01Who is responsible for your data
For your account, billing, support, and the security of our own platform, we are the controller. For the personal data that happens to exist inside the systems you connect — database rows, repository contents, deployment configuration — you are the controller and we act as your processor under our Data Processing Addendum.
Contact for privacy matters: [email protected]. Postal: ZerwOne Network LLC, Privacy Office, United States.
02What we collect
- Account data — email, name, hashed password or OAuth identifier, workspace and role membership, authentication sessions.
- Onboarding data — role, company, primary goal, and any compliance frameworks you tell us you are working toward. Used to tailor the product; you can skip these fields.
- Operational data — projects, connected resources, check runs, findings, evidence records, proposed fixes, approvals, and an append-only audit log of agent tool calls.
- Integration data — encrypted OAuth tokens and installation identifiers for GitHub, Supabase, and Vercel, plus the metadata each integration returns.
- Billing data — plan, subscription status, invoices, and Stripe customer identifier. We never receive or store your full card number.
- Support and contact data — the messages you send us and the email address you send them from.
- Device and usage data — IP address, user agent, pages viewed, and approximate location derived from IP. Product analytics and error monitoring are collected only with your consent.
- Cookies — see the Cookie Policy. No advertising or cross-site tracking cookies.
03Connection strings, repository code, and scan targets
This is the part that matters most for a security product, so here is exactly what happens.
- Database connection strings submitted for a one-off check are held for the active session and are not written to Sentrail's application database or logs. Persisted OAuth connections use encrypted provider credentials as described below.
- Stored provider credentials — OAuth access and refresh tokens — are encrypted at rest using envelope encryption with a key separate from the database, and are decrypted only in memory when a run needs them.
- Repository contents are fetched into an ephemeral, network-restricted analysis container that is destroyed when the run finishes. We do not keep a mirror of your repository.
- What we retain from a scan is the result, not the source: findings, the evidence for each finding (file path, line range, rule identifier, timestamps), and short redacted excerpts needed to explain the issue.
- Query results sampled during a database check are used to evaluate the check and are not stored beyond the evidence record for that finding.
- Secrets, tokens, passwords, and connection strings are redacted before anything is logged, stored as evidence, sent to an error monitoring service, or included in a model prompt.
LLM inference: redacted code excerpts, schema and configuration metadata, and finding text are sent to a model provider to triage findings and draft fixes. We use endpoints under the provider terms and configuration identified in our current subprocessor disclosures. Sentrail does not train its own models on customer data.
04What each integration can access
| Provider | Access requested | Limits we impose |
|---|---|---|
| GitHub | Repository metadata and contents (read), pull requests (write), checks (read) | Write access is used only to open draft pull requests you approve. We never push to a default branch. |
| Supabase | Project settings, database schema and policies, security advisors (read) | Migrations are proposed as SQL for your approval and are never applied automatically. |
| Vercel | Project and deployment configuration, environment variable names (read) | We read environment variable names and metadata, never their values. |
05How we use information
- To provide, operate, and maintain the Service, including running checks and drafting fixes you approve.
- To authenticate you, enforce plan entitlements and quotas, and prevent fraud or abuse.
- To secure and audit the Service, including investigating suspected unauthorized scanning.
- To bill you and keep the financial records the law requires.
- To answer your support requests and send operationally important notices.
- With your consent, to understand product usage and diagnose errors so we can improve.
- To comply with legal obligations and enforce our Terms.
06What we never do
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- We do not use your code, findings, or data to train models.
- We do not use your data to build a threat-intelligence product or publish anything about your systems.
- We do not act on findings in your systems without your approval.
07Legal bases (GDPR/UK GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the Service and your account | Performance of a contract (Art. 6(1)(b)) |
| Billing and financial records | Contract and legal obligation (Art. 6(1)(b), (c)) |
| Platform security, abuse prevention, audit logging | Legitimate interests (Art. 6(1)(f)) |
| Product analytics and error monitoring | Consent (Art. 6(1)(a)) |
| Responding to lawful requests | Legal obligation (Art. 6(1)(c)) |
09International transfers
We operate primarily from the United States. If you use the Service from outside the U.S., your information is transferred there and to the regions where our subprocessors operate. For transfers of personal data from the EEA, UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, as set out in our DPA, and we assess each transfer where required.
10Retention
| Data | Retention |
|---|---|
| Account and workspace data | While the account is active, then up to 90 days |
| Findings, evidence, and check history | While the project exists, or until you delete it |
| Audit logs of agent actions and approvals | Up to 24 months |
| Connection strings and submitted credentials | Not retained (request duration only) |
| Repository contents in an analysis container | Destroyed at the end of the run |
| Billing and invoice records | As required by tax and accounting law (typically 7 years) |
| Analytics and error monitoring events | Up to 12 months |
| Support correspondence | Up to 24 months |
11Security
We maintain the technical and organisational measures listed in Annex II of our DPA: TLS in transit, encryption at rest, envelope-encrypted provider tokens, row-level security and role-based access control, ephemeral isolated scanner containers, secret redaction, human approval gates for production-changing actions, append-only audit logs, and dependency and secret scanning in continuous integration.
No system is perfectly secure and we cannot guarantee absolute security. To report a vulnerability in Sentrail, see our responsible disclosure policy.
12Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to processing of your personal information, to data portability, to withdraw consent, and to lodge a complaint with your supervisory authority. If you are in California, you may also request disclosure of the categories collected and shared, request deletion or correction, and opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of. We will not discriminate against you for exercising a right.
Email [email protected]. We verify requests against your account and respond within the statutory period (30 days under GDPR, 45 days under the CCPA, extendable where permitted). An authorised agent may submit a request with written proof of authority. For personal data inside a system you connected, contact the customer that controls it; if that is you, use your own tooling or ask us for processor assistance.
To change cookie and analytics consent: .
13Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
14Changes to this policy
We will post any revised policy here with a new effective date and version. For material changes we will give reasonable advance notice by email or in-product before they take effect. Previous versions are available on request.
Structured around the GDPR Art. 13/14 information requirements, the CCPA/CPRA notice-at- collection categories, and the retention-schedule and subprocessor transparency practices used in published privacy policies from established infrastructure vendors. Provided for information; it is not legal advice. Review with qualified counsel before relying on it.
