Introduction
Uzera Inc. ("Uzera," "we," "us," or "our") provides the independent knowledge layer for coding agents. This Privacy Policy explains what personal information we collect, how we use it, and what rights you have over it.
This policy applies when you:
- Register for an account at uzera.com;
- Use the Uzera platform, CLI, or APIs; or
- Interact with us by email or support channels.
Our Service is designed for software development teams and their representatives. We do not offer products or services for personal, familial, or household use.
What We Collect
When you create an account, you give us an email address and set a password. That, plus the items below, is the personal information we keep - limited to what we need to run and secure the Service.
| Data | Nature | When | Why |
|---|---|---|---|
| Email address | Stored | Registration | Authentication and account communications |
| Plan status | Stored | On subscription change | Determining which features you can access |
| Operational & product data | Processed | When you use the platform | To provide the platform features you enable (such as governance, code health, memory, and connected-agent visibility) and to keep the Service running and secure |
Where you use platform features, we receive the activity and results needed to power them - for example rule and governance events, quality findings, and basic details about the coding agents connected to your workspace. We keep this to what those features require, and we keep the operational logging needed to run and secure the Service.
Your source code is different. It does not appear in this table because its contents never reach us. Uzera analyzes your code where it already lives - on your own machine - and we receive no copy of it. Section 3 explains how that works.
How Scanning Works
Local onlyUzera scans source code. Uzera does not collect source code. Those are two different things, and the difference is where the work happens.
The scan runs on your machine
Scanning is performed by Uzera software running locally - our CLI or local integration, executing on your own hardware inside your own environment. It reads the source files and diffs in the repositories you point it at, evaluates them against the rules you have configured, and returns the result to you. Every step of that happens in local memory, on your machine.
Your source code is never transmitted to Uzera. We hold no copy, no cache, no log, no queue, and no backup of it. There is no upload step to disable, because there is no upload.
Your code stays with you
The scan reads your source files in local memory on your machine and evaluates them there. The contents of your source code, your diffs, and your repository files are never sent to Uzera - we hold no copy of them. When you use platform features such as governance or code health, Uzera receives the results and activity from those features - for example rule events and violation summaries - so you can see them in your workspace, but never the underlying source code itself.
| Never leaves your machine | Used to run the Service |
|---|---|
| Your source code (its contents) | Your account details (email and plan) |
| Diffs and staged changes | The information that keeps you signed in |
| The raw files in your repositories | Activity and results from the platform features you enable |
What this means in practice
Because your code never reaches us, a set of risks simply does not exist between you and Uzera:
- We cannot read your code, because we do not have it.
- We cannot produce it in response to a subpoena, warrant, or government request.
- It cannot be exposed by a breach of Uzera's systems, because it was never in them.
- We cannot use it to train AI models - ours or anyone else's.
- No third party is ever exposed to it, including our infrastructure and cloud providers.
Analysis happens on your device, against code that never stops being yours. Being analyzed is not the same as being collected - and your source code is never collected.
What We Do Not Collect
We deliberately keep our data footprint small. In particular:
- We never collect your source code. The contents of your repositories and local files are never transmitted to or stored by us - analysis happens locally (see Section 3).
- We don't sell your data. We never sell, rent, or license your personal information to anyone.
- We don't run advertising trackers. No advertising cookies, no tracking pixels, no cross-site ad profiles, and no selling of your activity to data brokers.
- We don't build marketing profiles of your behavior or use your data for targeted advertising.
- We don't train AI models on your data. Your source code never reaches us, and we do not use your information to train our models or anyone else's.
- We share personal data only where needed to run the Service - for example our payment processor and email-delivery provider - never for their own purposes.
How We Use Your Information
We use the data we collect only for the following purposes:
- Authentication. Your email and password are used to verify your identity when you sign in.
- Transactional emails. We send account verification, password reset confirmations, and billing receipts from Stripe. These are triggered by actions you take and cannot be opted out of while your account is active.
- Newsletter and product updates. By creating an account, you are automatically subscribed to our newsletter. We use your email to send product news, feature announcements, and company updates. You can unsubscribe at any time using the link in any newsletter email, or by contacting security@uzera.com. We use a third-party email delivery service for this purpose; your email address is shared with that provider solely to deliver these messages. We will name that provider in this policy once one is selected.
- Plan access. Your plan status determines which features are available to you within the Service.
- Providing platform features. When you use the platform, we use operational and product data to deliver the features you enable and to keep the Service reliable and secure.
- Security. In the event of a suspected security incident affecting your account, we may use your email to notify you.
We do not use your information to build advertising profiles, train AI models, or for any purpose not listed above. Your source code cannot be used for any purpose at all - model training included - because we never receive it.
Payment, Billing & Third-Party Services
Payment processing is handled entirely by Stripe, a third-party payment processor. When you subscribe to a paid plan:
- Your card details, billing address, and payment history are held by Stripe, not Uzera.
- Uzera receives only a confirmation of payment and your resulting plan tier (e.g., free, pro).
- Billing receipts are sent by Stripe directly to your email address.
Stripe's privacy practices are governed by the Stripe Privacy Policy.
This policy does not apply to third-party websites or services linked from our platform, including Stripe, our documentation providers, or integration partners. We encourage you to review their privacy policies before providing personal information to any third party.
Cookies
We use only essential cookies - the ones required to sign you in and keep the Service working:
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| Session cookie | Essential | Keeps you signed in between page loads | Expires after a limited period, or when you sign out |
We do not use advertising cookies, analytics cookies, tracking pixels, or other behavioral-advertising technologies. Essential cookies are required to use the Service and cannot be turned off without signing out.
Your Rights
- Access. You may request a copy of the personal information we hold about you at any time.
- Correction. You may correct any personal information we hold by updating your account settings or contacting security@uzera.com.
- Deletion. You may request full deletion of your account and all associated data by contacting security@uzera.com. We process deletion requests within 30 days.
- Unsubscribe from marketing emails. Use the unsubscribe link in any newsletter, or email security@uzera.com. Transactional emails (account verification, password reset) cannot be turned off while your account is active.
To exercise any of these rights, contact security@uzera.com. We aim to respond to all rights requests within 30 days.
Data Retention
| Data | Retention |
|---|---|
| Your source code | Never received by Uzera - it stays on your own machine, under your control |
| Account details (email, password, plan) | Duration of your account, plus a short wind-down period after deletion |
| Session information | Expires after a limited period, or immediately when you sign out |
| Operational & product data | Kept while your account is active and for the period needed to provide the feature, then deleted or aggregated |
| Billing records | As required by Stripe and applicable tax regulations |
Your source code has no retention period with us, because it is never in our possession to retain. Deleting your account does not require us to delete any code - we never had it.
When you delete your account, we remove your account and operational data within 30 days, except where we must retain limited records to meet legal, security, or financial obligations. Billing records held by Stripe are governed by Stripe's own retention policies.
Security
We apply the following safeguards to protect the small amount of data we hold:
- Local-first processing: Your source code is analyzed on your own machine and never enters our infrastructure - so it cannot be exposed by a compromise of it.
- Encryption in transit: Industry-standard TLS on all connections.
- Encryption at rest: Strong, industry-standard encryption for stored data.
- Password hashing: Passwords are stored using a one-way hash and cannot be recovered by Uzera staff.
- Access controls: Role-based access and least-privilege principles for internal systems.
- Monitoring: We maintain the operational logging and safeguards needed to detect and respond to security events.
- Certifications: We are pursuing SOC 2 Type II and ISO 27001, and align our practices to those standards.
No system is completely immune to attack. If we become aware of a confirmed breach affecting your personal data, we will notify affected users within 72 hours of confirmation and inform relevant authorities as required by applicable law.
To report a security vulnerability, contact security@uzera.com.
Changes to This Policy
If we make material changes - such as collecting new categories of data - we will notify you by email at least 30 days before the change takes effect. Minor clarifications or corrections may be made with immediate effect.
We treat the local-code commitment in Section 3 as binding. If this ever changed so that the contents of your source code were transmitted to our servers, that would be a material change: we would give you at least 30 days' notice by email, and it would not apply to existing accounts without your explicit opt-in.
The "Last updated" date at the top of this page will always reflect the most recent revision. Previous versions are available on request.
Contact Us
For privacy-related questions, to exercise your rights, or to report a concern:
Privacy & Security: security@uzera.com
General Support: support@uzera.com
We aim to respond to all privacy inquiries within 30 days.
Children
The Service is intended for use by software development professionals aged 18 and over. We do not knowingly collect personal information from anyone under the age of 13. If we become aware that a child under 13 has provided us with personal data, we will delete it promptly. If you believe a minor has created an account, please contact security@uzera.com.
Governing Law & International Users
This Privacy Policy is governed by the laws of the United States, without regard to conflict of law principles. Any disputes arising under this policy shall be subject to the exclusive jurisdiction of the federal courts of the United States.
The Service is operated from the United States. If you access it from outside the United States, your personal data will be transferred to and processed in the United States. Data protection laws in the United States may differ from those in your country. By using the Service, you acknowledge this transfer.