Privacy Policy
Effective: November 2026 · v1.0
What we collect
- Account data via Clerk: email, name, and the OAuth provider you use to sign in (Google, GitHub, etc.).
- Wallet ledger and subscription state, stored per-user in our auth provider’s private metadata.
- Repositories and code artifacts you explicitly submit for scanning.
What we don’t do
- We do not train models on your code.
- We do not sell personal data to third parties.
- We do not retain submitted source longer than is needed to produce the report.
Subprocessors
Clerk (authentication), Vercel (hosting), Anthropic (analysis models), Stripe (payments — when enabled). Each is bound by a data-processing agreement.
Your rights
You can export or delete your account data at any time from Settings. For any other data request, email privacy@velosec.co.
Security
All traffic is HTTPS. Account passwords are managed by Clerk (bcrypt / argon2). Wallet ledger entries are append-only.