Legal
Privacy Policy
Last updated July 26, 2026
This Privacy Policy describes how Veridical handles data across veridical.dev and the Veridical code-review service, including account identity, workspace membership, connected repositories, pull-request review data, usage and billing records, support correspondence, request logs, and cookie-consent state. Veridical is operated by SzafranSoft (Łukasz Szafrański), a sole trader established in Poland. The policy is built primarily around the EU General Data Protection Regulation (GDPR) and Polish data-protection law, with a concise section for California residents under the CCPA/CPRA. Effective date and Last updated: July 26, 2026.
011. Who we are and what this policy covers
Veridical ("Veridical," "we," "us," or "our") is an AI code-review platform that reviews pull requests and returns findings together with a single, calibrated safe-to-merge score. Verified, not vibed.
Veridical provides a public marketing website and an authenticated code-review service. Hosted identity is supplied through WorkOS, paid-plan checkout and card handling are supplied through Stripe, and eligible public repositories may use the free plan without entering payment details.
This Privacy Policy explains what personal data we collect through the website, product accounts, connected services, reviews, billing and correspondence; why we collect it; the legal bases we rely on; who we share it with; how long we keep it; how we protect it; and the rights you have and how to exercise them. It applies to veridical.dev, the hosted Veridical app, and related communications. Third-party services also publish their own privacy notices.
"Personal data" and "personal information" mean information that identifies, relates to, or could reasonably be linked to you. We use the two terms interchangeably in this policy.
The data controller for the personal data described here (and the "business" for CCPA/CPRA purposes) is SzafranSoft (Łukasz Szafrański), a sole trader operating under the business name "SzafranSoft" and registered in the Polish Central Registration and Information on Business (CEIDG). Registered address: ul. Myśliwska 24/34, 80-126 Gdańsk, Poland. NIP: 5833526510. REGON: 540460539. This controller operates the Veridical product and the veridical.dev website.
Because the controller is established in the European Union (Poland), the EU GDPR and Polish data-protection law are the primary legal framework that governs the processing described here. No Article 27 EU representative is required, because the controller is established within the EU. A Data Protection Officer (DPO) has not been appointed because the processing does not meet the thresholds in Article 37 GDPR (it is small-scale and does not involve large-scale or systematic monitoring, or large-scale processing of special-category data). All data-protection requests and questions go to contact@veridical.dev.
022. The personal data we collect, and why
We practice data minimization: we ask for the smallest amount of information needed to provide and secure the website and Service, administer workspaces, perform requested reviews, account for usage and subscriptions, and respond to inquiries. We collect the following categories directly from you, from your organization or connected provider, or automatically as described.
- Account and workspace identity. WorkOS provides identifiers and claims such as name, work email, organization, membership, role, SSO and directory-lifecycle state. Veridical stores the minimum mapping needed to authenticate you, enforce tenant boundaries and permissions, and audit privileged activity. Source category: you, your organization, and WorkOS.
- Repository and review data. When an authorized user connects a forge or requests a review, we process repository and installation identifiers, pull-request metadata, commits, source diffs or files needed for the requested operation, configuration, findings, generated tests or patches, execution evidence, and user dispositions. We use this only to provide, secure, support, and improve the requested workspace service under its configured settings. Source category: you, your organization, and connected forge providers.
- Usage and billing data. We process plan, entitlement, pooled-credit usage, model and compute metering, Stripe customer/subscription identifiers, invoice-event type and billing-period metadata. Stripe receives and handles payment-card and checkout data directly; Veridical does not receive full card numbers or card security codes. Source category: you, your organization, Stripe, and Veridical usage records.
- Investor inquiries. When you contact us about investing, we collect the information you submit - typically your name, email address, firm, and any note or message you include. We use this solely to respond to and manage that inquiry. Source category: information you provide.
- Messages you send us. If you email contact@veridical.dev, we receive your email address, your message, and anything else you choose to include. We use it to respond and to keep a record of the correspondence. Source category: information you provide.
- Server and request logs. Like virtually all websites, our hosting and CDN provider automatically records standard technical data when you visit, including your IP address, browser user-agent string, the pages or resources requested, referrer, approximate location inferred from IP, and timestamps. We use this to deliver the site, diagnose errors, monitor performance, and detect and prevent abuse, spam, and security threats. Source category: collected automatically.
- Cookie consent state. Our cookie consent banner is live on the site. We store your consent choices in a first-party cookie so we can honor them on future visits. The cookie records which non-essential categories you allowed (if any), the time of your decision, and the policy version it was made against, and is set to re-prompt you after 6 months so your consent stays current. Today only strictly-necessary cookies are set; see Section 9. Source category: collected automatically / your settings.
- Anti-spam (honeypot). Our forms include a hidden field that is invisible to genuine users. If it is filled in - a strong signal of an automated bot - we silently reject the submission and do not store it. We do not retain personal data from rejected (bot) submissions.
033. What we do NOT collect
Veridical does not receive full payment-card numbers or card security codes from Stripe. We do not ask you to place passwords, access tokens, private keys, special-category personal data under the GDPR, or sensitive personal information under the CCPA/CPRA in source code, prompts, support requests, or configuration fields.
We do not use your personal data to make decisions about you that produce legal or similarly significant effects through solely automated means, and we do not carry out profiling of that kind.
The marketing website does not itself receive repository credentials, code, WorkOS credentials, or card data. Those operations occur in the authenticated product app and its connected providers. Customer source and source-derived artifacts are confidential data and are not public merely because the marketing site is public.
044. Legal bases for processing (GDPR)
We are established in Poland and process personal data under the EU GDPR and Polish data-protection law. We rely on the following legal bases under Article 6(1) GDPR for each processing activity. Where more than one basis could apply, we have identified the one we principally rely on.
- Consent - Article 6(1)(a). We rely on your consent for non-essential cookies (such as analytics or marketing cookies, if and when used) and for any optional marketing communications. You can withdraw consent at any time, with no effect on the lawfulness of processing carried out before withdrawal.
- Contract and steps requested before contract - Article 6(1)(b). We process account, workspace, requested repository/review, usage and subscription data to provide the plan or free public-repository access you request, administer your account, and respond to inquiries.
- Legitimate interests - Article 6(1)(f). We rely on our legitimate interests to operate, secure, support and improve the website and Service; prevent fraud and abuse; keep proportionate security and audit records; understand service reliability and cost; and communicate with people who have contacted us. We balance these interests against your rights and freedoms. You may object as described in Section 10.
- Legal obligation - Article 6(1)(c). We may process limited data where the law requires it, for example to respond to a valid legal request or to keep records we are required to retain.
055. Service providers and third-party processors
We do not run every part of our service ourselves. We use a small set of trusted providers that process personal data on our behalf, under contract and only on our documented instructions. We put data processing agreements in place with each processor where required, and we do not permit them to use your data for their own purposes. We maintain an up-to-date list of the processors we use; the current ones are described below.
- Cloud hosting and CDN provider. The website is hosted and delivered through our cloud hosting/CDN provider, which processes the request and server-log data described in Section 2 in order to serve the site, route traffic, and provide security and performance features.
- Google Cloud Platform - hosted application, regional database, object storage, queues, logs, key management and isolated execution infrastructure for the hosted Service.
- WorkOS - hosted identity, authentication, SSO and directory lifecycle.
- Stripe - hosted checkout, subscription billing, invoicing and payment processing. Stripe handles payment credentials directly and may act as an independent controller for some regulated payment activities.
- Azure OpenAI and Google Vertex AI - model processing selected by operator policy for review workloads. Deployment, region and data-handling settings apply to the configured service.
- GitHub, GitLab, Azure DevOps and other integrations you authorize - repository, pull-request and delivery data needed for the requested integration.
- Resend - transactional email delivery for account, service and inquiry communications where configured.
- Other infrastructure, analytics, or marketing tooling we may add in the future, which we will disclose here before it processes your personal data.
066. How your data is shared - and our no-sale / no-share commitment
We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We are not in the business of monetizing your information. Since inception we have never sold or shared personal data, and we have no operating history of doing so.
We disclose personal data only in these limited circumstances: to the service providers / processors described in Section 5, so they can perform services for us; to professional advisers (such as lawyers, accountants, or auditors) where reasonably necessary; in connection with a corporate transaction such as a merger, acquisition, financing, reorganization, or sale of assets, in which case personal data may be transferred as part of that transaction subject to this policy; and where we are legally required to do so, or where disclosure is reasonably necessary to comply with law, enforce our terms, or protect the rights, safety, or property of Veridical, our users, or others.
For transparency under the CCPA/CPRA: since inception we have disclosed identifiers (such as email address and IP address), internet/network activity (server logs), and the limited commercial/professional information you provide (such as company, GitHub organization, firm, and tier interest) to our service providers for the business purposes described in this policy. We have not disclosed personal information to third parties for those parties' own purposes, and we have not sold or shared personal information.
077. International data transfers
We are established in Poland, in the European Economic Area (EEA). The hosted control-plane design uses Google Cloud's Warsaw region, but an authorized integration or configured provider - including WorkOS, Stripe, a forge, Resend, or Azure model processing - may process data outside Poland or the EEA. Cross-cloud processing means the selected provider and deployment settings matter.
Where we make such transfers, we put appropriate safeguards in place as required by the GDPR - principally the European Commission's Standard Contractual Clauses (SCCs) and, where the recipient is certified, reliance on the EU-US Data Privacy Framework. We rely on these mechanisms for the transfers to our processors described in Section 5.
You can contact us at contact@veridical.dev to ask about, or request a copy of, the safeguards that apply to a specific transfer.
088. How long we keep your data (retention)
We keep personal data only for as long as we need it for the purposes described in this policy, and then delete or anonymize it. Our current retention periods are set out below.
We may retain certain information for longer where we are legally required to, or where reasonably necessary to establish, exercise, or defend legal claims; in that case we restrict the data to that purpose.
- Account and membership mappings - kept while the account/workspace is active and for the limited period needed for security, dispute and legal obligations after closure.
- Review records and source-derived artifacts - kept under the workspace retention policy, subject to legal hold, security investigation, backup and billing-integrity exceptions disclosed to the customer.
- Billing and tax records - kept for the period required by applicable accounting, tax, fraud-prevention and legal obligations; card credentials remain with Stripe.
- Email correspondence (including investor inquiries and general messages) - kept for up to 24 months, then deleted when no longer needed.
- Server and request logs - kept for up to 90 days for security, debugging, and abuse prevention, after which they are deleted or aggregated.
- Cookie consent state - the consent cookie is kept for 6 months (or until you change or clear your preferences, or we bump the policy version), after which you are re-prompted (see Section 9).
099. Cookies and similar technologies
Cookies are small files stored on your device. We aim to keep our use of them minimal. We group cookies into three categories: necessary, analytics, and marketing.
Necessary cookies are required for the website to function and to remember your settings; this includes your theme preference and the first-party consent-state cookie that records your cookie choices. These are always on and do not require consent. Analytics cookies, if used, would help us understand how the site is used so we can improve it. Marketing cookies, if used, would support measurement of campaigns or outreach. Analytics and marketing cookies are non-essential, default to off, and would only be set after you opt in.
Today only strictly-necessary cookies are set - your theme preference and your consent state. We do not currently set any analytics or marketing cookies. Our consent banner is live on the site and lets you accept, reject, or manage non-essential categories for if and when they are added; we remember and honor your choice and re-ask after 6 months. You can change your choice at any time by reopening the cookie settings, and you can block or delete cookies through your browser settings - though some parts of the site may not work as intended without necessary cookies.
Before enabling any non-essential (analytics or marketing) cookies, we will update this section with a cookie table listing each specific cookie or provider, its purpose, and its duration, and those cookies will be set only after you opt in through the consent banner.
1010. Your rights under the GDPR
Under the EU GDPR and Polish data-protection law you have the following rights over your personal data, which you can exercise free of charge (subject to limited legal exceptions).
To exercise any of these rights, contact us at contact@veridical.dev (see Section 13). We will respond within the period required by law (generally one month under the GDPR, extendable for complex requests). You also have the right to lodge a complaint with the Polish supervisory authority - the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych - UODO), ul. Stawki 2, 00-193 Warszawa, Poland - though we would appreciate the chance to address your concern first.
- Right of access - to obtain confirmation of whether we process your data and a copy of it, along with information about the processing.
- Right to rectification - to have inaccurate or incomplete data corrected or completed.
- Right to erasure - to have your data deleted in certain circumstances (the 'right to be forgotten').
- Right to restriction - to limit how we use your data in certain circumstances.
- Right to data portability - to receive certain data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Right to object - to object to processing based on our legitimate interests, on grounds relating to your particular situation, and to object to direct marketing at any time.
- Right to withdraw consent - where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
1111. Your rights under the CCPA/CPRA (California residents)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you the rights listed below. The categories of personal information we collect, the sources, the business purposes, and the categories of third parties to whom we disclose it are described in Sections 2, 5, and 6, which together serve as our notice at collection. This notice is made available to you at or before the point of collection, including at the relevant form.
Veridical does not sell your personal information and does not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. Because we do not sell or share personal information, there is no opt-out to perform - but you may still contact us to confirm this. We also do not collect or use "sensitive personal information" for purposes that would trigger a right to limit its use.
To exercise your California rights, email us at contact@veridical.dev. We will verify your request using the account, organization, correspondence, or other details associated with the information we hold and will not use verification information for another purpose. You may use an authorized agent where permitted; we may require proof of authorization and direct identity verification. We will not discriminate or retaliate against you for exercising these rights.
California's "Shine the Light" law (Cal. Civ. Code 1798.83) lets California residents ask about disclosures of personal information to third parties for those parties' direct-marketing purposes; we do not make such disclosures.
If you are a resident of another US state with a comprehensive privacy law, you may have similar rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, sale, or certain profiling. As stated above, we do not sell personal data, engage in targeted advertising, or carry out profiling that produces legal or similarly significant effects. Where your state provides a right to appeal a denied request, our denial response will explain how to appeal.
- Right to know - to request the categories and specific pieces of personal information we have collected about you, the sources, the business or commercial purposes, and the categories of third parties to whom it is disclosed.
- Right to delete - to request deletion of personal information we have collected from you, subject to legal exceptions.
- Right to correct - to request correction of inaccurate personal information.
- Right to opt out of sale or sharing - to direct us not to sell or share your personal information (note: we do not sell or share personal information).
- Right to limit use of sensitive personal information - note: we do not collect sensitive personal information for purposes that would trigger this right.
- Right to non-discrimination - we will not discriminate against you for exercising any of these rights.
1212. Security and breach notification
We take reasonable and appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or alteration. The hosted design includes encrypted transport, tenant-scoped authorization, provider-secret separation, private regional data services, bounded retention, audit records, signed credential-free execution handoffs, and isolated execution. No method is infallible, and design controls are not a certification or guarantee.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach, we will notify the President of the Personal Data Protection Office (UODO) without undue delay and, where feasible, within 72 hours of becoming aware of it, except where the breach is unlikely to result in a risk to your rights and freedoms. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify the affected individuals without undue delay, as required by applicable law.
1313. How to contact us and exercise your rights
The fastest way to reach us about privacy, to exercise any of the rights described above, or for any legal, general, or investor inquiry, is to email contact@veridical.dev. We use this single address for all purposes. Please tell us what you would like to do and include enough detail for us to locate your data (such as the email address you used). We will respond within the timeframes required by applicable law. Please also keep the information you have given us accurate and up to date, and let us know if it changes.
Our postal address is: SzafranSoft (Łukasz Szafrański), ul. Myśliwska 24/34, 80-126 Gdańsk, Poland. NIP: 5833526510. REGON: 540460539.
1414. Children's privacy
Veridical is a professional developer tool intended for businesses and adult professionals. The website and Service are not directed to anyone under the age of 18, and we do not knowingly collect personal data from anyone under 18.
If you believe a person under 18 has provided us with personal data, please contact contact@veridical.dev and we will take steps to delete it promptly.
1515. Governing law
This Privacy Policy and any matter relating to it are governed by Polish law, without regard to conflict-of-laws principles. The competent courts are those with jurisdiction over the controller's registered seat in Gdańsk, Poland.
Nothing in this policy limits any non-waivable rights you have under mandatory EU consumer-protection and data-protection law (such as the GDPR), or under the data-protection laws of your own country or US state (such as the CCPA/CPRA), which continue to apply where relevant regardless of the governing law stated here. This section is consistent with our Terms of Service, published at /terms.
1616. Changes to this policy
As Veridical and its provider settings evolve, we will update this Privacy Policy. We will post revisions at /privacy and update the effective indicator (currently July 26, 2026).
For a material change - such as a new processing purpose, processor category, region, automated-decision use, or material retention change - we will provide appropriate notice and seek consent where the law requires it.
Questions about this privacy policy? Email contact@veridical.dev.