Privacy
What is stored, where it lives, for how long and who can reach it — written as what is true today. What is not yet formalized is called out as such.
This is not a legal privacy policy yet. It is the operating commitment a future policy will formalize — and that policy will not promise less than this page.
What stays on the platform
We keep the minimum that sustains the product:
- Requirements and criteria
- The normalized requirement text, its criteria, the objections and their answers.
- Cited evidence
- Code excerpts named by a verdict or an objection — the excerpt, not the whole file.
- Runs
- Logs, cost and result of every attestation.
- Git mirror
- A read copy of the repository, deletable on request. We keep no other copy of your code.
- Account
- Name, email and role of each member of the organization.
Where your code goes
To the runtime the project picks — and the screen says which one before anything runs. Point the platform at your own AI account and your code is read by your own license, with your own key: it does not pass through the platform’s LLM account. With a local model, on self-hosted, it never leaves your infrastructure.
Whenever reading uses an AI account of the platform itself, we say which provider it is — and a change of provider is communicated. A public subprocessor list is not published yet; when it is, it lives on this page.
Who can reach it
Inside the organization, access follows the roles — read-only means read-only. A stored credential comes back to no one, not even the admin who created it. Exporting per-person metrics is an admin action and is audited; verdict agreement has no per-person view on any surface, because a people metric must not become a ranking.
For how long
The audit trail is kept for at least twelve months and exports as JSON. Objections, acceptances and reports outlive the retention of the run that produced them — they are the record of what was agreed, and deleting them would destroy the proof of the negotiation. The full retention policy is on the list of what must exist before the first external customer; until then, this page is what there is.
Deletion
Deleting a project removes the mirrors, the worktrees, the artifacts and the associated records, keeping only the audit log, minimized.
What is not formalized yet
- Legal privacy policy
- This page states the operating truth; the legal document is still to be written.
- Data processing agreement (DPA)
- There is no signable one yet.
- Subprocessor list
- Not published yet.
- Certifications
- None. The security page says what exists in their place.
When anything here changes, it changes on this page first.