POVV

Privacy Policy

Effective August 22, 2026 · POVV Kacper Gardocki — sole proprietorship (JDG), Poland · NIP 9151840843

1. Who is responsible for your data

“POVV” is a brand. The controller of personal data processed through this service is POVV Kacper Gardocki, a sole proprietorship (jednoosobowa działalność gospodarcza) established in Poland, NIP 9151840843, REGON 545448690, registered address al. Solidarności 68/121, 00-240 Warszawa, Poland. Because the controller is established in the EU, the GDPR applies to this processing in full. Contact: [email protected].

2. What we collect and why

Account data (email, authentication identifiers) and workspace configuration (labs, repository URLs, goals) — processed to perform our contract with you. Usage metering (audit counts, token costs) and payment status — contract performance and our legitimate interest in operating and billing the service correctly. Anonymous audits are keyed to a browser fingerprint derived from IP and a cookie value, processed under our legitimate interest in preventing abuse of a free, cost-bearing quota. Card details are collected and stored by Stripe, our payment processor — never by POVV.

3. Repository source code — zero retention

During an audit, a bounded snapshot of the repository is processed in memory and discarded when the audit completes. We do not persist your source code. For private repositories, the sealed verdict stores cryptographic hash anchors of evidence (SHA-256), never verbatim code. For public repositories, short verbatim quotes that survived machine verification may be sealed with file/line attribution. GitHub personal access tokens you connect are stored encrypted and used only to fetch repositories you direct us to audit.

4. Processors, and transfers outside the EEA

We use the following processors: Anthropic and xAI (model inference over repository snapshots), Supabase (database and authentication), Vercel (application hosting), Stripe (payments and invoicing), Upstash (rate limiting and abuse control), Cloudflare (bot verification), and PostHog (product analytics — active only where you have allowed analytics in the cookie banner). Several are established outside the European Economic Area. Where personal data is transferred to them it is done under the European Commission’s Standard Contractual Clauses and, where applicable, an adequacy decision, together with the supplementary measures described in each processor’s data protection terms.

Repository snapshots are sent to model providers for inference only. We do not train any model on your source code — not ours and not theirs. Anthropic and xAI are engaged on their commercial API terms, under which content submitted through the API is not used to train their models. That is a contractual position we rely on, not something we can inspect inside their infrastructure.

We do use our own work product to improve our services. The verdicts, findings, sealed synthesis and VMI narratives that POVV generates are ours, and we use them — in anonymized or aggregated form — to improve the audit engine, including a specialist audit model we train on our own hardware. Verdicts for private repositories carry cryptographic hash anchors of evidence and never verbatim source, so no private code can enter that corpus. Verdicts for public repositories may contain short quotes that survived machine verification, with file and line attribution, drawn from code that was already public; those quotes remain part of the improvement corpus. If that distinction matters to you, audit a private repository.

5. Public verdicts

POVV does not publish a verdict about your repository publicly without your consent. Verdicts for public repositories may be published at a hash-addressed URL together with their evidence manifest, when their submitter chooses to publish. Verdicts for private repositories are never published. POVV does not publish a verdict about a repository that its owner or an authorised submitter did not run. A sealed verdict is an append-only record: it can be revoked from public view, and its cryptographic receipt remains verifiable.

6. Retention and deletion

Account and workspace data persist while your account is active. Anonymous audit fingerprints and rate-limit counters expire automatically within days. You may request account deletion at [email protected]; we delete personal data within 30 days, except sealed audit ledger entries (retained as integrity-critical records with personal identifiers removed) and records we must retain by law — including invoices, which Polish tax law requires us to keep for five years.

7. Your rights

Under the GDPR you may request access to your personal data, its correction or erasure, restriction of processing, and portability; you may object to processing carried out on the basis of our legitimate interests; and where processing rests on consent you may withdraw it at any time without affecting prior processing. Write to [email protected]. We do not sell personal data and we do not use it for automated decision-making that produces legal effects concerning you.

If you believe we have handled your data unlawfully you may lodge a complaint with the President of the Personal Data Protection Office (UODO), Warsaw, Poland, or with the supervisory authority of your EU country of residence.

8. Cookies

POVV sets strictly necessary cookies for session and bot protection. Product analytics is anonymous and cookieless, and runs only where you have allowed it. There are no advertising or cross-site tracking cookies.

9. Security

Access controls are enforced at the database row level, secrets are stored encrypted, transport is TLS-only, and verdict integrity is protected by Ed25519 signatures over SHA-256 hashes. No system is perfectly secure; report suspected vulnerabilities to [email protected].

10. Changes and contact

Material changes will be announced in-product or by email. Questions: [email protected] · POVV Kacper Gardocki, Poland.

Privacy Policy — POVV · POVV