, including: encryption in transit (TLS); field-level AES-256 encryption at rest for Connected Account credentials; database storage encrypted at rest by our managed database provider; passwordless authentication (passkeys, email codes, OAuth); rate limiting, WAF, and bot protection; hardened container images with regular updates and vulnerability scanning; software testing at critical points; and deployment execution in isolated, ephemeral environments. Internal access to customer data is restricted to authorized personnel who need it to operate and support the Service. No method of transmission or storage is completely secure; we cannot guarantee absolute security. If an incident requires notice, we will notify affected customers without undue delay (see Terms, Section 9.7).
9Retention
We keep account and workspace data while the account is active. After account closure, we delete customer data within 30 days and from backups within 90 days, except where the law requires longer retention (for example, billing records for tax purposes). Transient processing artifacts (queues, and caches used to move and compare files during synchronization) are short-lived by design: in-memory cache entries expire within hours, and any spillover storage is cleaned up within days by automatic expiration rules.
10Your choices and rights
- Access, correction, deletion. Email privacy@cycle.sh to request a copy, correction, or deletion of your personal data. If the data belongs to a customer's workspace, we will route the request through the workspace owner, consistent with our Terms.
- Account deletion. Closing the account triggers the retention schedule in Section 9.
- Email. Transactional/service emails are part of operating the Service. If we ever send marketing email, it will include an unsubscribe option.
- Local law. Where a data-protection law applies to Cycle's processing of your personal data, we will honor requests that are valid under that law. This policy does not grant rights beyond those that applicable law requires.
11Business use; children
The Service is for business use and is not directed to consumers or to anyone under 18. We do not knowingly collect data from children.
12Changes to this policy
We will post updates at cycle.sh/privacy with a new effective date, and give notice of material changes (email and/or in-app) at least 30 days before they take effect.
13Contact
Midware Networks LLC · 8 The Green, Ste B, Dover, DE 19901, United States.
Privacy requests: privacy@cycle.sh · Legal notices: legal@cycle.sh