This Privacy Policy explains what information Verglas LLC (“Verglas”, “we”, “us”) collects when you visit perchscan.com or use Perch Cloud (the “Service”), how we use it, and the choices you have.

The open-source Perch CLI runs on your computer. When it is not connected to Perch Cloud, it sends us nothing, and your code goes only to the model provider you configure.

Information we collect

Account information. When you sign up or sign in, with GitHub or an emailed code, we receive your email address, your name if available, and an account identifier from our identity provider. When you connect GitHub, we receive your GitHub account name and the repositories you choose to share with the Perch GitHub App.

Workspace information. Workspace names, members and their roles, invitations, repository names and settings, CI configuration, and hashed CI credentials.

Code submitted for analysis. When a scan uses Perch Cloud, the relevant source code and rule questions are sent through the Service to our model provider to be analyzed. We do not store your source code after the analysis. We keep a one-way hash of each analysis request together with its answer, so that unchanged code can be answered from the cache.

Scan results. File paths, function and method names, line numbers, findings, scan status, and timing, shown in your dashboard and posted to your pull requests if you enable that.

Usage and billing. Credit used, cached results served, model token counts, requests, and the member or CI credential they are attributed to. Credit balance, auto reload settings, and purchase history. Payment card details are collected and stored by Stripe, not by us.

Forms on perchscan.com. If you ask to be notified or contact us, we collect the email address and any name, company, and message you provide, along with your approximate country.

Site analytics. We count page views and actions on perchscan.com, such as copying the install command, together with the page path and any campaign tags in the link you followed. We do not use a visitor identifier or advertising cookies. Campaign tags are kept in your browser’s session storage for the visit.

Technical data. Our hosting provider processes IP addresses, browser user agents, and request logs to deliver the Service, prevent abuse, and limit sign-in attempts.

Cookies

Perch Cloud uses only cookies needed to sign you in and keep you signed in securely. These cover your session and short-lived sign-in state. We do not use cookies for advertising or cross-site tracking.

How we use information

We use information to provide and secure the Service; to authenticate you; to run analyses and show results; to meter usage and bill you; to send service emails such as sign-in codes, receipts, and low-balance notices; to respond to support requests; to understand how the site and Service are used in aggregate; and to comply with law. We do not sell personal information, and we do not use your code to train machine learning models.

Service providers

We share information with providers that process it on our behalf to run the Service:

We may also disclose information if required by law, to protect the rights and safety of users or others, or as part of a merger, acquisition, or sale of assets.

Retention and deletion

We keep account and workspace information while your account is active. Cached analysis answers are kept until storage limits remove the least recently used ones or your workspace is deleted. When you delete your account from Settings, we delete the workspaces you own, including their scans, findings, cached answers, repositories, and credentials, and remove you from other workspaces. We keep billing records for as long as tax and accounting law requires.

Security

We use encryption in transit, hashed credentials, scoped access tokens, and access controls to protect information. No method of transmission or storage is completely secure.

Your choices and rights

You can view and update your profile in Settings, disconnect GitHub, and delete your account at any time. Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or to object to certain processing. To make a request, email support@perchscan.com. We will not discriminate against you for exercising these rights.

International transfers

Verglas is based in the United States, and our service providers may process information in the United States and other countries.

Children

The Service is not directed to children under 16, and we do not knowingly collect their personal information.

Changes

We may update this Privacy Policy. If we make material changes, we will update the effective date and ask you to agree to the new version when you next sign in, or notify you by email.

Contact

Verglas LLC, Oregon, United States. Email support@perchscan.com.