Legal

Privacy Policy

Effective 2026-06-05. This policy explains what data Steward collects, why, and what you can do about it. Plain language; defined terms tracked against the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

1. Scope

TrendVidia, LLC ("we", "us") operates Steward. This policy covers the Steward web app, GitHub App, and API. It doesn't cover GitHub's own handling of your data — review the GitHub Privacy Statement for that.

2. What we collect

Account data (from GitHub OAuth):

  • GitHub numeric id, login, email, avatar URL.
  • Display name (operator-set; optional).
  • OAuth-token scope and capture time (the encrypted token itself, when present).

Service usage data:

  • Installation metadata for the GitHub repositories you connect.
  • Pull-request, contributor, and evaluation records for repositories Steward governs.
  • Governance configuration you author.
  • Contributor reports you generate.
  • Audit log of every action you (or staff on your behalf) take.

Billing data (from our payment processor):

  • Plan, subscription status, billing email, country/region for tax determination.
  • We don't see your card number or full PAN — the payment processor handles that end-to-end.

Telemetry:

  • IP address + User-Agent on authenticated requests (audit log only).
  • Aggregated request metrics (no per-request body capture in metrics).
  • Application logs (errors, lifecycle events) shipped to a managed log store for observability.

3. Why we collect it

  • Operate the service. Without account + repo data, Steward can't authenticate you or govern your repositories.
  • Bill you. Plan + payment data flows to our payment processor so it can charge you correctly and remit applicable tax.
  • Secure the platform. IP + User-Agent in the audit log help us trace abuse, account takeover, and incident response.
  • Improve the service. Aggregate metrics inform reliability work. We do not train AI models on your code or governance data.
  • Comply with law. Records may be retained or disclosed when legally required.

4. Service providers (subprocessors)

We route customer data through subprocessors to operate the Service. Each is bound to confidentiality and security obligations consistent with this policy. We describe the categories below; the current named subprocessor list is available on request from privacy@trendvidia.com and we'll update the named list ahead of onboarding any new subprocessor.

CategoryPurpose
Identity providerOAuth + OIDC sign-in. Handles your authentication handshake; we receive identity claims, not your provider credentials.
Repository platformSource of webhook deliveries and repo content for the repositories you connect to Steward.
Compute hostingRuns the application workloads (web, worker, authorization service).
Managed databasePrimary durable store for users, governance configuration, evaluation history, and audit log. TLS-enforced + at-rest encryption.
Payment processorSubscription billing, tax determination, payment processing. Cardholder data never reaches our systems.
AI inference providersLarge-language-model inference and vector embedding for evaluation summaries, governance generation, contributor reports — unless you Bring Your Own Key.
Edge / CDN providerContent delivery, DDoS protection, bot challenge on contact forms.
Observability providerMetrics + log aggregation for operational monitoring. No customer content is shipped to log streams by design.
Operational alertingInternal-only — alerts on infrastructure health. No customer content in alert bodies.

5. AI routing & Bring Your Own Key (BYOK)

By default, AI-driven features route through our own provider accounts (large-language-model inference + vector embedding). We don't retain prompts and completions beyond the period needed to deliver the result, surface it in your history, and respect quota; we don't train models on your data.

When you Bring Your Own Key (BYOK), prompts and completions route through the provider account that you control, and our role is limited to forwarding the request. Your key is encrypted at rest with envelope encryption (AES-256-GCM) — see /security.

Private-repo content is excluded from contributor reports unless you explicitly opt in via Account → Privacy.

6. Cookies & tracking

We use a single first-party session cookie (steward_session) to keep you signed in. We don't run third-party advertising or analytics trackers on the marketing surface. Our edge/CDN provider may set its own cookies as part of bot-challenge rendering on /contact.

7. Retention

Account data: retained while your account is active. Deletion via /app/account tombstones the row; identifying fields are nulled and the GitHub id is detached on the same call.

Audit log: retained for the lifetime of the linked tenant for compliance + security investigation. After account deletion, the audit row stays linked to a deleted-user sentinel.

Evaluation history: retained while your subscription is active and for a reasonable transition window after cancellation.

Operational logs: retained for a short rolling window (approximately 14 days at time of writing) per our observability provider's policy.

8. Your rights

Subject to applicable law, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to processing or withdraw consent. To exercise these rights, email privacy@trendvidia.com.

For most users, /app/account covers the everyday cases — view your profile, edit your display name, revoke OAuth + API tokens, and trigger account deletion. We respond to verifiable rights requests within 30 days.

California residents: we do not sell or share personal data for cross-context behavioural advertising. You have the rights described in the CCPA/CPRA — access, deletion, correction, opt-out of sale/share (no-op for us), limit use of sensitive personal information.

9. International transfers

We're headquartered in the United States. Your data may be processed in the US, the EU, and other countries where our processors operate. For transfers from the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses with subprocessors and other lawful transfer mechanisms.

10. Children's privacy

Steward is not directed at children under 16. If you believe a child has provided us personal data, email privacy@trendvidia.com and we will delete it.

11. Changes

We may update this policy. The Effective date at the top reflects the current version. Material changes will be announced by email to the account billing contact and in-app to active users.

TrendVidia, LLC · Last updated 2026-06-05