Privacy

What we receive, and what we never ask for.

1ADK is a product about understanding software you own. That makes what it does and does not touch the most important thing on this page, so it is first.

What 1ADK never asks for

  • Access to GitHub, GitLab, Bitbucket or any other repository host.
  • SSH keys, deploy keys, personal access tokens or infrastructure credentials.
  • An archive, clone or upload of your source code.
  • Production credentials or the contents of your .env.
  • A database dump.
  • An inbound connection to your machine or your network.

None of these is optional-but-recommended. The product has no code that would use them, and no screen that would ask.

What 1ADK does receive

One thing: an Evidence Package. A coding agent you already use reads your system on your side and writes a structured description of it — the names of components, what each is for, what it connects to, what data it handles, and what those conclusions are based on. Nothing in that description becomes part of your project until you have read it and approved it — and if you work by hand, you read the file itself before it leaves your machine.

The package format is deliberately made of typed fields and enumerations rather than free text, because every free-text field is a place a secret can hide. The few free-text fields that exist are short, and the server refuses a package that carries something that looks like a credential, a private key, or a block of source.

The honest limit

If you run the analysis with a cloud coding agent — Claude Code, Codex or similar — that agent reads your code, under its own terms and its own privacy policy. That is a boundary between you and them, and 1ADK cannot and does not speak for it. Choose a local model and the reading can stay entirely inside your own infrastructure.

We say this rather than promising that nobody else ever sees your source, which would be the more comfortable sentence and would not be true for most people's setup.

What is stored, and where

  • Your account — email address, the name you gave, your organization's name, and when you signed in. Passwords are stored only as a one-way hash and are never recoverable, by us or by anybody.
  • Your project's knowledge — what the Evidence Packages described, in a database file that belongs to that project alone. One project is one isolated store; no query can reach across two. Today an account is one person, so that person is the only one who can open it.
  • An audit trail — who did what, when, from which address. It records identifiers, counts, hashes and timestamps. It never records package contents, evidence bodies, credentials or repository content, and it cannot be edited afterwards.
  • Activation events — how far your account got through the product: registered, created a project, read what is known. No IP address, no user agent, no page URL, no referrer. It exists so we can tell where people get stuck, not who they are.
  • Where your account came from — recorded once, when the account is created, and never updated afterwards: which page of this website you first landed on, the page you were reading when you followed the link into the application, the name of the site that linked to you if there was one (linkedin.com, not the page or anything you searched for), and any campaign labels we ourselves put in the link. It is kept so we can tell which writing is worth continuing. No IP address, no user agent, no full referring address, no advertising identifier, and nothing you typed into a page. It travels in the address of the link you follow, where you can read it and remove it before you press Create account.

Everything runs on servers we operate in Europe. We do not sell data, we do not share it with advertisers, and there are no third-party trackers on this website — no analytics script, no advertising pixel, no session recorder.

The package file itself

A package that reaches 1ADK — uploaded by you, or sent by a coding agent you connected — is held in quarantine while it is checked, and while you decide whether to accept it. Once it has been read into your project — or refused, or discarded — the file is deleted. A refused package is deleted immediately, because a package refused for carrying something it should not is exactly the file you want gone soonest.

Who can see your project

You. Every lookup in the product starts from your organization membership rather than from a project identifier — knowing an id is not access — and today an account has exactly one member, the person who created it. When several people can share an account, membership will be what decides, and it will be something you grant.

We cannot browse your project's knowledge from the back office. The back office shows account-level facts — how many projects, how many analyses, which plan — and not what your system contains.

Taking it with you

You can download what 1ADK knows about a project, from the project page, whenever you like. It is the owner of the organization who takes it, the same person who can delete the project, and there is nobody outside your own team to ask, nothing to schedule and no ticket: it is one file, made while you wait, and taking a copy changes nothing about the project. It is Markdown — plain text, readable in any editor, with or without 1ADK.

What is in it is what the product shows you: what your system is made of, what talks to what, where your data comes to rest, what is recorded as risky and still open, and what nobody has established. Risks you have already decided — accepted or mitigated — and questions that are no longer open, whether they were answered, dismissed or found not to apply, are counts in the file rather than lists, because neither is outstanding work. The file says how many of each there were, so a project that has been worked on does not read as one nobody ever asked anything about. It also says which analysis it reflects and how much of your system that analysis actually opened, because a copy that did not say so would read as an account of all of it.

The export carries no source code and no passwords, keys or tokens. We never had the first, and the check that refuses the second on the way in runs again on the way out. Three other things are not in it, and we would rather say so than let you assume they were lost: the evidence behind each statement, which stays in the product; how the picture changed over time, since the file is the state after the most recent analysis; and anything about your account, which is not part of a project's knowledge. We do not keep the file after making it.

It is offered on the deletion page too, above the form, because taking a copy first is the point of having one: once the deletion has run there is nothing left to copy.

Getting rid of it

You can archive a project at any time, from the project page. An archived project stays readable, stops being counted against your plan, and nothing is deleted.

Deleting a project is yours to do, from the project page. The confirmation names what will be destroyed, read from that project rather than written as a general description: every generation of its Project Store, its scans, the packages it has received including anything still waiting in quarantine, and its backup copies. It counts the machines connected to that project too, and what ends for them is their access to it: nothing on a machine of yours is touched, because 1ADK never had access to it. You type the project's name to confirm. The work then runs in the background and the project leaves your list when it is finished. It cannot be undone.

Closing your account is yours to do too, from the plan page. Every project goes first, exactly the way deleting it on its own would delete it, and then the account itself and anybody whose only account it was. The one thing that can stop it is a subscription still being billed: on the day card payment is switched on, your card and your subscription are held by Stripe and not by us, so we will not cancel it on your behalf. You cancel it there, and then the account closes here.

Backups of a project are deleted with it, in the same operation. There is no window in which a project is gone from your account but still restorable from ours. What we will not claim is that every last copy everywhere vanishes in the same instant: we take ordinary operational snapshots of the account database, so that one server failure does not lose everybody's account at once. A snapshot taken before a deletion still holds that database's record of what was deleted — a project's name, its dates, what was run on it — but never what the project knew, which lives in files of its own and not in that database. A snapshot exists to bring a lost server back, and a deleted project is not restored from one.

What survives a deletion is the record that it happened: that the project or the account existed, who asked for it to go, and when. It names them by identifier, and it is kept for the reason any deletion record is kept — a deletion that leaves no trace of having happened is one nobody can check afterwards. Payments and invoices stay too; they are accounting records and we are required to keep them.

Two things in that record are not identifiers, and we would rather write them here than let you find them. Where you named something yourself, the name is in the entry about it: a machine you connect reports the name its agent was given, and that entry is not rewritten afterwards. And anything you wrote to us in your own words — a message about a plan, feedback you sent — is correspondence with your account rather than data about a project, so deleting one project does not delete it. Closing the account does: it goes with the account, together with the record of what you asked to buy.

None of this needs us any more, and there is no waiting period in front of it. The one part still done by hand is billing: if there is no billing page for us to send you to, write to info@1adk.com and a person will stop the billing, and then you close the account yourself. We have not set a limit on how long an account nobody uses is kept, and we are not going to print a number we have not decided; when there is one it will be written here before it applies to anybody.

Email

We send transactional email only: password resets, and a confirmation when you ask about a paid plan. There is no marketing list and no newsletter, so there is nothing to unsubscribe from.

Paying

Nothing on this site or in the product takes a card today, so there is no card number, expiry date or billing address anywhere in what we hold. When card payment is switched on it will be handled by Stripe: your card details go to them, and what reaches us is the fact that a subscription exists and its status.

Who to ask

1ADK is built and operated by Mikhail Piskunov. The company behind it, the one that receives payment and the one that decides what happens to your data, is FinMV SIA in Latvia.

  • Registered name — FinMV SIA
  • Registration number — 40203378371
  • Registered on — 8 February 2022
  • VAT — LV40203378371
  • Country of registration — Latvia

Write to info@1adk.com with anything about this page. It is read by a person, and every other address this site publishes arrives in the same mailbox. There is no telephone number and no postal address to give you: the company publishes neither.

Last updated 24 August 2026.

See what it produces first.

A finished project map, on a system we invented, built the same way yours would be.

Open the demonstration Build your own — free