Terrestrial legal
Privacy Policy
Effective date: August 19, 2026
Version: 2026-08-19
Terrestrial is operated by InterContinental Digital Technologies Inc., a corporation based in New Brunswick, Canada.
What matters most
This Privacy Policy explains how Terrestrial handles personal information.
- What we collect: account and authentication information; prompts and conversations; project source, files, images and settings; collaboration and support communications; billing and integration information; device, browser, network and usage records; and information held in Terrestrial Cloud when a creator enables those features.
- Why we need it: to authenticate users; generate, edit, test, publish and host applications; provide collaboration and cloud features; process subscriptions and requested integrations; meter plans; prevent abuse; secure and debug the Service; provide support; and comply with law.
- Who receives it: depending on the features used, information may be processed by infrastructure and hosting providers, database and object-storage providers, AI gateways and model providers, GitHub, Stripe, deployment and email providers, security and authentication providers, creator-enabled services, and professional advisers.
- Important consequences and risks: prompts, files and images needed for an AI request may be sent to an AI provider; publishing or sharing can expose selected content to other people; providers may process information outside Canada; and no online service is completely secure.
- Generated Applications are separate: a person or organization that creates a Generated Application is responsible for the personal information that application independently collects and for providing its own privacy notice.
- No Meta advertising tracker is currently active: Terrestrial does not currently use Meta Pixel, Conversions API or another non-essential advertising tracker.
Do not put regulated or highly sensitive information in Terrestrial unless a separate written agreement expressly permits it.
This summary highlights key information. The complete Policy below provides more detail.
1. Who is responsible and what this Policy covers
InterContinental Digital Technologies Inc. operates Terrestrial and is responsible for personal information under its control. We have designated the Privacy Officer to receive access, correction, deletion, consent-withdrawal and complaint requests.
This Policy applies to personal information handled through the Terrestrial website, account and guest flows, builder, collaboration features, Terrestrial Cloud, previews, publication and hosting, billing, integrations, support and related operations.
This Policy does not automatically govern a Generated Application created by a Terrestrial customer. The creator of that application is responsible for explaining its own collection and use of personal information. Section 7 explains this distinction.
When you create an account or guest workspace, Terrestrial asks you to acknowledge this Policy separately from agreeing to the Terms of Service. That acknowledgment is not blanket consent to every possible use of information. We seek consent or rely on another legally permitted basis as appropriate to the particular collection, use or disclosure.
2. Information you provide
The information we receive depends on how you use Terrestrial.
Account, guest and authentication information
This may include:
- your name, email address and account profile;
- password-verification records and other authentication credentials;
- account, guest, session and recovery records;
- organization membership, role, invitation and ownership information;
- generated-app account information when you use an application’s Terrestrial Cloud authentication;
- communications needed for email verification or password recovery; and
- information supplied to verify your identity, authority or a privacy request.
Prompts, projects and collaboration
This may include:
- prompts, conversations, plans and generation instructions;
- project source code, files, images, screenshots, uploads and imported repositories or archives;
- project names, settings, runtime and publication configuration;
- comments, replies, mentions and other review communications;
- collaborator roles, invitations, presence and editing records;
- build, test, security-review and deployment choices;
- custom-domain and publication metadata; and
- information you include when asking for support.
Avoid including personal information in prompts, source files, screenshots or uploads unless it is reasonably necessary and you have authority to use it.
Integrations and secrets
If you enable an integration, we may receive or store configuration and authorization information such as:
- GitHub account, installation, repository and branch information;
- encrypted connection credentials or a fine-grained token used for a requested GitHub operation;
- deployment, domain, storage, authentication, anti-abuse, payment or email configuration;
- Terrestrial Cloud collection, bucket, function, schedule and webhook definitions; and
- credentials you intentionally place in designated encrypted secret controls.
Do not put secrets in ordinary source files, prompts, chat messages or collection records.
Billing and subscription information
This may include:
- selected plan and billing scope;
- checkout, customer and subscription identifiers;
- price and product identifiers;
- billing interval, amount, currency and tax information;
- subscription, payment, refund, return and entitlement status;
- purchase-consent and renewal/refund disclosure records; and
- bounded payment-provider event and reconciliation records.
Payment-card details entered in hosted checkout are handled by the payment provider. Terrestrial does not claim to store the full payment-card number or card-security code entered there.
Terrestrial Cloud and Generated Application information
When a project creator enables Terrestrial Cloud, the Service may store information collected through the Generated Application, including:
- app-user email addresses, authentication and session records;
- collection records and uploaded files;
- function inputs, bounded outputs and execution status;
- form submissions, order requests and other application records;
- security-filtered and aggregated error telemetry;
- payment, refund, return, exchange and fulfilment metadata; and
- information sent to a creator-enabled email, payment, AI, authentication or other service.
The exact fields depend on what the creator builds and enables. The creator is responsible for limiting collection and providing an appropriate notice to its end users.
Acceptance and transaction evidence
When you accept the Terms and acknowledge this Policy, we store an acceptance record containing your Terrestrial user identifier, the Terms and Privacy versions, cryptographic digests of the accepted documents, the acceptance source and time. The account-acceptance record does not contain a raw IP address, user agent, prompt or marketing identifier.
For a paid checkout, we may separately retain the checkout and payment-provider event identifiers, purchaser or organization reference, subscription reference, plan, price, versioned billing disclosure, amount, currency and acceptance time as transaction evidence.
3. Information collected through use and from other services
Device, browser, network and request information
When your browser or application communicates with Terrestrial, we may receive information such as:
- IP address or a sanitized client-address value supplied by an authorized edge provider;
- browser and device type;
- operating system;
- request time, route and response status;
- session, security and recovery identifiers; and
- information used to detect abuse, fraud, automated traffic or unauthorized access.
For some guest-recovery and abuse-prevention controls, device and network scopes are transformed into pseudonymous identifiers using a keyed hash. The underlying source identifier is not retained in the related allowance record.
Usage and operational records
We may collect or generate:
- account, project and feature activity;
- build, generation, deployment and publication status;
- model selection and aggregate token or usage counts;
- plan-metering and quota records;
- file versions, history and collaboration events;
- audit and security-review records;
- browser-test results and private test screenshots;
- bounded, security-filtered runtime error information;
- function, schedule, webhook and integration execution records; and
- support, incident and fraud-prevention records.
A prompt may be stored as project conversation history, but prompt text is not added to the separate model-routing telemetry described by the product.
Information returned by integrations
Connected services may return information needed to complete a requested operation, such as repository metadata from GitHub, checkout or subscription state from Stripe, deployment state from a hosting provider, verified identity information from an authentication provider, or delivery status from an email provider.
Published-site analytics
For successful published HTML document requests, Terrestrial stores daily aggregate page-view counts and paths. The published-site analytics table does not store cookies, IP addresses, user agents, referrers or visitor identifiers. Asset requests and unsuccessful page requests are not included in those view counts.
Other operational systems may process request and security information as described above; the analytics limitation applies specifically to the published-site analytics data.
4. How we use personal information
We use personal information for purposes that include:
- creating, authenticating, securing and recovering accounts and guest workspaces;
- generating, editing, testing, repairing, previewing, hosting and publishing projects;
- providing collaboration, review, version history, cloud collections, storage, functions and generated-app authentication;
- carrying out AI and other integration requests;
- processing checkout, subscriptions, payments, refunds and billing entitlements;
- sending requested transactional communications, verification or recovery messages;
- operating organization membership, roles, pooled plan limits and billing scope;
- measuring usage and enforcing plan, storage, generation, function and rate limits;
- preventing fraud, abuse, credential misuse and unauthorized access;
- diagnosing errors, maintaining the Service and responding to support requests;
- conducting security review, audit, backup, recovery and incident response;
- keeping contract, billing, tax, dispute and legal evidence;
- complying with legal obligations and responding to lawful requests; and
- communicating material Service, billing, security or policy changes.
If we want to use personal information for a materially different purpose, we will identify that purpose and obtain any new consent required by law before doing so.
5. AI processing
Terrestrial uses managed AI to provide generation, planning, editing, repair, visual review and related features.
Depending on the request, information sent for AI processing may include:
- prompts and recent project conversation;
- relevant project source and files;
- uploaded reference images;
- bounded preview images and redacted structural findings;
- runtime diagnostics treated as untrusted input; and
- instructions and context needed to complete the requested task.
This information may be sent through Vercel AI Gateway to the model provider selected for the request, which may include providers such as Anthropic, OpenAI, Moonshot AI or xAI, or may be sent to Anthropic directly where the direct provider is configured. Available providers can change as the Service changes.
Terrestrial stores project conversation, Output and bounded usage or job information as needed to operate the builder and its history. Some captured reference material may be processed ephemerally, while uploaded project attachments remain part of project history until deleted or the project lifecycle removes them.
AI providers process submitted information under their applicable agreements, terms and privacy practices. Provider retention, training and independent-use practices may differ. This Policy does not promise that every provider never retains information or never uses information for model improvement.
A project creator may also enable a separate Generated Application AI function, such as an OpenAI text or image function. In that case, application-user input is sent to the creator-selected provider under the creator’s configuration. The creator must disclose that processing to the application’s users.
Do not submit regulated or highly sensitive data for AI processing unless a separate written agreement expressly permits it.
6. Service providers and other disclosures
Depending on the features used, we may provide personal information to:
- infrastructure, hosting, content-delivery, database and object-storage providers;
- generation, build, browser-execution, monitoring and deployment providers;
- Vercel AI Gateway and the selected AI model provider, or Anthropic directly;
- GitHub for connected source-control operations;
- Stripe for Terrestrial subscriptions or creator-enabled hosted checkout;
- email-delivery providers for transactional, verification, recovery or creator-configured messages;
- authentication and security providers, including providers enabled by a project creator;
- creator-enabled services such as payment, email, AI, domain, deployment, storage and anti-abuse integrations;
- professional advisers such as lawyers, accountants, auditors and insurers; and
- another entity involved in a proposed or completed merger, financing, reorganization, asset sale or similar corporate transaction, subject to appropriate confidentiality and applicable law.
We may also disclose information:
- at your direction or with your consent;
- to authorized collaborators, organization members or Generated Application creators;
- to comply with law, court process or a lawful government request;
- to investigate fraud, abuse, security incidents or violations of the Terms;
- to protect the rights, safety and security of Terrestrial, users, providers or others; or
- to establish, exercise or defend a legal claim.
A third-party service may act only as our processor for a requested purpose, or it may independently determine some of its own purposes, depending on the service and transaction. Its own privacy policy applies to information under its independent control.
You may contact the Privacy Officer to ask for more information about provider categories and disclosures relevant to your information.
7. Published, shared and Generated Application content
When you publish an application, its public pages, assets, selected metadata and functionality can be accessed by other people. Public content may be copied, indexed or redistributed outside Terrestrial’s control.
Password-protected, member-only and private-preview links limit ordinary access but do not guarantee confidentiality. Anyone who receives a valid bearer preview link or password may be able to use it until it expires or is revoked.
When you invite collaborators, reviewers or organization members, the information and project Content available to them depends on their role. Removing access prevents future authorized access but may not remove copies a recipient already made.
A Generated Application may independently collect personal information from its users. The person or organization operating that application decides what to collect and why and is responsible for:
- providing its own privacy notice;
- obtaining any required consent;
- responding to end-user privacy requests;
- configuring collection access, retention and deletion;
- selecting and disclosing integrations; and
- complying with applicable privacy, consumer and sector-specific law.
Terrestrial may process that information as a service provider to the creator and may process limited information for its own security, billing, legal and Service-operation purposes. If you are an end user of a Generated Application, contact the application creator first about its collection and use of your information. We may redirect a request to the creator when the creator controls the relevant information.
A Generated Application may also use browser storage, cookies, analytics or third-party services selected or coded by its creator. Those practices are not described solely by this Terrestrial Policy.
8. Processing outside New Brunswick and Canada
Terrestrial and its service providers may process or store information outside New Brunswick or outside Canada. The location depends on the provider, integration, model, deployment and feature used.
Information processed in another country may be subject to that country’s laws and may be accessible to courts, governments or law-enforcement authorities under lawful process there.
Where applicable law makes Terrestrial accountable for personal information transferred to a service provider for processing, we remain accountable and use contractual or other appropriate means to require a comparable level of protection. This does not prevent a foreign authority from applying its lawful powers to a provider in that jurisdiction.
Contact the Privacy Officer if you want more information about cross-border processing relevant to your use of the Service.
9. Retention, deletion and browser-held recovery data
We retain personal information only as long as reasonably needed for the purposes described in this Policy, including providing the Service, maintaining security and audit records, resolving disputes, enforcing agreements and meeting legal, tax, accounting and payment obligations.
Retention periods vary by record and context. For example:
- account and active project information is generally retained while needed to provide the account or project;
- project deletion controls remove active project data as implemented, but deletion may not immediately remove recipients’ copies, publication caches, provider records, limited backups or legal and security evidence;
- guest workspace and recovery information is temporary and may be removed when its guest lifecycle or recovery eligibility ends;
- billing, payment, refund and transaction evidence may be retained for legal, accounting, fraud-prevention and dispute purposes;
- acceptance, security, audit, incident and abuse-prevention records may be retained for their applicable evidentiary or operational period;
- creator-configured retention may apply to some Terrestrial Cloud records, but it does not override records that must be kept for security, payment or legal purposes; and
- aggregate or de-identified information may be retained where it no longer identifies an individual.
Deleting an account may remove or detach account references in different ways depending on the record. For example, an acceptance record tied solely to a deleted identity may be removed, while purchase evidence may remain with the purchaser reference detached so that transaction evidence is not erased.
The editor can keep encrypted browser recovery information in IndexedDB for the current tab, a selected seven-day or 30-day period, or until it is explicitly cleared, depending on the selected setting. This information is stored on the browser device and may remain until the applicable retention or clear action runs. Clearing server data does not necessarily clear every browser-held copy immediately.
Limited backups, provider caches and disaster-recovery copies may remain until rotated or no longer reasonably needed. We do not promise an instant deletion or one universal deletion deadline.
To request account-level access, correction or deletion, contact the Privacy Officer. We may verify identity and may deny or limit deletion where retention is required or permitted for security, fraud prevention, payment, dispute, legal or other lawful purposes.
10. Safeguards
We use administrative, technical and organizational safeguards intended to be appropriate to the sensitivity and context of the information.
Depending on the system, safeguards may include:
- role-based and project-scoped access controls;
- restricted access for workers and service components;
- encryption for designated secrets and browser recovery data;
- one-way hashing or keyed hashing for certain tokens and pseudonymous identifiers;
- bounded inputs, outputs, logs and provider responses;
- redaction or filtering of selected error and security records;
- audit, monitoring, rate-limit and abuse-prevention controls; and
- backup and recovery procedures.
Safeguards reduce risk but cannot eliminate it. No online service, transmission, encryption method or storage system is perfectly secure. You are responsible for protecting your devices, credentials and project permissions and for maintaining independent copies of important work.
Do not submit information that these Terms prohibit or that requires safeguards or regulatory commitments not covered by a separate written agreement.
11. Your choices and privacy rights
Subject to applicable law, you may ask us to:
- confirm whether we hold personal information about you;
- provide access to that information and an account of its use and disclosure;
- correct information that is inaccurate or incomplete;
- explain relevant processing purposes, provider categories and safeguards;
- delete personal information that is no longer needed or that may lawfully be deleted;
- withdraw consent where consent is the basis for processing; or
- investigate a privacy complaint.
Withdrawal of consent is subject to legal or contractual restrictions and reasonable notice. It may mean we cannot provide an account, guest recovery, AI request, integration or other feature that depends on the information.
We may request enough information to verify your identity and locate the relevant records. Information supplied for verification will be used for that purpose. Access may be limited where law permits or requires, including to protect another person’s information, security, confidential commercial information or legal privilege.
You can also:
- manage collaborators, publication access and integrations through available project controls;
- clear or change supported browser recovery retention settings;
- cancel future subscription renewals through billing controls; and
- use browser settings to clear cookies and browser storage, understanding that blocking essential storage can prevent login, guest recovery, preferences, previews or other requested features from working.
Please raise a privacy complaint with the Privacy Officer first so we can investigate it. If you are not satisfied, you may contact the Office of the Privacy Commissioner of Canada.
12. Cookies, browser storage, analytics and tracking
Essential cookies
Terrestrial uses cookies and similar records needed for requested functionality, including:
- account and application sessions;
- security and same-origin protections;
- guest-device binding and recovery;
- preview and protected published-site access; and
- requested preferences.
Some security-sensitive cookies are inaccessible to page scripts and use browser security attributes. Disabling them can prevent authentication, guest recovery, preview access or protected-site access.
Session storage and local storage
The browser may use session storage or local storage for drafts, selected files, preferences, temporary workflow state and static or no-runtime Generated Application fallbacks. A Generated Application may also use storage through code selected by its creator.
Encrypted IndexedDB editor recovery
Terrestrial’s collaborative editor may store encrypted recovery information in IndexedDB so unsent edits can survive refreshes, file changes or disconnections. The browser uses an account-scoped, non-exportable key for this recovery data. A valid current server authorization is still required before cached source is displayed.
Available settings may retain recovery data for only the current tab, seven days, 30 days or until cleared. Encryption and access checks reduce risk but do not make a shared or compromised device risk-free.
Pseudonymous abuse-prevention identifiers
Terrestrial may derive keyed-hash identifiers from guest device or network scopes for guest recovery, rate limits and abuse prevention. These identifiers are designed to avoid persisting the underlying source identifier in the related guest allowance record. They are security controls, not advertising identifiers.
Published-site analytics
Terrestrial stores daily aggregate counts and paths for successful published HTML page views. The analytics table does not store cookies, IP addresses, user agents, referrers or visitor identifiers.
Advertising tracking
Terrestrial does not currently use Meta Pixel, Meta Conversions API or another non-essential advertising or attribution tracker.
Before introducing a non-essential advertising tracker, we will revise this Policy and the applicable consent experience. Such a tracker will remain disabled until affirmative consent has been obtained where required.
This statement concerns the Terrestrial Service itself. A Generated Application creator may separately add its own analytics or tracking and must disclose and obtain consent for that activity as required by law.
13. Children
Terrestrial is intended only for people who have reached the age of majority where they live and can enter a binding agreement. It is not directed to children, and children may not create Terrestrial accounts or guest workspaces.
If you are a parent or guardian and believe a child improperly submitted personal information to Terrestrial, contact the Privacy Officer. We may ask for reasonable information to verify the request and locate the relevant records.
Generated Application creators must not use Terrestrial to process children’s personal information unless a separate written agreement expressly permits it and the creator has satisfied all applicable consent, notice, safeguarding and legal requirements.
14. Changes and contact
We may update this Policy as the Service, providers, law or our privacy practices change.
We will communicate a material change through the Service, the email associated with an account or another appropriate method before it takes effect when required. If a change introduces a materially new purpose, disclosure or consequence, we will obtain any new consent required by law.
Questions, access or correction requests, deletion requests, consent withdrawals and privacy complaints may be sent to:
Privacy Officer InterContinental Digital Technologies Inc. (Terrestrial) New Brunswick, Canada privacy@useterrestrial.com Our mailing address is available upon request at the email address above.
We may require reasonable verification before disclosing, correcting or deleting personal information.