Privacy

Privacy notice.

The public website uses no analytics cookies or advertising trackers and accepts no source-code uploads. Optional product-metric upload is disabled by default and, when separately enabled with explicit consent, accepts only daily aggregate counts and timing buckets.

Versioned notice. Checkout remains disabled until the exact published policy version is bound to the selected business or consumer buyer scope. The local repository-review product does not upload repository content to Veyact.

Controller

Raul-Nicolae Manolescu, Einzelunternehmen
Schopfwiesenstr. 5
75236 Kämpfelbach
Germany

Email: hello@veyact.com

Data used by the subscriber service

  • essential HttpOnly checkout-state and subscriber-session cookies
  • opaque Stripe customer, subscription, Checkout Session, Price, and event identifiers
  • subscription status, payment status, plan code, policy-consent versions, and timestamps
  • consumer withdrawal or cancellation declaration name, contract reference, requested effect, signed-intent hash, receipt checksum, and timestamp
  • a one-way hash of the subscriber recovery credential, never the raw recovery code
  • pseudonymous device identifiers, public-key and installation fingerprints, lease sequence, enrollment-ticket state, renewal nonce state, and entitlement timestamps
  • security and billing event records required to prevent replay and enforce access
  • only with explicit opt-in: daily aggregate event counts, duration buckets, platform, plan, and product version; raw local events and repository identity remain on the device

Required and optional information

Business checkout requires business name, billing country and address, purchaser authority, a supported tax identifier where required, provider payment confirmation, and policy consent. Consumer checkout requires individual name, billing country and address, provider payment confirmation, and policy consent. Without the applicable information, Veyact cannot conclude or perform the subscription contract.

The public consumer withdrawal and cancellation functions require a name and Checkout, subscription, or invoice reference. The service uses these details to identify and evidence the declaration, binds the review step with a short-lived signed token, and immediately provides a downloadable receipt. It does not collect an email address or card details through these functions.

Direct support email is optional. A minimal invoice or Checkout Session reference may be needed to resolve account or billing requests. Source code, repository archives, card data, credentials, raw recovery codes, and provider keys are neither required nor accepted through support.

Data that stays off the service

  • repository content, repository paths, task text, proposal diffs, and raw verifier logs
  • card details, which are entered only on Stripe-hosted pages
  • device private keys, raw recovery credentials, API keys, runner pairing tokens, and customer source archives
  • analytics identifiers, advertising cookies, and cross-site tracking profiles

Purposes, legal bases, and retention

Checkout, entitlement, consumer-rights declarations, and support records are used to take steps requested before a contract, administer a subscription, and process withdrawal or cancellation under Article 6(1)(b) GDPR. Accounting records and records required to demonstrate consumer-rights handling are retained to meet legal obligations under Article 6(1)(c). Replay prevention, service integrity, fraud prevention, and responsible security handling rely on the seller's legitimate interests under Article 6(1)(f), balanced against the limited data involved. Optional daily aggregate product metrics are processed only after explicit consent under Article 6(1)(a); consent can be withheld or withdrawn without losing the deterministic local product.

Checkout-state cookies expire after two hours, pending checkout records are pruned after 24 hours, and subscriber access cookies expire after no more than 30 days. Strictly necessary cookies provide checkout integrity and authenticated subscriber access; no advertising or analytics cookies are used.

Operational subscription and entitlement state is kept during the subscription and for up to three years after the end of the calendar year in which it ends where required for contract, dispute, fraud, or security evidence. Security and replay-event records are kept for up to 12 months unless a documented incident or legal claim requires longer retention. Optional daily aggregate product metrics are automatically limited to a rolling 90-day store. Ordinary support correspondence is kept for up to 24 months; correspondence that is a legally relevant business record may be retained for six years. Invoices, bookkeeping records, and the policy-consent evidence required to understand them are retained for eight years from the end of the relevant calendar year, or longer only where another mandatory tax period applies.

When a retention period ends, Veyact deletes or irreversibly minimizes the record unless preservation is required for an unresolved claim, tax audit, security incident, or other legal obligation. A request for deletion cannot override a mandatory retention duty.

Providers, transfers, and automated decisions

Hetzner hosts the website, subscriber service, private consumer-rights declaration store, and the separately gated aggregate-metrics endpoint in Germany. Stripe processes checkout, tax, payment, invoice, and billing-management data under its service and privacy terms. For a Checkout marked Sold through Link, Link is merchant of record and also processes transaction emails, indirect tax, subscription management, refunds, disputes, and transaction support under its published terms. Cloudflare routes the published email domain. Direct support email is handled by the sender's and recipient's email providers. No support-ticket database, advertising tracker, repository upload form, or marketing form capture is active. The metrics endpoint is disabled by default and stores no repository fingerprint, path, ref, commit, finding, prompt, source, diff, agent output, provider data, contact detail, IP address, or user-agent string.

Where a provider processes data outside the European Economic Area, Veyact relies on the provider's applicable adequacy decision, EU Standard Contractual Clauses, or another lawful transfer mechanism and reviews the transfer boundary before activation. Current provider documentation is available through the provider's published privacy and data-transfer materials.

The optional local runrail recommend --provider deepseek --allow-network command contacts the fixed DeepSeek API directly from the customer's machine only after explicit network consent and dedicated BYOK enablement. Veyact does not relay that request. It transmits the published aggregate field allowlist, but no source, diff content, path or file name, commit, repository identity, task text, raw verifier output, audit run id, or provider key. The customer must assess DeepSeek's terms and transfer conditions before enabling it. Its output is candidate advice only and grants no execution authority.

No Veyact process makes a decision with legal or similarly significant effects solely by automated means. Subscription access follows the provider-reported subscription state and deterministic entitlement rules; support can review errors, while private-pilot and repository-execution authority remain separate and closed.

Your rights and contact

Subscribers and affected individuals may request access, correction, deletion, restriction, objection, portability where applicable, or information about a transfer by contacting Veyact. Veyact may require proportionate identity verification before disclosing account data.

Individuals may complain to the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg or another competent supervisory authority. Providing or refusing the optional DeepSeek advisory does not affect access to the deterministic local product.