← Back to Asenvra

Privacy Policy

Last updated: May 30, 2026

1. Introduction

Asenvra ("we," "our," or "the Service") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our production-readiness scanning platform. Please read this policy carefully. By using Asenvra, you agree to the practices described in this Privacy Policy.

2. Information We Collect

Account Information

  • Email address (required for account creation)
  • GitHub profile information (if you sign up via GitHub OAuth)
  • Account creation date and subscription status

Code You Submit

  • Source code you upload via ZIP file or provide via public GitHub URL
  • This code is processed temporarily and deleted after the scan completes
  • We do not store, share, or use your source code for any purpose other than generating your scan report

Scan Results

  • Scan reports, scores, issue lists, and analysis results are stored securely in your account
  • These results are only accessible to you, protected by row-level security
  • Environment variable names detected by VibeOps are stored; values are never stored

Usage Data

  • Pages visited, features used, and scan frequency (via privacy-respecting analytics)
  • Browser type and device information for debugging purposes

Payment Information

  • Payment processing is handled entirely by Stripe — we never see or store your credit card details
  • We store only your Stripe customer ID and subscription status

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the scanning services
  • Process your payments and manage your subscription
  • Send you service-related emails (scan completion notifications, billing updates)
  • Respond to your support requests
  • Detect and prevent fraud or abuse
  • Analyze aggregate usage patterns to improve the product

4. How We Protect Your Data

We implement industry-standard security measures to protect your information:

  • Row-Level Security (RLS): Every database table uses RLS policies ensuring you can only access your own data
  • Ephemeral Processing: Your code is analyzed on temporary storage and deleted after scan completion
  • Encrypted Transmission: All data is transmitted over HTTPS with TLS encryption
  • Secure Authentication: Authentication is handled through Supabase with industry-standard password hashing
  • No Card Storage: Payment card data is processed by Stripe and never touches our servers

5. Data Sharing

We do not sell, rent, or trade your personal information. We share data only with:

  • Stripe — to process payments (they receive only the payment data you provide at checkout)
  • Supabase — to store and manage your account and scan data (hosted on their infrastructure with RLS)
  • Resend — to send transactional emails on our behalf (they receive only your email address and the email content)
  • Law enforcement, if required by law or to protect our legal rights

6. Your Code Privacy

We take the privacy of your source code extremely seriously. Here is exactly what happens when you submit code for scanning:

  1. Your code is transferred to our scanning server over an encrypted connection
  2. The code is written to a temporary directory on ephemeral storage
  3. Our scanning tools (ShipCheck, MockHunter, VibeOps) analyze the code in memory
  4. The scan report is generated and saved to your account
  5. The temporary directory and all your source code files are permanently deleted

At no point is your code stored in any persistent database or backup. We do not use your code to train AI models or for any purpose beyond generating your scan report.

7. Data Retention

  • Account data: Retained while your account is active; deleted within 30 days of account deletion
  • Scan results: Retained while your account is active; deleted with your account
  • Source code: Never retained beyond the scan process (deleted within minutes)
  • Payment records: Retained as required by law and Stripe's policies

8. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and all associated data
  • Object to processing of your data for marketing purposes
  • Export your scan results in a machine-readable format

To exercise any of these rights, contact us at support@asenvra.com.

9. Cookies & Tracking

We use minimal, essential cookies to maintain your authenticated session. We use privacy-respecting analytics that do not track you across other websites. We do not use advertising trackers or sell your data to ad networks.

10. Children's Privacy

Asenvra is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. We encourage you to review this policy periodically.

12. Contact

If you have questions about this Privacy Policy or our data practices, please contact us at support@asenvra.com.