Wren is in Alpha — free to use while we're building. See planned pricing →
TLS everywhere

All traffic between the Roblox Studio plugin and our servers uses TLS 1.2+. Your prompts and diffs are never sent unencrypted.

No plaintext passwords

Passwords are hashed with bcrypt before storage. We never log or store passwords in plaintext. Password reset links are time-limited and single-use.

No model training on your code

Session data — including prompts, file contents, and diffs — is not used to train AI models. We do not opt you in to any training data programs without your consent.

Data minimization

We collect only what we need to operate the Service. No behavioral fingerprinting, no cross-site tracking, no selling data to advertisers.

Session isolation

Your sessions are isolated per account. No other user can see your prompts, diffs, or history. Sessions are authenticated with signed tokens, not shared IDs.

Responsible disclosure

Found a vulnerability? We welcome responsible disclosure. See the disclosure section below.

Transparency

What happens when Wren runs a job.

Here's the exact data path for an agent run so you know what goes where.

Infrastructure

How we're built.

Hosting

ScriptWEAVER's backend is hosted on servers in the continental United States. Data is not transferred outside the US without disclosure. We use a reputable cloud infrastructure provider with physical security, redundancy, and managed patching.

Access Controls

Production database access is restricted to a minimal set of internal services. Human access to production data requires multi-factor authentication and is logged. We follow least-privilege principles: engineers have access only to what their role requires.

Dependency Management

We maintain an inventory of third-party dependencies and monitor for known vulnerabilities. Critical dependencies are patched within 72 hours of a disclosed CVE. We avoid dependencies with histories of malicious supply-chain behavior.

Incident Response

In the event of a data breach or security incident, we will notify affected users by email within 72 hours of becoming aware of the incident, as required by applicable law. We will clearly describe what happened, what data was affected, and what we are doing about it.

AI model provider commitments.

Wren routes requests to third-party AI model providers. Here's what we require of them.

No training on API inputs without consent

All AI model providers we use under API agreements prohibit using your session data for training their foundation models without your consent.

Data processing agreements in place

We maintain active DPAs with all AI providers that process user data, documenting permitted uses and security obligations.

US-based processing

We select provider endpoints that process data in the United States and document this in our privacy notices.

Responsible Disclosure

Found a vulnerability?

We appreciate researchers who responsibly disclose security issues. If you've found a vulnerability in ScriptWEAVER's web app, API, plugin, or infrastructure, please email us before public disclosure so we have time to patch it.

We will acknowledge your report within 48 hours
We will keep you updated on remediation progress
We will credit you in our disclosure if you wish
We will not pursue legal action for good-faith disclosure
Contact: security@scriptweaver.example.com
PGP key available on request.

Please do not test against user accounts other than your own. Automated scanning tools may trigger rate limiting or temporary account suspension.

Questions about security?

If something isn't answered here, we're happy to explain our practices further.

security@scriptweaver.example.com Privacy Policy →