Privacy Policy
Version 1.2 · Effective 2026-09-29 · Operated by VISNRY Entertainment
1. What we collect
- Email address, collected when you sign up (every plan, including Free) and used to issue your API key, send sign-in links, security notices and, on paid plans, billing notices.
- Governance audit metadata for each file governed: timestamp, file path, content hash (SHA-256), critic domains run, verdict (PASS / WARN / GATE), finding titles and line numbers, duration, and the agent/tool that made the request. We do not store the content of your source files, see section 2.
- API key identifiers: a SHA-256 hash of each issued key, its label, creation/expiry and last-used time. Plaintext keys are never stored.
- Account and team state: tenant ID, plan tier, members, roles, SSO/MFA configuration, and security events (sign-ins, key issuance/revocation, policy changes) in a per-tenant tamper-evident audit log.
- Billing state: subscription tier and Stripe customer/subscription IDs. No payment card details are stored on our servers; Stripe holds those.
- Session cookie: when you sign in to the dashboard we set a first-party, HttpOnly session cookie (expires after 7 days or on sign-out). We do not use advertising or cross-site tracking cookies.
2. What we never collect
- The source code or file content you send for governance. Files are analysed in memory and only the metadata in section 1 is written; verdict records and exports contain no reconstructable source.
- Passwords (sign-in is by API key, email link, SSO or two-factor code).
- Advertising identifiers or third-party tracking cookies.
3. How we use your data
Audit metadata powers your governance history, dashboards and reports, and lets us detect patterns in your codebase's compliance posture. Email is used for account, security and billing communication, never sold or used for third-party marketing. Aggregate, de-identified verdict counts (no tenant IDs, emails or file paths) appear on our public trust page.
4. Retention
Audit metadata and account data are retained for as long as your account is active, so your history stays available to you. Sign-in links and verification tokens expire within 30 minutes. When an account is deleted, its data is removed within 30 days (billing records are retained as long as tax and accounting law require).
5. Your rights
You can access and export your audit history from the dashboard at any time. To request deletion of all data associated with your account, email ezra@visnryentertainment.com with the subject line "Data Deletion Request" and your tenant ID or registered email; we complete deletion within 30 days and confirm by email. EU/UK users may also exercise access, rectification, portability and objection rights by the same route.
6. Sub-processors and storage
We do not sell your data. It is processed only by the sub-processors needed to run the service, each under a data-processing agreement or industry-standard equivalent terms; the current list, purpose and location of each is published at /legal/sub-processors (hosting: Railway; billing: Stripe; transactional email: Resend; edge/DNS: Cloudflare). Data is encrypted in transit and at rest.
7. Security
API keys are stored only as SHA-256 hashes; dashboard sessions use HttpOnly cookies; two-factor authentication and enforced SSO are available on every account; every security-relevant event is written to a per-tenant, hash-chained audit log that you can export and verify. See /trust for the integrity and authenticity guarantees, and /security for responsible disclosure.
8. Contact
Questions about this policy or our data handling: ezra@visnryentertainment.com. Related documents: Terms of Service · Sub-processors · Trust.