Calmacalma← Back to Calma

Privacy Policy

Effective July 6, 2026 · Last updated July 6, 2026

This policy explains what Calma collects, why, how long we keep it, and the choices you have. Our approach is to collect as little as we need and to hold your code only for as long as it takes to verify it.

1. Who we are

Calma provides a service that re-runs a repository and independently verifies the numbers it reports. This policy applies to that service and to our website. For the code and data inside a repository you connect, we act as a processor on your behalf; for your account and how you use the product, we act as a controller.

2. What we collect

Account information

When you sign in, our identity provider gives us your name, email address, and a user identifier. If you sign in with SSO, we receive the attributes your organization releases.

Repository and run content

To verify a repository, we clone it into an isolated sandbox and execute it. During a run we process the repository’s code, any committed data and result files, and the outputs the run produces. We only access repositories you explicitly connect.

Results and metadata

We store the verification results, verdicts, and run metadata (such as the repository reference, timing, status, and logs) so you can view your history in the dashboard.

Usage and device data

Like most services, we log basic technical data — IP address, browser type, timestamps, and in-product actions — for security, debugging, and analytics.

3. How we use information

  • to run the verifications you request and show you results;
  • to operate, secure, and improve the service;
  • to authenticate you and prevent abuse of our sandboxes;
  • to communicate with you about the service; and
  • to comply with legal obligations.

We do not sell your personal information, and we do not use your code or data to train AI models.

4. Legal bases (GDPR)

Where the GDPR applies, we process personal data to perform our contract with you (running verifications, providing your account), for our legitimate interests(securing and improving the service), to meet legal obligations, and with your consent where required (for example, non-essential cookies).

5. Sub-processors

We use the following service providers to run Calma. Each is bound by a data-processing agreement and processes data only to provide its service to us.

ProviderPurposeLocation
WorkOSAuthentication and identity (sign-in, SSO)USA
VercelWeb application hosting and deliveryUSA / global edge
Fly.ioVerification engine hostingUSA / global
E2BNetwork-isolated sandboxes for running your code (CPU)USA
ModalSandboxes for running your code (GPU)USA
AnthropicAI assistance for run planning (no training on your content)USA
GitHubReading the repositories you connectUSA
SupabaseApplication database (account and run metadata)USA / EU

We will give reasonable notice before adding a new sub-processor that handles your content, so you can object.

6. Data retention

The sandbox that runs your code is ephemeral: it is created for a run and destroyed when the run ends, and the cloned copy of your repository is not kept afterward. We retain verification results and run metadata for as long as your account is active so you can review them, and we retain account information for the life of your account. When you delete a run or close your account, we delete the associated data from our live systems within 30 days; residual copies in encrypted backups age out on a rolling basis. We may retain limited records longer where the law requires it.

7. Security

  • encryption in transit (TLS) and at rest;
  • untrusted code runs only inside network-isolated sandboxes, separated from our systems;
  • scoped access controls and least-privilege internal access;
  • tenant isolation so one customer cannot reach another’s data; and
  • signed, replayable verification receipts rather than retained raw data.

No system is perfectly secure, but we work to protect your data and to respond quickly to incidents.

8. International transfers

We and our sub-processors may process data in the United States and other countries. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict your personal data, and to object to certain processing. If you are in California, you may request to know, delete, and correct your information, and to opt out of “sale” or “sharing” — which we do not do. We will not discriminate against you for exercising these rights. To make a request, email privacy@trycalma.ai; we respond within the timeframes the law requires.

10. Cookies

We use strictly necessary cookies to keep you signed in and to secure the service, and limited analytics to understand usage. You can control non-essential cookies through your browser.

11. Children

Calma is not directed to children under 16, and we do not knowingly collect their personal data.

12. Changes

We may update this policy. If a change is material, we will take reasonable steps to notify you and will update the date above.

13. Contact

Questions or requests? Email privacy@trycalma.ai.

This document is a plain-language starting point written for clarity, not a substitute for legal advice. Have counsel review and localize it, and confirm the sub-processor list and retention windows match your production setup, before you rely on it.