1. Who this applies to
MainLayer is a business service. Organizations (“customers”) install the MainLayer endpoint agent on machines used by their developers and use the MainLayer portal to view the resulting data. The customer decides which developers are monitored, in which privacy mode, and for how long data is retained. MainLayer processes that data on the customer's behalf.
2. What we collect from developer machines
In the default metadata-only mode the agent sends:
- AI session lifecycle events: start, activity, idle, end, errors; the provider and, when exposed, the model.
- Repository identity as a fingerprint of the Git remote, plus whether it matches the organization's connected inventory. Branch names are sent as-is or hashed, per organization setting.
- Prompt metadata: length, a non-reversible fingerprint, locally computed features and risk labels. Not the prompt text.
- Tool and MCP call metadata: tool name, kind, duration, success. Diff statistics and hunk fingerprints for assistant-made edits. Not file contents.
- Device inventory: operating system, agent version, installed AI tools and their versions, adapter health, and a hashed host name.
- Policy decisions and their outcomes.
Organizations may enable a sanitized mode (locally redacted prompt features and snippets) or a content-enabled mode (raw prompt and code evidence for explicitly listed repositories). Both are off by default, require an administrator to opt in, and are recorded in the audit log.
3. What we never collect
- Keystrokes or mouse activity.
- Screen captures or recordings.
- Terminal command history.
- Activity in applications other than the supported AI coding tools.
- Raw prompts or source code in metadata-only mode.
“Active” in MainLayer means an active AI session, not a person at a keyboard. MainLayer does not produce rankings of individual developers.
4. Portal account data
For people who sign in to the portal we store name, work email, a password hash, organization memberships and roles, session records, and an audit trail of administrative actions.
5. How data is used and shared
Data is used solely to provide the service to the customer: dashboards, policy evaluation, attribution and outcome metrics, and support. We do not sell data, use it for advertising, or train models on customer data. Sub-processors are limited to the infrastructure providers that host the service; a current list is available on request.
6. Retention
Detailed telemetry events are retained for 30 days by default; daily aggregates for up to 24 months; audit events for at least 90 days. Customers can shorten these periods. Data is deleted within 30 days of a customer terminating the service.
7. Developer rights and transparency
Every monitored developer can open a personal page in the portal showing the data their organization can see about them, the privacy mode in effect and the last upload. Requests to access, correct or delete personal data should be directed to the customer organization, which controls the data; we assist customers in fulfilling them.
8. Security
See our Security page for the technical measures that protect this data.
9. Changes and contact
We will announce material changes to this policy to customer administrators before they take effect. Questions: [email protected].
