← Back to home

Privacy Policy

Last updated: August 2026

This Privacy Policy explains what information Caveman ("we", "our") collects when you use our README generation service, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).

Information We Collect

Account data. If you sign in with Google, we receive your email address and display name. We use this only for authentication, rate-limiting, and account management. We never post to or otherwise modify your Google or GitHub accounts.

Generation inputs. When you generate a README, we temporarily receive a repository URL or project description, plus a subset of your repository's source files (up to 25 files, up to 5,000 characters each) needed to write the README.

Third-Party AI Processing

To generate READMEs, the repository content described above is transmitted to Groq (a third-party AI inference provider) via their API. Groq processes the content only to produce the generated README text.

We do not permanently store, train on, or share your repository contents. We do not use your code to improve third-party models. The AI provider's handling of data is governed by its own privacy policy, but we only send the minimal content required for a single generation and receive the generated text back immediately.

Cookies and Local Storage

Caveman uses your browser's local storage to persist your authentication session and in-progress README drafts locally on your device. We do not use advertising cookies and we do not sell or share your personal data with advertisers.

Analytics

We collect aggregated, non-identifying usage metrics (page views, feature usage, timestamps) to understand how the product is used and to prevent abuse. Aggregated logs are retained for up to 30 days and are not sold.

Data Retention

Generated READMEs are not stored on our servers beyond the duration of the generation session. Local drafts in your browser remain until you clear them.

Data Transfers

We operate on cloud infrastructure and our AI provider (Groq) may process data on servers located outside your country of residence. Where applicable, we rely on appropriate safeguards, such as the EU Standard Contractual Clauses or the provider's adequacy certifications, for such international transfers.

Your Rights (GDPR/CCPA/CPRA)

You have the right to access, correct, and delete the personal data we hold about you, to object to or restrict certain processing, and to data portability. California residents have the right to know what personal information we collect and to opt out of any "sale" or "sharing" of personal information - we do not sell or share your personal data. To exercise any of these rights, email hello@caveman.dev and we will respond within 30 days.

Children's Privacy

Caveman is not directed at children under 13 and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

Security

We use encryption in transit (HTTPS) for all traffic to and from our servers. Access to any stored account data is restricted to authorized personnel and used only for support and abuse prevention.

Changes to This Policy

We may update this policy from time to time. Material changes will be reflected by a new "Last updated" date above. Continued use of the service after changes constitutes acceptance of the updated policy.

Contact

Questions about this policy or your data? Email hello@caveman.dev.