Skip to content
Aferiz

Privacy

What is stored, where it lives, for how long and who can reach it — written as what is true today. What is not yet formalized is called out as such.

This is not a legal privacy policy yet. It is the operating commitment a future policy will formalize — and that policy will not promise less than this page.

What stays on the platform

We keep the minimum that sustains the product:

Requirements and criteria
The normalized requirement text, its criteria, the objections and their answers.
Cited evidence
Code excerpts named by a verdict or an objection — the excerpt, not the whole file.
Runs
Logs, cost and result of every attestation.
Git mirror
A read copy of the repository, deletable on request. We keep no other copy of your code.
Account
Name, email and role of each member of the organization.

Where your code goes

To the runtime the project picks — and the screen says which one before anything runs. Point the platform at your own AI account and your code is read by your own license, with your own key: it does not pass through the platform’s LLM account. With a local model, on self-hosted, it never leaves your infrastructure.

Whenever reading uses an AI account of the platform itself, we say which provider it is — and a change of provider is communicated. A public subprocessor list is not published yet; when it is, it lives on this page.

Who can reach it

Inside the organization, access follows the roles — read-only means read-only. A stored credential comes back to no one, not even the admin who created it. Exporting per-person metrics is an admin action and is audited; verdict agreement has no per-person view on any surface, because a people metric must not become a ranking.

For how long

The audit trail is kept for at least twelve months and exports as JSON. Objections, acceptances and reports outlive the retention of the run that produced them — they are the record of what was agreed, and deleting them would destroy the proof of the negotiation. The full retention policy is on the list of what must exist before the first external customer; until then, this page is what there is.

Deletion

Deleting a project removes the mirrors, the worktrees, the artifacts and the associated records, keeping only the audit log, minimized.

What is not formalized yet

Legal privacy policy
This page states the operating truth; the legal document is still to be written.
Data processing agreement (DPA)
There is no signable one yet.
Subprocessor list
Not published yet.
Certifications
None. The security page says what exists in their place.

When anything here changes, it changes on this page first.