Privacy

Privacy notice.

The public website does not run analytics or accept source-code uploads. The subscriber application will use only essential security cookies and Stripe-hosted billing when subscription sales are approved.

Current public-site boundary. The controller identity, purposes, legal bases, providers, retention boundaries, rights, and technical data flows are documented below. Checkout remains disabled and must bind the exact published policy version before subscription data processing begins.

Controller

Raul-Nicolae Manolescu, Einzelunternehmen
Schopfwiesenstr. 5
75236 Kämpfelbach
Germany

Email: hello@veyact.com

Data used by the subscriber service

  • essential HttpOnly checkout-state and subscriber-session cookies
  • opaque Stripe customer, subscription, Checkout Session, Price, and event identifiers
  • subscription status, payment status, plan code, policy-consent versions, and timestamps
  • a one-way hash of the subscriber recovery credential, never the raw recovery code
  • pseudonymous device identifiers, public-key and installation fingerprints, lease sequence, enrollment-ticket state, renewal nonce state, and entitlement timestamps
  • security and billing event records required to prevent replay and enforce access

Data that stays off the service

  • repository content, repository paths, task text, proposal diffs, and raw verifier logs
  • card details, which are entered only on Stripe-hosted pages
  • device private keys, raw recovery credentials, API keys, runner pairing tokens, and customer source archives
  • analytics identifiers, advertising cookies, and cross-site tracking profiles

Purposes, legal bases, and retention

Checkout, entitlement, and support records are used to take steps requested before a contract and administer a business subscription under Article 6(1)(b) GDPR. Accounting records are retained to meet legal obligations under Article 6(1)(c). Replay prevention, service integrity, fraud prevention, and responsible security handling rely on the seller's legitimate interests under Article 6(1)(f), balanced against the limited pseudonymous data involved.

Checkout-state cookies expire after two hours, pending checkout records after 24 hours, and subscriber access cookies after no more than 30 days. Subscription, invoice, security, and support records are retained only for the active relationship and applicable German statutory periods. The exact sales-release retention schedule and deletion exceptions must be fixed before checkout opens.

Providers and contact

Hetzner hosts the website and subscriber service in Germany. Stripe processes payment and billing data under its own privacy terms. Cloudflare routes the published business email address. Direct support email is handled by the sender's and recipient's email providers. No support-ticket database, product analytics, advertising tracker, or website form capture is active.

The optional local runrail advise command contacts DeepSeek only after explicit network consent and BYOK enablement. It transmits minimized bucketed counts and booleans from a passing review, but no source, diff content, path or file name, commit, repository identity, task text, raw verifier output, audit run id, or provider key. DeepSeek's output is candidate advice only and grants no execution authority.

Business subscribers and affected individuals may request access, correction, deletion, restriction, objection, portability where applicable, or information about a transfer by contacting Veyact. They may complain to the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg. Exact transfer safeguards, the sales-release retention schedule, and the policy version bound to checkout must be complete before sales open.