LEGAL · PRIVACY POLICY

Privacy Policy

Last Updated: July 29, 2026 · Version 1.1

This policy explains what DeeBoys LLC d/b/a Validash ("Validash," "we") collects, why, and what happens to it. The Service is currently offered to customers in the United States. It is a business tool and not directed to children under 18.

§ 1What we collect

Account & purchase data. Email address, authentication identifiers, purchase history, and support correspondence. Payments are processed by Stripe: we never see or store full card numbers; Stripe's handling is governed by Stripe's privacy policy.

Submitted code. The repositories and files you submit for auditing. We treat submitted code as your confidential information, not as data for our use. Note: source code sometimes contains embedded personal information (committer names/emails, credentials, user data). We apply automated skipping/redaction to common secret formats and secret-bearing files, but you are responsible for what your submissions contain, please don't submit regulated or sensitive personal data (see Terms §11).

Reports & audit metadata. The generated Report, its score, the repository reference and commit identifier, timestamps, tier, and processing telemetry (durations, engine status, token counts).

Site basics. Standard logs (IP, browser type, pages) for security and operations. We use only essential cookies/local storage needed for the product to function; we do not run third-party advertising trackers.

§ 2How we use it

To provide and operate the Service (running audits, delivering Reports, processing payments); to administer guarantee claims; to secure the Service (abuse prevention, rate limiting); to communicate with you about purchases and support; to improve the Service using aggregated, de-identified operational data that does not contain or reveal your code; and to comply with law.

We do not sell or share your personal information for advertising. We do not use your submitted code to train any AI model. Our model providers are engaged on business or API terms under which inputs are not used to train theirs; that commitment is the provider's own, and every provider is named at validash.com/subprocessors.

§ 3Who touches your data (subprocessors)

Current subprocessors, what each receives, and locations are listed at validash.com/subprocessors and include: Google Cloud / Firebase (hosting, storage, functions, US); Stripe (payments, US); and the AI model providers used for analysis: Google (Gemini API, paid tier), OpenAI (API), Anthropic (API), Mistral (served via Amazon Bedrock on US AWS infrastructure), and Fireworks AI (model inference, engaged when a primary provider fails) (this list is updated before any provider is added or replaced). Where a model's origin differs from who serves it, the subprocessor list states both, because what matters is the data path and not a model's provenance. Where we have not contracted for a specific processing region, the subprocessor list says so rather than implying one. All model-provider usage is on business/API terms under which inputs are not used for training. We will update the subprocessor list before adding or replacing providers.

We disclose data otherwise only: to comply with legal process; to protect rights, safety, or the integrity of the Service; or in connection with a business transfer (in which case commitments in this policy continue to apply to transferred data).

§ 4How long we keep it

Extracted code payloads: automatically deleted within 24 hours after processing completes. That is the outer bound we commit to; in ordinary operation a payload is deleted as soon as its audit finishes.
Reports and audit metadata: retained for the access period stated at purchase or until the expiry shown on your Report, then deleted by scheduled sweeps. You may request earlier deletion.
Failed or abandoned sessions: reclaimed and purged automatically on a schedule.
Account data: for the life of the account plus a reasonable period for legal/accounting purposes.
Model-provider retention: API inputs are subject to the retention windows set out in each provider's own business terms, typically for abuse monitoring. Those windows are the provider's and not ours, they differ between providers, and we do not publish a per-provider retention status; read the provider's own terms for the current position.

§ 5Security

Data is encrypted in transit (TLS) and at rest (via Google Cloud). Repository access tokens you provide are encrypted at the application layer before storage and are deleted with the session. Access to production systems is restricted. No system is perfectly secure; we will notify affected customers of any breach as required by law.

§ 6Your choices and rights

You can access and update account information, request a copy of your data, or request deletion of your account and Reports at any time via hello@validash.com. We honor deletion requests within 30 days, subject to legal retention duties. Depending on your state of residence, you may have additional statutory rights (access, correction, deletion, portability); we honor these for all customers regardless of threshold applicability. We do not discriminate for exercising rights.

§ 7Changes

We'll post updates here with a revised "Last Updated" date and notify you of material changes by email or site notice. Changes are prospective.

§ 8Contact

DeeBoys LLC d/b/a Validash · hello@validash.com · Address available on request