calma← Back to CalmaPrivacy Policy
This policy explains what Calma collects, why, how long we keep it, and the choices you have. Our approach is to collect as little as we need and to hold your code only for as long as it takes to verify it.
1. Who we are
Calma provides a service that re-runs a repository and independently verifies the numbers it reports. This policy applies to that service and to our website. For the code and data inside a repository you connect, we act as a processor on your behalf; for your account and how you use the product, we act as a controller.
2. What we collect
Account information
When you sign in, our identity provider gives us your name, email address, and a user identifier. If you sign in with SSO, we receive the attributes your organization releases.
Repository and run content
To verify a repository, we clone it into an isolated sandbox and execute it. During a run we process the repository’s code, any committed data and result files, and the outputs the run produces. We only access repositories you explicitly connect.
Results and metadata
We store the verification results, verdicts, and run metadata (such as the repository reference, timing, status, and logs) so you can view your history in the dashboard.
Usage and device data
Like most services, we log basic technical data — IP address, browser type, timestamps, and in-product actions — for security, debugging, and analytics.
3. How we use information
- to run the verifications you request and show you results;
- to operate, secure, and improve the service;
- to authenticate you and prevent abuse of our sandboxes;
- to communicate with you about the service; and
- to comply with legal obligations.
We do not sell your personal information, and we do not use your code or data to train AI models.
4. Legal bases (GDPR)
Where the GDPR applies, we process personal data to perform our contract with you (running verifications, providing your account), for our legitimate interests(securing and improving the service), to meet legal obligations, and with your consent where required (for example, non-essential cookies).
5. Sub-processors
We use the following service providers to run Calma. Each is bound by a data-processing agreement and processes data only to provide its service to us.
| Provider | Purpose | Location |
|---|---|---|
| WorkOS | Authentication and identity (sign-in, SSO) | USA |
| Vercel | Web application hosting and delivery | USA / global edge |
| Fly.io | Verification engine hosting | USA / global |
| E2B | Network-isolated sandboxes for running your code (CPU) | USA |
| Modal | Sandboxes for running your code (GPU) | USA |
| Anthropic | AI assistance for run planning (no training on your content) | USA |
| GitHub | Reading the repositories you connect | USA |
| Supabase | Application database (account and run metadata) | USA / EU |
We will give reasonable notice before adding a new sub-processor that handles your content, so you can object.
6. Data retention
The sandbox that runs your code is ephemeral: it is created for a run and destroyed when the run ends, and the cloned copy of your repository is not kept afterward. We retain verification results and run metadata for as long as your account is active so you can review them, and we retain account information for the life of your account. When you delete a run or close your account, we delete the associated data from our live systems within 30 days; residual copies in encrypted backups age out on a rolling basis. We may retain limited records longer where the law requires it.
7. Security
- encryption in transit (TLS) and at rest;
- untrusted code runs only inside network-isolated sandboxes, separated from our systems;
- scoped access controls and least-privilege internal access;
- tenant isolation so one customer cannot reach another’s data; and
- signed, replayable verification receipts rather than retained raw data.
No system is perfectly secure, but we work to protect your data and to respond quickly to incidents.
8. International transfers
We and our sub-processors may process data in the United States and other countries. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict your personal data, and to object to certain processing. If you are in California, you may request to know, delete, and correct your information, and to opt out of “sale” or “sharing” — which we do not do. We will not discriminate against you for exercising these rights. To make a request, email privacy@trycalma.ai; we respond within the timeframes the law requires.
10. Cookies
We use strictly necessary cookies to keep you signed in and to secure the service, and limited analytics to understand usage. You can control non-essential cookies through your browser.
11. Children
Calma is not directed to children under 16, and we do not knowingly collect their personal data.
12. Changes
We may update this policy. If a change is material, we will take reasonable steps to notify you and will update the date above.
13. Contact
Questions or requests? Email privacy@trycalma.ai.
This document is a plain-language starting point written for clarity, not a substitute for legal advice. Have counsel review and localize it, and confirm the sub-processor list and retention windows match your production setup, before you rely on it.