Privacy policy
What this site collects, why, how long it is kept, and how to have it deleted. Written to be read rather than to be survived.
Last updated 21 September 2026
The short version
- — Code you paste into the tools is sent to Anthropic to produce the result. It is not used to train any model.
- — We keep the result of a review and a one-way hash of what you submitted. We do not store the raw code you pasted.
- — The contact form stores what you type in it, so we can reply.
- — We do not sell anything to anyone, and there is no advertising or third-party tracking on this site.
- — Email robert.alfaro@nuvez.net and we will delete what we hold about you.
What we collect, and why
Code and descriptions you submit to the tools
The IaC Review, Code Review, Resource Optimization, IaC Generator and App Generator all take what you type or paste and send it to Anthropic's API, which produces the result you see. Anthropic processes it to serve that request and does not use it to train models.
When a review completes we store a record of it: the review output, a one-way hash of your input, the file name if you gave one, and the severity counts. The raw code you pasted is not written to our database. Be aware that the review output itself may quote short fragments of your code where it is explaining a finding.
Please do not paste live credentials, private keys or secrets. If you do, tell us and we will delete the record straight away.
The contact form
Your name, email address, the topic you picked, your message, and whether you ticked the newsletter box. It is stored so the enquiry is not lost, and emailed to us so we see it. We use it to reply to you and for nothing else.
Usage and diagnostics
We record which pages are requested, along with the IP address the request came from, the browser's user-agent string, and a derived device type. We also use Microsoft Application Insights for performance and error telemetry. This is how we find out that something is broken; it is not used to build a profile of you or shared with advertisers.
If you sign in
The dashboard and admin areas use Microsoft Entra ID. When you sign in we receive and store your account identifier, your email address and your display name, so we know who is allowed to see what. We never receive your password.
The App Generator and GitHub
To prove a generated project actually builds, the App Generator pushes it to a private, throwaway GitHub repository under our own account, runs it on GitHub Actions, reads the result, and then deletes the repository. Your description of the application reaches GitHub only as part of the generated code.
Who else processes it
We are a small company and we do not build our own infrastructure. These are the services that handle your data on our behalf. There are no others, and no advertising or analytics networks.
| Who | What they receive | Why |
|---|---|---|
| Microsoft Azure | Everything — hosting, database, file storage, email delivery, sign-in, telemetry | The application runs here |
| Anthropic | The code, Terraform or description you submit to a tool | Produces the review or generated output |
| GitHub | Generated projects only — never code you submitted for review | CI verification, in a throwaway repository that is then deleted |
How long we keep it
- — Usage and activity records: automatically deleted after 90 days.
- — Review records: kept so that a finding from months ago is still there when someone asks why a decision was made. Deleted on request.
- — Contact submissions: kept while we are talking to you and for our own records afterwards. Deleted on request.
- — Throwaway CI repositories: deleted at the end of the run that created them.
Cookies
This site sets cookies only where it has to: one to keep you signed in if you sign in, and one to protect forms against cross-site request forgery. There are no advertising cookies and no third-party trackers, which is why you are not being asked to dismiss a consent banner.
Security
Traffic is encrypted in transit with TLS, and data is encrypted at rest by the Azure services that hold it. Access to production runs through managed identities rather than stored keys, and secrets live in Azure Key Vault. Access to your data is limited to the people who need it to run the service — which, today, is a very short list.
We are not SOC 2 or ISO 27001 certified. We would rather say that plainly than imply otherwise. If you need a security review before sending us anything, ask and we will answer your questionnaire directly.
Your choices
You can ask us what we hold about you, ask for a copy of it, ask us to correct it, or ask us to delete it. Depending on where you live you may have these rights under the GDPR, the UK GDPR or the CCPA; we will honour the request either way rather than asking you to prove which one applies.
We do not sell personal information and we do not share it for cross-context behavioural advertising.
Children
This is a service for professional engineering teams. It is not directed at children and we do not knowingly collect information from anyone under 16.
Changes, and how to reach us
If this policy changes materially we will update the date at the top of this page. We will not quietly broaden what we do with data you have already sent us.
Questions, or a deletion request: robert.alfaro@nuvez.net . Nuvez, LLC, Minneapolis, MN
See also our terms of service.