Privacy policy
Packbat is local-first. Your raw agent sessions stay in the archive you choose, and every off-box copy is encrypted before it leaves your machine.
Scope
This policy covers the Packbat command-line application, packbat.dev, user-owned remote storage, and optional Packbat Cloud. Packbat is operated by Liam Vinberg.
Last updated: 18 July 2026.
Local archives
Packbat reads supported AI-agent session stores on your machine and writes verbatim, compressed archives to the local path you choose. The local archive, derived index, configuration, logs, and recovery material stay on your machine. Packbat does not send them to a Packbat service.
Packbat does not include product telemetry, behavioral analytics, advertising trackers, or data collection for training AI models. The public website does not add analytics or tracking cookies. Its hosting provider may process standard network request data needed to serve and secure the site.
Google Drive and Dropbox
If you connect Google Drive or Dropbox, Packbat requests the minimum storage access needed for the feature. Google Drive uses the drive.file scope, which limits Packbat to files it creates or that you explicitly open with it. Dropbox uses an App Folder, which confines Packbat to its dedicated folder. Packbat does not inspect unrelated files in either account.
Packbat uses this access only to write, list, read, and restore Packbat archive objects and indexes. Archive objects and indexes are encrypted on your machine before upload. Google or Dropbox can see storage metadata needed to provide the service, such as object names, sizes, timestamps, and API request metadata, but not the plaintext session contents or encrypted index payload.
OAuth access and refresh tokens are stored only in Packbat's private local configuration and sent to the selected provider when required to authorize storage operations. They are not sent to Packbat, included in the recovery kit, sold, shared for advertising, or used for model training.
Packbat's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Review the provider policies for more information: Google Privacy Policy and Dropbox Privacy Policy.
Optional Packbat Cloud
Packbat Cloud is optional. If you choose it, GitHub authenticates your account. Packbat stores your GitHub numeric account identifier, rotating CLI credential records, opaque machine identifiers, object names, sizes, checksums, storage accounting, and subscription state. It does not store your GitHub access token after the account exchange.
Cloud archive bytes and indexes are encrypted before upload. Packbat Cloud stores ciphertext only; the private recovery key remains with you and never reaches Packbat. Cloudflare provides the API, database, and object-storage infrastructure.
If you buy Packbat Cloud, Stripe processes payment details, billing name, address, tax information, and email. Packbat stores Stripe customer and subscription identifiers, plan interval, status, and timestamps, but does not receive or store card details, billing identity, or billing email.
Read the relevant provider policies: GitHub Privacy Statement, Cloudflare Privacy Policy, and Stripe Privacy Policy.
Sharing and operational data
Packbat does not sell personal data. It shares data only with a provider you direct it to use, with infrastructure providers needed to operate an optional service, when required by law, or when needed to protect users and the service from abuse. Packbat does not use Google or Dropbox user data for advertising, credit decisions, surveillance, or training generalized or personalized AI models.
Packbat Cloud keeps minimal exception-only operational logs for up to seven days. These logs may contain an internal account identifier and an error or enforcement reason, but never archive contents, OAuth tokens, recovery keys, or behavioral analytics.
Retention and deletion
Local archives and user-owned remote copies remain until you remove them from the storage you control. Local OAuth credentials remain until you unlink the destination, remove the private configuration, or revoke access in Google or Dropbox.
Packbat Cloud retains ciphertext while your subscription is active. After a lapse or cancellation, it keeps the account and ciphertext available for restore during a 90-day grace period, then deletes the stored objects and account records. Packbat Cloud also supports authenticated account deletion; it fences outstanding upload links before deleting ciphertext and database records.
Your choices and contact
You can use Packbat without an account or remote service. You can disconnect a remote, revoke its OAuth grant, delete data from storage you own, revoke a Packbat Cloud CLI credential, or delete the Cloud account. Depending on where you live, you may also have rights to access, correct, export, restrict, object to, or delete personal data Packbat controls.
For privacy questions or requests, open a GitHub issue. Do not include secrets, OAuth tokens, recovery keys, or raw session content in a public issue.
This policy will be updated when Packbat's data practices materially change. The date at the top will show the latest revision.