Legal
Privacy policy
Last updated July 15, 2026
What we collect
When you create an account we store your email address and a hashed password with our authentication provider (Supabase). Our database runs in the EU (Zürich region).
We use PostHog for product analytics (how the site and platform are used) and Sentry for error reporting. Both receive technical data such as browser type, pages visited and error traces. Transactional email — account confirmations, sign-in mail — is delivered through Brevo.
What we don’t do
We don’t sell your data, we don’t run third-party advertising, and we don’t collect more than the platform needs to operate.
Session records
When robot control sessions launch, every command sent to a robot is recorded in an append-only audit log tied to the account that sent it. This is a safety and accountability feature of the platform, not an analytics feature.
Your rights
You can request a copy or deletion of your account data at any time by contacting us at contact@twoleg.app. Deleting your account removes your personal data; audit records required for safety and legal reasons are retained in de-identified form.
Changes
If this policy changes materially we will note it here and, for significant changes, notify you by email.