Privacy Policy

Last updated: June 2026

1. Introduction & Scope

Welcome to Verto ("we," "us," or "our"). Verto provides AI-powered pre-deployment checks for GitHub Pull Requests. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our dashboard, GitHub App, and related services (collectively, the "Service"). By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the Service immediately.

This policy applies to all users of Verto, including those who access the Service via our website, dashboard, or the Verto GitHub App installed on their repositories.

2. Information We Collect

We collect the following categories of information:

  • GitHub Data via OAuth: When you authenticate with GitHub, we receive your GitHub username, email address, profile avatar, and a list of repositories where the Verto GitHub App is installed. We request read and write access to Pull Requests on your selected repositories.
  • Account Data via Clerk: We use Clerk as our authentication provider. Clerk collects and manages your account credentials, session tokens, email address, and profile information on our behalf.
  • Pull Request Diffs for Analysis: When a Pull Request is opened or updated on a repository where Verto is installed, we temporarily retrieve the code diff (the changes introduced in the PR) for the sole purpose of performing automated AI-powered analysis. We do not download or store your entire codebase.
  • Usage Data: We may collect information about how you interact with the Service, including pages visited, features used, and timestamps of activity.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service, including running AI-powered checks on your Pull Requests.
  • Authenticate your identity and manage your account.
  • Display your check history, repository status, and dashboard analytics.
  • Communicate with you about service updates, security alerts, and support inquiries.
  • Improve and optimize the Service, including analyzing usage patterns and fixing bugs.
  • Comply with legal obligations and enforce our Terms of Service.

Your code is never used to train our AI models or any third-party AI models.

4. Third-Party Services

We rely on the following third-party services to operate Verto:

  • Clerk — Handles user authentication, session management, and account security. Clerk processes your login credentials, email address, and session data. For more information, see Clerk's Privacy Policy.
  • Groq— Powers our AI analysis engine. Pull Request code diffs are sent securely to Groq's API for the purpose of generating automated feedback and suggestions. Groq does not retain your code data beyond the scope of the API request. For more information, see Groq's Privacy Policy.
  • Neon— Provides our serverless PostgreSQL database infrastructure. Analytical metadata (repository names, PR numbers, check statuses) is stored in Neon's managed database.

We do not sell, rent, or share your personal data with third parties for their own marketing purposes.

5. Data Retention

We retain only analytical metadata — such as repository names, Pull Request numbers, check timestamps, and pass/fail statuses — to power your dashboard history and analytics. We do not persistently store raw code diffs or source code in our database. Code diffs are processed in-memory during analysis and are discarded immediately after the check completes.

Account data is retained for as long as you maintain an active Verto account. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law.

6. Data Security

We take the security of your data seriously and implement the following measures:

  • HTTPS Encryption: All data transmitted between your browser, our servers, and third-party services is encrypted using TLS/HTTPS.
  • Encrypted Storage: Data at rest in our database is encrypted using industry-standard encryption algorithms.
  • Access Controls: Access to production systems and user data is restricted to authorized personnel only, using role-based access controls and multi-factor authentication.

While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to following industry best practices.

7. Cookies & Tracking

Verto uses cookies primarily for authentication and session management. Specifically, Clerk sets session cookies to keep you logged in and to verify your identity across requests. These are essential cookies required for the Service to function.

We do not use third-party advertising cookies or cross-site tracking technologies. We may use minimal analytics to understand Service usage, but we do not build advertising profiles from your data.

8. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, by sending a notification via email or through the dashboard. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.

9. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: akarshkushwaha593@gmail.com

We aim to respond to all inquiries within 30 business days.