Privacy Policy

Effective 2026-04-26

1. What we collect

  • Account data. The email address you sign up with, and a Supabase-managed authentication record. We do not store plaintext passwords — Supabase handles credential hashing.
  • Audit submissions. The contract source code, contract name, and (when imported from chain) the contract address and chain ID you provide.
  • Payment data. The wallet address you pay from and the transaction hash for ETH payments. We do not store your private keys; we never see them.
  • Generated artifacts. The audit report and any proof-of-concept code we produce, along with telemetry (token spend, durations, agent counts) used for billing reconciliation.

2. How we use it

  • Run the audit you requested and deliver the report.
  • Bill you for the audit and reconcile payments.
  • Diagnose issues and improve the agents' accuracy.
  • Send you transactional email about your audits (completion, failure, refund). We do not send marketing email without explicit opt-in.

3. Who else sees it

Audit submissions are processed by third-party model providers (currently Anthropic and OpenAI for some agents). The contract source is sent to those providers as part of the prompt; their privacy and data-retention policies apply during that processing window.

Audit reports are pinned to IPFS via Pinata. IPFS content is publicly addressable by CID; if you do not want a report on IPFS, contact us before submission and we'll skip the pin step.

We do not sell, rent, or share your data with advertisers.

4. Retention

We retain audit jobs and reports for as long as your account is active. On account deletion, we remove the database row and stop showing the report through our service. Content already pinned to IPFS persists on the IPFS network independently of our database; we cannot guarantee global IPFS unpinning.

5. Your rights

You may request a copy of your data, ask us to delete your account, or correct inaccurate information by emailing info@devoltfi.com. We respond within 30 days.

6. Security

Data in transit is encrypted via TLS. Database access is restricted to service-role keys held in our infrastructure provider's secret store. Internal access to user data is limited to engineers debugging specific reported issues.

7. Children

VOLTAudit is not directed at children under 16. We do not knowingly collect data from minors.

8. Changes

We will update this policy as the service evolves. Material changes will be linked from the homepage and announced to active users.

TermsPrivacyRefundsLast updated 2026-04-26