In plain language
- Reqursor Development uses AI models to write and review code changes for your tickets.
- You choose how the AI is powered, with a model provider account of your own or with Reqursor Credits.
- With your own account, your prompts go from your server straight to your provider and not through Reqursor. With credits, they pass through our relay, which does not store them, to Anthropic, whose own terms then apply.
- We never train AI models on your code, tickets or prompts.
- AI output can be wrong. Checks reduce the risk, and you decide what is merged and deployed.
- We do not claim any rights in the code the agent writes for you.
1. About this policy
This policy explains how Reqursor Development, the self-hosted AI development agent made by Reqursor Technologies ("Reqursor", "we", "us"), uses AI models: which models, through whose account, what data goes where, and who is responsible for what. It is part of the Terms of Service, and it works together with the Acceptable Use Policy and the Privacy Policy.
This policy describes the product as it is today. We update it when the product changes, and the date and revision number at the top show when it last changed.
2. What the AI does in Reqursor Development
For each ticket you give it, Reqursor Development works through a series of steps, each in a fresh AI session:
- it implements the change on its own branch, never on a protected branch
- it runs the built-in checks (a secret scan, a scan for unfinished code, a dependency policy and a limit on the size of the change) and any build, type, lint and test commands you have configured, which stay off until you set them
- it reviews the change against the ticket's criteria, and each criterion needs evidence from the code
- it fixes problems it finds, up to a limit you set
- it has an independent verifier look at the result, and it runs a security scan whose findings at or above the severity you set block the change
The software's own rules make the decision to ship. They take the AI's review and the independent verifier's verdict as inputs, and a failing check always blocks a change, whatever the AI says. A change that is not shipped goes to a person with the reasons. Pushing to your git remote is off by default, and you can require a person to approve every change before it is committed. If you switch on Autopilot, the software starts tickets by itself during the working hours you set.
3. Which AI models are used and through whose account
Reqursor Development calls AI models in one of two ways, and you choose which one each installation uses.
Your own model provider account. You connect an account that you set up yourself:
- an Anthropic API key, to use Claude from Anthropic
- your own Amazon Bedrock, Google Vertex AI or Microsoft Foundry account with access to Claude
- as a beta option, Kimi from Moonshot AI, with your own key. It is off unless your license includes it and you switch it on for a project after reading a disclosure (see section 6).
With your own account, your agreement with the provider governs the AI. Your use of Claude falls under your own agreement with Anthropic, or with the cloud provider you use, and we are not a party to that agreement. You pay the provider directly, and we do not receive your provider bill. The software meters usage locally to show you costs and to apply the spending limits you set.
Reqursor Credits. You pay us for model usage with credits, and we provide access to the model. We make the requests to our model provider with our own account, and the provider's terms with us apply. Credits are available to paid licenses that are billed online. They are not part of the trial, and an installation on an offline license file cannot use them. The models we offer through credits are listed in the product and in the license portal. At this time they are Claude models from Anthropic. We do not offer Kimi through credits. If we add a provider, we publish it in this policy and in the Privacy Policy before we send any prompt to it.
In both cases:
- The provider's usage policies apply to what you ask the agent to do.
- Signing in with a Claude subscription instead of an API key is not available.
- Each provider is responsible for its own models, availability, pricing and output. As the Terms of Service set out, we are not liable for the acts, output or outages of a provider.
4. What data goes where
Reqursor Development sends your code and ticket text only to the destinations you choose:
- Your model provider, or our relay. A prompt contains the ticket text, your project instructions (the "invariants" you set), the files the agent reads and the changes it reviews. With your own account it goes from your server directly to your provider, and it does not pass through Reqursor. With Reqursor Credits it goes to our relay first, and the relay passes it on to the model provider (see section 7).
- Your git remote, where you let the agent push branches or open pull requests.
- The integrations you connect, such as your tracker, email, Slack or webhooks, which get the updates you switch on. These carry ticket titles and outcomes, not your code.
Apart from your prompts in credits mode, the only things the software itself sends to Reqursor are license and credit information, as the Privacy Policy describes: a daily license check, the signed release list, the release files you choose to download, credit reservations and usage records, and the actions you start yourself, such as activating a license. These never contain your code, ticket text, prompts or model output. We also switch off the AI tooling's non-essential traffic, such as its own telemetry and update checks, through the setting its maker provides, so that model traffic goes through the local gateway.
We never use your code, tickets or prompts to train AI models. With your own account, we do not receive them. With credits, our relay does not store them. If you send us material yourself, for example in a support request or a diagnostics bundle, the Privacy Policy applies to it.
Your own data on your server stays there: your tickets, run history, audit log and encrypted secrets. Run logs and artifacts are deleted after 90 days by default, and you can change that period. Your credentials for your own model provider stay on your server, encrypted. The agent is not given them: a local gateway holds them and hands each stage a short-lived token. Where the agent runs without isolation (see section 8), a command it runs can still read what the account running the software can read.
5. What your provider does with your data
With your own account, what the provider does with your prompts and the model's output, including how long it keeps them, whether it uses them to train models and where it processes them, is set by your agreement with that provider. We cannot promise more than they do. Before you connect a provider, read its terms and data processing terms, and choose the plan that fits your needs.
With Reqursor Credits, the model provider is Anthropic, working under its commercial terms with us. Under its commercial terms, Anthropic states that it does not train its models on data from its API customers. Anthropic's terms, not ours, govern what it does with the requests it receives, and it may keep requests and answers for a limited time under those terms. It may process data outside the European Economic Area, and we rely on the safeguards that data protection law allows. We do not have a zero-retention agreement with Anthropic. If you work with sensitive code or personal data, check that these arrangements give you the protection you need, and use your own account if you need a direct agreement with a provider.
6. Beta models: Kimi from Moonshot AI
Kimi is a beta option with your own key, and it is not part of the standard setup. Before a project can use it, the product shows a disclosure that you must accept for that project. At the time of writing, the disclosure says that:
- data goes to Moonshot AI's servers at api.moonshot.ai
- Moonshot AI processes and stores it in Singapore, which has no EU adequacy decision
- Moonshot AI's terms allow it to use prompts and outputs to improve its models unless otherwise agreed in writing
- we have found no data processing agreement with Moonshot AI
Use this option only for code and data you are free to share on those terms. If this changes, we update the disclosure in the product and this policy.
7. Reqursor Credits and our relay
When you use Reqursor Credits, the local gateway of your installation sends each model request to our relay at inference.reqursor.com, and the relay forwards it to the model provider with our provider account. We act as your processor for the content of these requests, with Anthropic as our sub-processor, and you are the controller of any personal data in them. Our Data Processing Agreement covers this processing and applies automatically, and our sub-processor list names the providers involved. For the usage records, we are the controller.
- Prompts and answers are not stored. The relay reads a request in memory to check it and to count the usage, and it does not keep the request or the model's answer. It keeps no copy of your code or ticket text.
- What the relay keeps. It keeps usage records: identifiers, the model, the stage, token counts, the outcome and the time. These records carry opaque references for the run, ticket and project, not their names, and never code or ticket text. The relay deletes delivered records after 7 days, and its access logs, which hold the IP address of the connecting server, the time, the method, the route, the status, the duration and a request ID, but never a body, a query string or a header value, are kept for at most 30 days. A record that our license server rejects stays on the relay, with identifiers and token counts only, until we have reviewed and deleted it.
- What the license server keeps. The usage records are sent to our license server, which prices them and updates your credit balance. The license server keeps them, together with your credit and billing records, as the retention section of the Privacy Policy describes.
- Limits and checks. The relay accepts only the standard fields of a model request and refuses the rest, including tools that run on the provider's side and links to outside files. It applies request and spending limits per license. It does not scan the content of your prompts for secrets. Keep secrets out of tickets and code that you send.
- Kill switch. We can switch the relay off for all licenses or pause the use of credits for one license, for example when there are signs of abuse. The software then pauses the tickets that depend on credits.
- Who is involved. Besides us, the model provider (Anthropic) and our hosting provider handle the requests. The sub-processor list and the Privacy Policy name them.
If you do not want your prompts to pass through our relay, use your own model provider account. Nothing in the software requires credits.
8. Your responsibilities
You are responsible for how you use AI in Reqursor Development. In particular, you:
- Review the output. You remain responsible for reviewing, testing, deploying and using every change. Use approvals, protected branches and your own checks in a way that fits the risk of your code.
- Decide what the AI may see and reach. Do not give the agent code, data or credentials that it does not need, and do not send data that you are not allowed to send to a provider or to our relay.
- Choose the deployment carefully. Isolation of the agent depends on how you run the software. On Windows and in process-only mode, the agent has no isolation from the host. Use a dedicated machine, and read the documentation and the product's security page.
- Watch costs. Set spending limits per ticket, day, month and project, and keep an eye on your provider bill or your credit balance.
- Follow the law. Laws on AI, such as the EU AI Act, and rules in your sector can place duties on you as the business that uses AI. You are responsible for yours. We do not make claims about how your use is classified.
- Follow the rules of your provider and our Acceptable Use Policy.
9. Limits of AI output
AI models make mistakes. Output can be wrong, incomplete, insecure or out of date, and it can look convincing when it is not. The same instruction can give different results at different times. The checks in Reqursor Development, such as tests, reviews and scans, reduce the risk but cannot remove it. They do not catch every subtle error.
The software also does not defend against everything. It cannot protect you from a compromised provider or host, from your own administrators, from a deployment without isolation, from data that the agent sends where it is allowed to, or from errors that the checks do not see. The protections are described in the documentation and on the product's security page.
We do not guarantee that AI output is correct, secure, complete, free of third-party rights or fit for a purpose. Credits used by a run are not refunded because the result was wrong, as the Refund, Cancellation and Credits Policy says. Our liability is limited as the Terms of Service say.
10. Prompt injection and untrusted content
Tickets, issue comments, repositories and web pages can contain instructions meant to steer the AI. Reqursor Development marks ticket text as external content, tells the model not to follow instructions in it, and logs tickets that look suspicious in the audit log. This helps, but it is a safeguard and not a guarantee, and it flags without blocking. Treat tickets from people outside your team as untrusted, and keep the agent's access as small as you can.
11. Who owns the output
You keep all rights in your code, tickets and other data. We claim no rights in the code changes that Reqursor Development produces for you. Rights in AI-generated output are not settled in every country, and your provider's terms may also apply to it. We do not promise that you will hold rights in AI output, or that it does not resemble third-party material. Review licensing and provenance where it matters to you.
12. Questions and changes
If you have questions about how AI is used in Reqursor Development, contact us:
- Legal: [email protected]
- Privacy: [email protected]
- Anything else: [email protected]
- Contact form: reqursor.com/contact
We may update this policy when the product, our providers or the law change. We tell customers about material changes in advance, as the Terms of Service describe. Reqursor Technologies, Rotterdam, The Netherlands. Chamber of Commerce (KvK) number: 42184274. Dutch law applies to this policy, the CISG does not apply, and the District Court of Rotterdam (Rechtbank Rotterdam) has exclusive jurisdiction, as the Terms of Service state.
Legal Contact
[email protected] · Reqursor Technologies, Rotterdam, The Netherlands