Skip to content
Vallit
Pricing
  • Checks
  • Reports
  • Fixes
  • Monitoring
  • Trust page
  • Vera
  • Getting started
  • What we check
  • Reading a report
  • Fixing what we found
  • The guardian
  • Alerts
  • Privacy and safety
  • Troubleshooting
  • Browse all docs
  • Research
  • Updates1.15.236
  • Security
  • About
Check my appSign in

Product

ChecksEverything we look at, on your site and in your codeReportsYour score and every finding, in plain wordsFixesFix it yourself, or let our team do itMonitoringWe keep checking, every single dayTrust pageShow your customers what passedVeraOur AI, which checks its own work

Docs

Getting startedWhat we checkReading a reportFixing what we foundThe guardianAlertsPrivacy and safetyTroubleshootingBrowse all docs

Resources

ResearchUpdatesSecurityAbout
PricingSign inCheck my app

Privacy policy

What data we process on vallit.net and in the app, why, with whom and for how long.

DeutschEnglish
Last updated
8 October 2026
Controller
Theo Reichert, Vallit
Cookies on this website
None
Questions
info@vallit.net

On this page

  1. 1Controller
  2. 2What this covers
  3. 3What we never do with your data
  4. 4How we handle your code
  5. 5Visiting the website
  6. 6The free check
  7. 7Account and sign-in
  8. 8Features of the app
  9. 9Payment
  10. 10Measurement in the app
  11. 11Cookies and browser storage
  12. 12Checked apps and our checker
  13. 13Recipients and processors
  14. 14Security
  15. 15How long we keep data
  16. 16Your rights
  17. 17What you must provide, and no automated decisions
  18. 18Changes
On this page
  1. 1Controller
  2. 2What this covers
  3. 3What we never do with your data
  4. 4How we handle your code
  5. 5Visiting the website
  6. 6The free check
  7. 7Account and sign-in
  8. 8Features of the app
  9. 9Payment
  10. 10Measurement in the app
  11. 11Cookies and browser storage
  12. 12Checked apps and our checker
  13. 13Recipients and processors
  14. 14Security
  15. 15How long we keep data
  16. 16Your rights
  17. 17What you must provide, and no automated decisions
  18. 18Changes

1Controller

The controller for personal data on this website and in the app is:

Theo Reichert
Vallit
Parkstraße 1
76131 Karlsruhe
Germany
Email: info@vallit.net

All details are in the legal notice. For any question about privacy, write to info@vallit.net.

2What this covers

This policy covers

  • the website vallit.net, with the documentation at /docs and the updates at /updates,
  • the app at app.vallit.net, where you have apps checked, keep an account and buy a plan, and
  • our checker, which visits apps at their owners’ request.

In short: the website sets no cookies, measures no visits and loads nothing from other providers. We process personal data only once you write to us or use the app, and then only what that needs.

3What we never do with your data

  • We never sell data and pass none to ad networks or data brokers.
  • We do not analyse your data for our own purposes. What we see when we check your app, meaning findings, reports and code, we use only for your report, your monitoring and fixes you ask for. Not for advertising, not for profiles of you, not for statistics we pass on.
  • We do not train AI models on your code, your findings or your conversations.
  • We never store the secrets we find. Of an exposed key we record only its kind and where it was, never the key itself.
  • We read only what you allow: the pages your app already shows to everyone, and your code only if you connect a repository, and then read-only.
  • No tracking on this website: no cookies, no analytics, no content from other providers.
  • Our service providers process data only on our behalf and on our instructions, never for their own purposes. The exception is Stripe for payments (section 9).

4How we handle your code

If you connect a repository:

  • Read, and pull requests only with permission. Vallit’s GitHub App reads your code. If you also allow it in GitHub, it proposes fixes as a pull request on a branch of its own; it does not change your main branch or your settings, and only what you merge is applied.
  • Only what you share. You choose in GitHub which repositories the app may see, and you can revoke its access there at any time.
  • In memory, for one check. We load your code into memory for a check, without cloning it, writing it to disk or running it. The report says where a finding is.
  • Only excerpts go to a language model, and only to confirm a specific finding (section 8). Nothing is trained on them.

You don’t have to connect a repository: the check of your address works without access to your code.

5Visiting the website

Hosting and server logs

The website is served by Vercel Inc. (USA). On every visit Vercel processes the data needed to deliver it: your IP address, date and time, the address requested, the page you came from (referrer), and your browser and operating system (user agent). This is needed to deliver the page, fend off attacks and find errors. Vercel keeps these logs only for a short time.

The legal basis is our legitimate interest in a secure, working website (Art. 6(1)(f) GDPR).

No cookies, no analytics, no third-party content

The website sets no cookies and uses no analytics or tracking tools. We serve fonts and scripts ourselves. Your browser loads the pictures of our updates from app.vallit.net, our own app at the same host; the same applies as for the server logs above. Your browser makes no requests to third parties. A consent banner is therefore not needed.

In the documentation your browser remembers in its session storage which view of a screenshot you chose. This entry never leaves your device and is deleted when you close the tab (§ 25(2) no. 2 TDDDG).

Our server fetches the texts on /updates and in the footer from app.vallit.net once an hour. No data about you is sent. The language of this page follows your browser’s language setting; we store nothing for that either.

Contact form and email

When you write to us through the contact form (at /contact and on the pricing page), we send your name, email address, company, the number of your apps and your message as an email through Resend to our mailbox. The website itself stores none of it. To limit misuse, our server briefly counts how often your IP address writes (at most five messages in ten minutes); this count lives only in memory and is not stored. A hidden field and a timing check keep bots out, without any third-party service.

If you email us directly, we process your address and your message the same way. The legal basis is Art. 6(1)(b) GDPR where it concerns a contract or an enquiry about one, otherwise our legitimate interest in answering you ((f)). Our mailbox is run by Apple (iCloud Mail). We delete the correspondence once it is settled and no retention duty applies.

6The free check

When you have an address checked in the app, we process

  • the address of the app you have checked, and the result of the check,
  • your confirmation that you run the app or were asked to check it, with the time,
  • a hash of your IP address, which limits the number of checks (at most five an hour). Your IP address cannot be read from it directly, but it is pseudonymous, not anonymous,
  • if you give it, your email address, to which we send the finished report.

The legal basis is carrying out the check you asked for (Art. 6(1)(b) GDPR); the limit and the confirmation serve our legitimate interest in preventing misuse and being able to show that a check was requested ((f)).

We use your email address only to send you the report, never for marketing. When a check with an email address comes in, we are notified internally so we can help with questions.

We delete checks without an account after 90 days.

7Account and sign-in

For an account we process your email address, your name, your organisation’s name and the members you invite. Sign-in, confirmation codes, sessions and the check that a human is signing in are handled by Clerk, Inc. (USA), which also processes your IP address and browser for this. Passwords are handled by Clerk alone; we never receive them.

If you sign in with Google or Apple, we receive your name and email address from them. Their privacy notices apply to that sign-in as well.

The legal basis is the contract of use (Art. 6(1)(b) GDPR); fending off automated sign-ins serves our legitimate interest in a secure service ((f)). We keep your account data until you delete the account or the organisation.

8Features of the app

Apps, reports and monitoring

We store the apps you add, their reports and their findings. If you have an app monitored, we visit it every five minutes and store the status code and response time; we delete these measurements after 90 days. When it goes down, when it recovers and in the daily summary, we email the address you set for this.

Proving that a domain is yours

You prove it with a DNS record. If you give us a Cloudflare access token for this, we use it once to create the record and do not store it. If you choose the way through your domain provider (Domain Connect), we send you there, and its privacy notice applies.

Connected repositories

If you connect a GitHub repository, we download its contents at every check through Vallit’s GitHub App (GitHub, Inc., USA) and analyse it for your report. To confirm findings in the source code, we send individual code excerpts through Vercel’s AI Gateway to language models by Anthropic PBC (USA). This happens only if you have connected a repository.

Fixes by us

When you ask for a fix, a person at Vallit sees the finding, the app concerned, the code concerned and what you tell us, and works on the request. What we propose and change is governed by the terms.

The legal basis for everything in this section is the contract of use (Art. 6(1)(b) GDPR).

9Payment

You pay for plans through Stripe (Stripe Payments Europe, Ltd., Ireland). You enter your payment details directly at Stripe; we never receive them. We store your Stripe customer number, your plan and the payment status. Stripe processes some payment data as a controller in its own right, for example to prevent fraud; Stripe’s privacy policy applies to that.

The legal basis is the contract (Art. 6(1)(b) GDPR). We keep invoices and accounting records for as long as commercial and tax law requires, usually eight to ten years (Art. 6(1)(c) GDPR).

Accepting the terms

For every order we store which version of the terms and of the Data Processing Agreement was accepted, when, with which account and email address, and for which order. Stripe also keeps the version with the payment. This lets both sides show what was agreed. The legal basis is the contract and our legitimate interest in this record (Art. 6(1)(b) and (f) GDPR). We keep it as long as the workspace exists.

10Measurement in the app

In the app (not on the website) we measure with Vercel Web Analytics and Vercel Speed Insights which pages are opened and how fast they load. These tools set no cookies and build no cross-device profiles. Secret parts of addresses, such as report links, are masked before sending.

The legal basis is our legitimate interest in improving the app and keeping it fast (Art. 6(1)(f) GDPR).

11Cookies and browser storage

The website sets no cookies. The app stores only what it needs to work:

EntryWhat forHow long
Clerk session cookiesKeep you signed in and protect the sign-inUntil you sign out or the session ends
vallit-sidebar (cookie and localStorage)Remembers whether the sidebar is open or closedOne year
vallit-seen-version (localStorage)Remembers which news you have already seenUntil you delete it
vallit-auth-email (sessionStorage)Carries your email address from one sign-in step to the nextRemoved after sign-in

These entries are strictly necessary for the service you asked for (§ 25(2) no. 2 TDDDG); no consent is needed.

12Checked apps and our checker

Our checker visits an app only when its owner has asked for it, and reads only what the app already shows to every visitor. It identifies itself on every request in its user agent and points to vallit.net/security.

We store what we found and where, but never the content itself: of an exposed key, for example, only its kind, its first characters and a hash. Should a checked app expose personal data of its users, we record only that and where it does. This data does not come from you but from the checked app (Art. 14 GDPR); it is processed on behalf of the app’s owner.

To look up certificates, domain data and known vulnerabilities of software packages, we query public directories (OSV, rdap.org, SSLMate CertSpotter, crt.sh), sending only domain and package names.

To find gaps in our own checks, we pass publicly visible traits of a small sample of checked apps, that is headers, excerpts of public scripts and the titles of earlier findings, through Vercel’s AI Gateway to a language model by Anthropic; recognised credentials are removed first. These traits concern the app, not people. The legal basis is our legitimate interest in improving the checks (Art. 6(1)(f) GDPR).

13Recipients and processors

We pass data only to service providers that process it on our behalf and on our instructions (Art. 28 GDPR), and only as far as their task needs:

ServiceTaskSeat, storage
Vercel Inc.Hosting of the website and the app, server logs, measurement in the app (Web Analytics, Speed Insights), AI GatewayUSA; the app runs in Frankfurt
Supabase, Inc.The app’s databaseUSA; the app’s data in Frankfurt
Clerk, Inc.Accounts, sign-in, sessions, protection against automated sign-insUSA
ResendSending reports, alerts and daily summaries by email; messages from the contact formUSA
Stripe Payments Europe, Ltd.Payments, subscriptions, customer portalIreland
GitHub, Inc.Access to repositories you connectUSA
Anthropic PBCConfirming findings in code excerpts from connected repositories and looking for gaps in our checks in public traits of checked apps, through Vercel AI GatewayUSA
Apple (iCloud Mail)Our mailboxIreland

Some of these providers are based in the USA or access data from there. We transfer data there only if the recipient is certified under the EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR) or has agreed the European Commission’s standard contractual clauses with us (Art. 46(2)(c) GDPR). You can have a copy of these safeguards on request.

Personal data you put into Vallit as a customer, for example from your apps and repositories, we process on your behalf. The Data Processing Agreement applies to it; the services used for it are listed under subprocessors.

14Security

All connections to the website and the app are encrypted with TLS. Only the people at Vallit who need access for their work have it. We never store the secrets we find.

15How long we keep data

  • Checks without an account and monitoring measurements: 90 days.
  • Account, organisation, apps and reports: until you delete the account or the organisation. When you delete an organisation, we remove the organisation, app, email address and IP hash from its checks; we delete the rest of the check data after 90 days.
  • Acceptance of the terms with an order: as long as the workspace exists.
  • Invoices and accounting records: for the statutory retention period.
  • Email correspondence: until the matter is settled, unless a retention duty applies.

16Your rights

You have the right

  • to know what data we hold about you (Art. 15 GDPR),
  • to have incorrect data corrected (Art. 16),
  • to have your data deleted (Art. 17),
  • to have processing restricted (Art. 18),
  • to receive your data in a common format (Art. 20), and
  • to withdraw consent at any time with effect for the future (Art. 7(3)).

Right to object: where we process data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation (Art. 21 GDPR). We then stop processing the data unless we can show compelling legitimate grounds.

A short email to info@vallit.net is enough.

You may also complain to a data protection supervisory authority (Art. 77 GDPR). Ours is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Heilbronner Straße 35, 70191 Stuttgart, Germany.

17What you must provide, and no automated decisions

For an account we need your email address; without it we cannot create one. Everything else is voluntary. You can use the free check without an email address.

The rating of an app in a report is automatic, but it concerns the app, not you as a person. We make no automated decisions within the meaning of Art. 22 GDPR.

18Changes

When our service or the law changes, we update this policy. The version on this page applies; the date of the last change is at the top.

Vallit

A clearer picture of
the app you built.

What's new

1.15.2369 October 2026

The update log shows what changes for you
  • Only changes that reach you
All updates

Product

  • Check my app
  • What we check
  • Fixes
  • Vera, our AI
  • Docs
  • Pricing
  • Updates
  • Sign in

Company

  • About
  • Research
  • Get in touch
  • Security
  • Status

Legal

  • Impressum
  • Privacy
  • Terms
  • DPA
  • Subprocessors

© 2026 Vallit