1. Who we are and what this covers
This policy explains how Veratex, Inc. ("Veratex", "we") handles personal data when you use veratex.ai or the Veratex service (the"Service"). If personal data appears in a repository you connect, such as a name in its commit history, you are the controller and we process that data on your instructions. This policy covers both situations.
2. Information we collect
- Account information. When you sign in with GitHub we receive your GitHub username, display name, email address, and avatar. We do not receive or store your GitHub password.
- Repository data. When you install the Veratex GitHub App, we access the repository metadata, issues, pull requests, and source code needed to run the jobs you configure. We process source code in temporary, isolated sandboxes. We keep job records, logs, diffs, and results so you can review Veratex's work.
- Billing information. Payments are processed by Stripe. We store your Stripe customer ID, subscription ID, and plan status. Your card details go directly to Stripe and never reach our servers.
- Usage and log data. We log request metadata, IP addresses, browser type, and dashboard actions to operate and secure the Service.
- Cookies. We use a single first-party session cookie to keep you signed in. We do not use advertising cookies or cross-site tracking.
3. How we use information
- To run jobs, open pull requests, and show you the results.
- To secure the Service, prevent abuse, and debug failures.
- To bill subscriptions and maintain account records.
- To communicate with you about the Service, such as security notices and material changes to terms or policies.
- To comply with legal obligations.
We do not sell or rent personal data. We do not share it for cross-context behavioral advertising. We also do not use your repository content to train machine-learning models. Model inference runs through the Anthropic API under terms that do not permit training on the submitted content.
4. Legal bases (EEA and UK)
Where the GDPR applies, we process personal data to perform our contract with you, pursue legitimate interests such as securing and improving the Service, and meet legal obligations such as keeping accounting and tax records. When we process repository content for you, your instructions govern that work.
5. Who we share it with (subprocessors)
The following providers help us run the Service. We share personal data with them under data-processing agreements:
| Provider | Function | Location |
|---|---|---|
| Vercel | Application hosting | United States |
| Neon | Database (accounts, jobs, logs) | United States |
| E2B | Isolated sandboxes where agent jobs run | United States |
| Anthropic | Model inference for agent runs | United States |
| Stripe | Payment processing | United States |
| GitHub | Source control and authentication | United States |
We may also disclose information when the law requires it, to protect Veratex or others, or as part of a merger, acquisition, or asset sale. This policy will continue to cover transferred data.
6. Data retention
We keep account data while your account is active. We keep job records, logs, and diffs so you can audit Veratex's work, then delete or anonymize them when we no longer need them. Source code in a sandbox is destroyed with that sandbox after the job. If you delete your account or uninstall the Veratex GitHub App, we delete the related personal data within 30 days, except for records we must retain for legal, billing, or security reasons.
7. Security
We encrypt data in transit with TLS and at rest. Agent jobs run in fresh, isolated sandboxes with short-lived, limited credentials. Our servers check every merge decision. The security page describes the architecture in detail. If a breach affects your personal data, we will notify you and the relevant authorities when the law requires it, including within the GDPR's 72-hour window where applicable.
8. International transfers
Veratex is based in the United States, where our subprocessors also handle data. For transfers from the EEA, UK, or Switzerland, we use safeguards such as the EU Standard Contractual Clauses with our subprocessors.
9. Your rights
Your local law may let you access, correct, delete, or export your personal data; restrict or object to some processing; or withdraw consent when we rely on it. California residents have corresponding rights under the CCPA/CPRA, including protection from discrimination for exercising those rights. We do not sell or share personal information as those terms are defined there. To make a request, email privacy@veratex.ai; we will respond within the legal deadline. You may also complain to your local supervisory authority.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the Service changes. We will notify you of material changes by email or through the Service before they take effect. The "Last updated" date above shows the current version.
12. Contact
Privacy questions and requests: privacy@veratex.ai.