Skip to content

Privacy policy

What this site collects, why, how long it is kept, and how to have it deleted. Written to be read rather than to be survived.

Last updated 29 September 2026

The short version

  • — Code you paste into the tools is sent to Anthropic to produce the result. It is not used to train any model.
  • — We keep the result of a review and a one-way hash of what you submitted. We do not store the raw code you pasted.
  • — The App Generator saves each run (your description, choices, plan and generated code) so you can come back to it and share its link. Anyone with the link can view it. It is deleted 30 days after its last change (90 days if you were signed in, and you can extend that), or straight away if you delete it.
  • — We log each App Generator request (what you asked, what came back, its cost, your IP address and browser) and any feedback you give, so we can improve it. Only our administrators see it, and it is deleted after 90 days.
  • — The contact form stores what you type in it, so we can reply.
  • — We do not sell anything to anyone, and there is no advertising or third-party tracking on this site.
  • — Email robert.alfaro@nuvez.net and we will delete what we hold about you.

What we collect, and why

Code and descriptions you submit to the tools

The IaC Review, Code Review, Resource Optimization, IaC Generator and App Generator all take what you type or paste and send it to Anthropic's API, which produces the result you see. Anthropic processes it to serve that request and does not use it to train models.

When a review completes we store a record of it: the review output, a one-way hash of your input, the file name if you gave one, and the severity counts. The raw code you pasted is not written to our database. Be aware that the review output itself may quote short fragments of your code where it is explaining a finding.

Please do not paste live credentials, private keys or secrets. If you do, tell us and we will delete the record straight away.

The contact form

Your name, email address, the topic you picked, your message, and whether you ticked the newsletter box. It is stored so the enquiry is not lost, and emailed to us so we see it. We use it to reply to you and for nothing else.

Usage and diagnostics

We record which pages are requested, along with the IP address the request came from, the browser's user-agent string, and a derived device type. We also use Microsoft Application Insights for performance and error telemetry. This is how we find out that something is broken; it is not used to build a profile of you or shared with advertisers.

If you sign in

The dashboard and admin areas use Microsoft Entra ID. When you sign in we receive and store your account identifier, your email address and your display name, so we know who is allowed to see what. We never receive your password.

The App Generator and GitHub

To prove a generated project actually builds, the App Generator pushes it to a private, throwaway GitHub repository under our own account, runs it on GitHub Actions, reads the result, and then deletes the repository. Your description of the application reaches GitHub only as part of the generated code.

Saved App Generator runs

Each App Generator run is saved as it happens, so refreshing the page doesn't lose it and you can share its link with someone to review. A saved run holds your description and choices, the plan, the diagram, the generated code, and the result of the CI check. It is reached only through its link, which is random and can't be guessed, and anyone you give the link to can view it. Only the browser that created a run can change or delete it. The run page has a Delete this run button.

A run is deleted 30 days after its last change. If you were signed in when you made it, it is listed under My apps and kept for 90 days after its last change, and Keep 90 more days there restarts that. If you ask us, we can keep one permanently; ask us again and we'll put it back on the normal schedule or delete it.

App Generator request log and feedback

So we can see how well the App Generator answers and improve it, we keep a log of each request it sends to the AI and of any feedback you give it: what you typed and chose, any note you added, what came back, how many AI tokens it used and what that cost, how long it took, your IP address and browser, the page that referred you to this site and any campaign tags in its link, and, if you are signed in, your name and email. Only our administrators can see it. Each entry is deleted after 90 days, or sooner if you ask us.

Signing in to the App Generator

Your first app needs no account. To create more, or to rebuild one, you sign in with a Microsoft or Google account. We receive your name, email address and an account identifier from them, and keep you signed in with a cookie for 30 days. We don't get your password. To count the free app, a cookie identifies your browser and we note your IP address; both are forgotten after 30 days.

Who else processes it

We are a small company and we do not build our own infrastructure. These are the services that handle your data on our behalf. There are no others, and no advertising or analytics networks.

Who What they receive Why
Microsoft Azure Everything — hosting, database, file storage, email delivery, sign-in, telemetry The application runs here
Anthropic The code, Terraform or description you submit to a tool Produces the review or generated output
GitHub Generated projects only — never code you submitted for review CI verification, in a throwaway repository that is then deleted

How long we keep it

  • — Usage and activity records: automatically deleted after 90 days.
  • — Review records: kept so that a finding from months ago is still there when someone asks why a decision was made. Deleted on request.
  • — Contact submissions: kept while we are talking to you and for our own records afterwards. Deleted on request.
  • — Throwaway CI repositories: deleted at the end of the run that created them.
  • — Saved App Generator runs: automatically deleted 30 days after their last change, or when you delete them.

Cookies

This site sets cookies only where it has to: one to keep you signed in if you sign in, and one to protect forms against cross-site request forgery. There are no advertising cookies and no third-party trackers, which is why you are not being asked to dismiss a consent banner.

Security

Traffic is encrypted in transit with TLS, and data is encrypted at rest by the Azure services that hold it. Access to production runs through managed identities rather than stored keys, and secrets live in Azure Key Vault. Access to your data is limited to the people who need it to run the service — which, today, is a very short list.

We are not SOC 2 or ISO 27001 certified. We would rather say that plainly than imply otherwise. If you need a security review before sending us anything, ask and we will answer your questionnaire directly.

Your choices

You can ask us what we hold about you, ask for a copy of it, ask us to correct it, or ask us to delete it. Depending on where you live you may have these rights under the GDPR, the UK GDPR or the CCPA; we will honour the request either way rather than asking you to prove which one applies.

We do not sell personal information and we do not share it for cross-context behavioural advertising.

Children

This is a service for professional engineering teams. It is not directed at children and we do not knowingly collect information from anyone under 16.

Changes, and how to reach us

If this policy changes materially we will update the date at the top of this page. We will not quietly broaden what we do with data you have already sent us.

Questions, or a deletion request: robert.alfaro@nuvez.net . Nuvez, LLC, Minneapolis, MN

See also our terms of service.