$ cat /legal/privacy.txt

Privacy Policy

Last updated: August 2026. This is a placeholder policy and will be replaced with reviewed legal text before general availability.

1. What we collect

  • Account and contact data: name, work email, and company when you register or contact us.
  • Repository data: source code, diffs, and CI metadata you authorize us to access, processed to provide the scanning and patching service.
  • Usage data: logs and telemetry about how the Service is used, for reliability and abuse prevention.

2. What we don't do

  • We do not sell your data.
  • We do not use your private source code to train models for other customers.
  • We do not retain repository data after you disconnect the integration, except as required by law or for backup cycles of up to 30 days.

3. How we use data

We use the data above to operate and improve the Service, respond to requests, and meet legal obligations. Findings and scan results are visible only to your organization.

4. Subprocessors and storage

We use a small number of infrastructure providers (cloud hosting, email delivery) bound by data-processing agreements. Data is encrypted in transit and at rest. Enterprise customers may request on-prem runners, in which case repository data never leaves their environment.

5. Your rights

You may request access, correction, export, or deletion of your personal data at any time by emailing security@adversarial.sh. We respond within 30 days.

6. Cookies

This marketing site sets no tracking cookies. The authenticated product uses strictly necessary session cookies only.

7. Changes and contact

We will announce material changes to this policy before they take effect. Privacy questions and security disclosures: security@adversarial.sh.