Privacy Policy
This policy explains what DeeBoys LLC d/b/a Validash ("Validash," "we") collects, why, and what happens to it. The Service is currently offered to customers in the United States. It is a business tool and not directed to children under 18.
§ 1What we collect
Account & purchase data. Email address, authentication identifiers, purchase history, and support correspondence. Payments are processed by Stripe: we never see or store full card numbers; Stripe's handling is governed by Stripe's privacy policy.
Submitted code. The repositories and files you submit for auditing. We treat submitted code as your confidential information, not as data for our use. Note: source code sometimes contains embedded personal information (committer names/emails, credentials, user data). We apply automated skipping/redaction to common secret formats and secret-bearing files, but you are responsible for what your submissions contain, please don't submit regulated or sensitive personal data (see Terms §11).
Reports & audit metadata. The generated Report, its score, the repository reference and commit identifier, timestamps, tier, and processing telemetry (durations, engine status, token counts).
Site basics. Standard logs (IP, browser type, pages) for security and operations. We use only essential cookies/local storage needed for the product to function; we do not run third-party advertising trackers.
§ 2How we use it
To provide and operate the Service (running audits, delivering Reports, processing payments); to administer guarantee claims; to secure the Service (abuse prevention, rate limiting); to communicate with you about purchases and support; to improve the Service using aggregated, de-identified operational data that does not contain or reveal your code; and to comply with law.
We do not sell or share your personal information for advertising. We do not use your submitted code to train any AI model, and our model providers are contractually prohibited from using API inputs to train theirs.
§ 3Who touches your data (subprocessors)
Current subprocessors, their roles, and locations are listed at validash.com/subprocessors and include: Google Cloud / Firebase (hosting, storage, functions, US); Stripe (payments, US); and the AI model providers used for analysis: Google (Gemini API, paid tier), OpenAI (API), Anthropic (API), and one additional scanner engine slot currently under lineup revision (this list is updated before any provider is added or replaced). All model-provider usage is on business/API terms under which inputs are not used for training. We will update the subprocessor list before adding or replacing providers.
We disclose data otherwise only: to comply with legal process; to protect rights, safety, or the integrity of the Service; or in connection with a business transfer (in which case commitments in this policy continue to apply to transferred data).
§ 4How long we keep it
§ 5Security
Data is encrypted in transit (TLS) and at rest (via Google Cloud). Repository access tokens you provide are encrypted at the application layer before storage and are deleted with the session. Access to production systems is restricted. No system is perfectly secure; we will notify affected customers of any breach as required by law.
§ 6Your choices and rights
You can access and update account information, request a copy of your data, or request deletion of your account and Reports at any time via support@validash.com. We honor deletion requests within 30 days, subject to legal retention duties. Depending on your state of residence, you may have additional statutory rights (access, correction, deletion, portability); we honor these for all customers regardless of threshold applicability. We do not discriminate for exercising rights.
§ 7Changes
We'll post updates here with a revised "Last Updated" date and notify you of material changes by email or site notice. Changes are prospective.
§ 8Contact
DeeBoys LLC d/b/a Validash · hello@validash.com · Address available on request