verqen/← Home

Privacy Policy

Effective date: 2026-06-08 · Last updated: 2026-06-08

This Privacy Policy explains what data Verqen collects, how we use it, and your rights. It is written to be accurate and auditable — we do not claim controls we do not have.

1. Who we are

Verqen is an AI code-review service for typed codebases, operated by German Kosach, the Netherlands ("Verqen", "we", "us").

For data-protection purposes, where Verqen processes your source code on your behalf, you are the data controller and we are the processor. For your own account and billing data, we are the controller.

2. What we collect

CategoryExamplesSource
Account dataEmail, GitHub identity (username, account ID)You / GitHub via Clerk
Repository metadataRepo names, PR numbers, commit SHAsGitHub App installation
Source code (transient)PR diff + minimal surrounding contextYour repo, during a scan
Review findingsLocation, severity, explanation, masked snippetGenerated by the engine
Billing dataPlan, payment status, invoicesStripe
Usage & meteringScan counts, aggregate token cost, feature usageOur systems
LogsRedacted operational logs (secrets masked)Our systems

We do not collect or store full copies of your repositories.

3. How we handle your source code

This is the part that matters most, so we state it plainly:

By default, no human at Verqen reads your code — it flows machine-to-machine through the pipeline. Operator access for support or debugging is minimized, logged, and never used to train any model.

4. What we send to LLM providers

On the cloud tier, the PR diff + minimal context is sent to our LLM provider (Anthropic and/or OpenRouter) under their data-processing terms, including no-training / zero-retention options where the provider supports them. We never send full repositories — only what the diff review requires. On self-host / Enterprise, the provider is your choice and your contract.

5. How we use data

We do not sell your data, and we do not use your code or findings to train models.

6. Sub-processors

We use the following sub-processors. Business/Enterprise customers receive notice of material changes.

Sub-processorPurposeData exposed
Anthropic / OpenRouterLLM review (cloud tier)PR diff + context
CloudflareDNS, WAF, network edge, accessRequest metadata
HetznerHosting, compute, database, backupsFindings, metadata, transient scan data
ClerkAuthenticationEmail, GitHub identity
StripeBillingBilling data (no code)
PostHogProduct analyticsUsage events, account identifiers

7. Data retention

DataRetention
PR diff / source sent for reviewDuration of the scan only; not persisted afterward
FindingsKept for dashboard history; deletable by you at any time
Content-hash cacheKeyed by commit SHA; findings only, no raw code
LogsRedacted; retained for 30 days
Billing recordsRetained as required by law/accounting

You can delete your org's findings, disconnect repositories, or uninstall the GitHub App at any time. Uninstalling stops all reviews and marks repositories disconnected.

8. Your rights (GDPR and similar)

You have the right to access, correct, delete, export, restrict, or object to the processing of your personal data, and to withdraw consent where processing is based on it. To exercise these rights, contact [email protected]. You may also lodge a complaint with your supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).

9. International transfers

Hosting and database are in the EU (Hetzner). Some sub-processors (e.g. Anthropic) may process data outside the EEA; where they do, transfers are covered by appropriate safeguards such as Standard Contractual Clauses.

10. Security

We describe the actual mechanisms in place. Verqen reduces risk in AI-generated code; it does not guarantee the absence of bugs or vulnerabilities, and should not be the sole gate for safety-critical systems.

11. AI transparency (EU AI Act)

Verqen is an advisory tool operated with human oversight: findings are suggestions and the developer decides what to act on. The system can miss issues and can produce false positives. It is one layer of review, not a substitute for security testing.

12. Cookies

We use strictly necessary cookies for authentication and session management (via Clerk), and product-analytics cookies (PostHog) to understand and improve the service. You can request opt-out of analytics at [email protected].

13. Data Processing Agreement

Business and Enterprise customers can request a Data Processing Agreement (DPA) at [email protected].

14. Changes

We may update this policy; the "Last updated" date reflects the latest version. Material changes will be communicated to account holders.