← verdica.cloud

Privacy Policy

LAST UPDATED 25 AUGUST 2026

This policy covers Verdica Cloud, the hosted service at app.verdica.cloud and its GitHub App. The open-source CLI and GitHub Action you run yourself send us nothing at all and are not covered here.

What we process, and why

Your code

To check a pull request we clone the repository into a temporary working directory, run the gate, and delete the working directory when the check ends. We do not store your source code, and we do not keep copies of your diffs.

When a change falls inside the scope of a recorded decision, the diff hunks of the files in that scope and the text of that decision are sent to our model provider for a contradiction judgment. Nothing else about your repository leaves our infrastructure.

Who processes data with us

No other processors. We do not sell data, and we do not share it for advertising.

Where data lives, and for how long

All data is stored in the European Union. Installation data lives as long as the App is installed; check records are kept as the audit trail of your dashboard. Uninstalling the App deletes your installation record and covered-repository choices. Write to us to have the remaining check records deleted.

Your rights

Under the GDPR you may request access, correction, deletion, or export of your data, and you may object to processing. Write to hello@verdica.cloud; we answer within thirty days. You also have the right to complain to your national data protection authority.

Security

Traffic is served over TLS. Credentials and webhook secrets are held as environment secrets, never in the repository. Webhook deliveries are verified with HMAC-SHA256 before anything is processed. Access to production is limited to the operator of the service.

Changes

Material changes to this policy will be announced on this page and, when they affect how your data is processed, in the dashboard before they take effect.

Contact

Verdica — hello@verdica.cloud