Privacy, in plain words.
This is the whole policy, not a summary of one. It says what we hold, why, where it lives and for how long. Short on time? Read only the bold line under each question.
Version 1.0In force from 10 October 2026Vyana Compute, New Delhi, India
- We hold your account details and what your workspace puts into Groundrule.
- Your source code stays on your machines. Scans send results, not files.
- No ads, no selling data, no trackers on this site or in the product.
- AI sees only what a feature needs, with secrets removed, and only if your workspace turns AI on.
- Ask for a copy or for deletion by email. A person answers.
You're reading the bold lines only. They're part of the text and accurate, but the detail under each one still applies.
Whose data is it, and who is responsible for it?
There are two kinds of data in Groundrule. We are responsible for the first. Your organization is responsible for the second, and we only handle it on its instructions.
Data about you
Your name, email and sign-in details. Vyana Compute decides how this is used, within this policy, and answers for it.
In legal terms we are the data controller, or data fiduciary.What your workspace puts in
Your rulebook, scan results, imported documents and proposals. They belong to your organization, which decides what goes in and who sees it. We store and serve them.
In legal terms your organization is the controller and we are its processor.Groundrule is built and operated by Vyana Compute, based in New Delhi, India. You can reach the people responsible for privacy at legal@groundrule.dev. If your company needs a written data processing agreement, write to us and we'll work one out with you.
We use data about you because we need it to provide the service you signed up for, and we keep security data such as IP addresses because we have a legitimate interest in keeping the service safe.
What do you hold, why, where, and for how long?
Twelve things, listed below. Pick one to see why we have it, where it lives, how long it stays and who can see it.
Your account
Your name, email address, whether it is verified, the role you described during onboarding, a password hash if you set a password, and your GitHub identity if you sign in with GitHub.
- Why
- To create your account, sign you in, and email you about it: confirmations, sign-in links, password resets, invitations and changes to this page. No newsletters.
- Where
- Our database.
- How long
- While the account exists. Removed within 30 days of a deletion request.
- Who can see it
- You, people in your workspaces (your name, email and role), and the people at Vyana Compute who run Groundrule.
Sign-in and sessions
A SHA-256 hash of each session token with your browser's user-agent string and when it was used; hashes of email links; rate-limit counters keyed by email or IP address; for CLI sign-in, the computer's name and the IP address of the request.
- Why
- To keep you signed in, let you see and end your sessions, make email links single-use, and slow down anyone guessing passwords or links.
- Where
- Our database. The session cookie lives in your browser and cannot be read by scripts.
- How long
- Sessions: 30 days or until you sign out; changing or resetting your password ends your other sessions. Email links: deleted 7 days after they expire. Rate-limit counters and CLI sign-in requests: about a day.
- Who can see it
- Nobody can read a token back. The people who run Groundrule can see that a session exists.
Workspace and members
The workspace's name, address and company; the onboarding answers (team size, stack, coding agents, code host); members, their roles and invitations.
- Why
- To run the workspace, recommend packs for its stack, and control who can do what.
- Where
- Our database.
- How long
- While the workspace exists.
- Who can see it
- People in the workspace, and the people who run Groundrule.
Your rulebook
The standards your workspace writes, with every version and change note; which packs are on; rollout settings per organization, team and repository; teams, owners and repositories; and an audit log of administrative actions (who did what, and when, with IDs and names, never content).
- Why
- This is the service: to serve your rulebook to the dashboard, the CLI and the MCP server.
- Where
- Our database.
- How long
- While the workspace exists. The audit log cannot be changed or deleted from within the product.
- Who can see it
- People in the workspace, according to their role.
API tokens
Each token's name, a SHA-256 hash, its first 12 characters, its permissions and expiry, when it was last used, and whether and by whom it was revoked. The token itself is shown once and never stored.
- Why
- So the CLI, CI and coding agents can read the rulebook, and, if allowed, upload scans and propose rules.
- Where
- Our database.
- How long
- Kept after expiry or revocation, so the list shows its history. A revoked or expired token never works again.
- Who can see it
- The person who created it, and workspace admins.
Scan reports
For each scan of a repository: its name, branch, commit and file count; the stack and tools found; the paths, line counts and hashes of agent files; for each rule, its outcome, counts and up to three examples (file, line, message, and a one-line snippet of at most 200 characters with secrets redacted, none for security rules); instructions found in agent files, redacted; who uploaded it.
- Why
- To show evidence, preview impact, suggest promotions, and turn what your repositories already say into proposals.
- Where
- Our database.
- How long
- The latest 20 scans per repository. Older ones are removed when a new one arrives.
- Who can see it
- People in the workspace. --no-snippets uploads no code at all.
Imported documents
When someone imports a document: its name, title, kind, size, page and passage counts, the cost estimate and cost, who imported it, and, for a connected app, a link to the page. While it is being read, its text, split into passages, with secrets redacted.
- Why
- To find the rules in it with AI and cite where each came from.
- Where
- Our database. The uploaded file itself is never stored.
- How long
- The import's record is kept. The passages are deleted as soon as reading ends, or when an import is cancelled or abandoned (after a day unconfirmed, or 30 minutes interrupted).
- Who can see it
- People in the workspace who can author rules.
Proposals
Everything waiting in or decided in the inbox: the proposed rule's text (redacted), its category, AI's draft and confidence where AI was used, its sources (repository, file and lines) and citations (document, location, and a quote of up to 600 characters); for proposals from people or agents, who proposed it, their reason and example, and for review comments, the reviewer's GitHub username and a link; every decision, with who made it and why.
- Why
- So your team can review, accept or reject proposals with their evidence, and see what was decided later.
- Where
- Our database.
- How long
- Kept. A proposal from a scan leaves the open list once no repository contains it anymore.
- Who can see it
- People in the workspace.
Connected apps and GitHub
For Notion, Google Docs or Confluence: the app, the account or site name, and its access and refresh tokens, encrypted with AES-256-GCM. For the GitHub App: the GitHub account it is installed on and who installed it, and the IDs of recent webhook deliveries.
- Why
- To read the pages and review comments someone chooses to import, with read-only access.
- Where
- Our database.
- How long
- Until an admin disconnects the app (which deletes the tokens) or uninstalls the GitHub App. Webhook delivery IDs: 7 days.
- Who can see it
- Workspace admins see the connection. Nobody can read the tokens.
AI usage
For each AI request: the feature, the person, the time, the model, token counts, cost, status, the number of redactions and the duration. Never the text sent or returned. Separately, a cache of the model's answers keyed by a hash of what was sent.
- Why
- To show your workspace what AI costs, enforce its monthly budget, and avoid paying twice for the same answer.
- Where
- Our database.
- How long
- The ledger is kept. Cached answers: 30 days, and none at all with zero retention.
- Who can see it
- People in the workspace who can see AI settings.
Logs
Request logs at our hosting providers and in our service: IP address, method, path, status, timing and a request ID. Authorization headers and cookies are removed before logging. Request bodies, tokens and code are never logged.
- Why
- To keep the service running, find faults and investigate abuse.
- Where
- At the hosting providers listed below.
- How long
- For each provider's standard log retention. We don't copy logs anywhere else.
- Who can see it
- The people who run Groundrule.
Emails you send us
Whatever you write to us, and your address.
- Why
- To answer you.
- Where
- Our mailbox.
- How long
- For as long as the conversation is useful. Ask and we'll delete it.
- Who can see it
- The people at Vyana Compute who answer email.
The open-source command-line tool sends nothing to us unless a repository is connected to a workspace. Connected, it fetches your rulebook, and sends a scan or a proposal only when someone runs scan --upload or propose.
What will you never do with it?
We don't store your source code or the files you upload, sell data, show ads, run trackers, or train models on what you send.
Store your source code
Checks run where your code is. A scan sends results and, if you allow them, a few short redacted snippets.
Keep the files you upload
A document becomes text passages, and the passages are deleted once read.
Sell or rent data
Not yours, and not your colleagues'.
Show ads or build ad profiles
There is no advertising anywhere in Groundrule.
Run trackers or analytics scripts
There are none on this website, the documentation or the product.
Train models on your data
Groundrule trains no models. AI requests go to Anthropic's API for one answer at a time.
Who else handles my data?
Four companies, each for one job, plus the apps your workspace chooses to connect. None of them may use your data for their own purposes.
Anthropic processes AI requests under its commercial terms for API customers. A workspace can choose zero retention where a zero-data-retention agreement is in place, or turn AI off, in which case nothing is sent.
We also hand data over when the law requires it. If that ever concerns your workspace we'll tell you first, unless we're legally forbidden to. If Groundrule is ever sold or merged, this policy continues to apply to your data until you're told otherwise and given the chance to leave.
Where is it kept, and does it cross borders?
Our database runs in the United States (Oregon), which may be outside your country.
Every workspace's data is kept in one database, separated by workspace. If your data must stay in a particular country, Groundrule isn't ready for that yet, and the early access page says so.
Where data moves between countries, we rely on our providers' standard contractual protections. Ask us if you need the details for a particular provider.
How do you protect it?
Encryption in transit, hashed secrets, encrypted app tokens, and a database that keeps workspaces apart by itself. We don't have a SOC 2 report yet.
- All traffic uses TLS. Connected-app tokens are encrypted by us with AES-256-GCM before they are stored.
- Passwords are scrypt hashes. Session tokens, email links and API tokens are stored as hashes. We couldn't read them back if we wanted to.
- Row-level security in the database restricts every query to one workspace, and the service connects with a role that cannot bypass it.
- Secrets are removed from everything sent to AI, and from the snippets and instructions a scan uploads.
The security page lists every control, and what isn't in place yet. If we find that your data was accessed by someone who shouldn't have had it, we'll tell every affected workspace's admins without undue delay, and no later than 72 hours after we confirm it, with what we know and what we're doing.
What can I ask you to do?
See it, fix it, delete it, or object. Email us. A person answers within 30 days, and it costs nothing.
Get a copy
Everything we hold about you, in a form you can read.
Email usFix something
If anything about you is wrong or out of date.
Email usDelete it
Your account, or a whole workspace with everything in it.
Email usObject or complain
Tell us to stop using your data in some way, or that we got it wrong.
Email usYou can already end your other sessions, revoke API tokens, disconnect apps and stop snippets yourself in the dashboard and the CLI. Deleting a whole account or workspace isn't in the dashboard yet, so write to us and we do it within 30 days. Copies in database backups, where they exist, age out on our host's backup schedule.
We may need to confirm that a request really comes from you, normally by replying to the address on the account. You also have the right to complain to the data protection authority where you live. We'd like the chance to put it right first.
What if I appear in someone else's workspace?
Ask that organization first. What its members put into Groundrule belongs to it. We'll help them answer you.
A workspace can hold information about people who aren't its members: the name of a reviewer whose pull-request comment became a proposal, or a name in an imported document. That organization controls it. We hold it on their instructions and can't hand it over, change it or delete it on our own. If you write to us, we'll pass your request to the organization concerned where we can identify it, and tell you that we have.
Does this website use cookies or track me?
No. This website and the documentation set no cookies and load no analytics or third-party scripts. The dashboard sets one cookie, to keep you signed in.
Fonts are served from our own domain, so reading these pages tells nobody but our host that you were here. The host sees your IP address because that is how web pages are delivered.
The dashboard remembers two preferences in your browser's local storage, your light or dark theme and whether the sidebar is collapsed, and the documentation remembers your theme. They never leave your browser.
Is Groundrule for children?
No. Groundrule is a tool for engineering teams, and accounts are for adults.
We don't knowingly create accounts for anyone under 18. If you believe a child has signed up, write to us and we'll remove the account.
What happens when this page changes?
If a change matters, we email every workspace admin at least 14 days before it takes effect. The history is below.
Fixing a typo or making a sentence clearer doesn't count as a change that matters. Collecting something new, sharing data with someone new, or changing what you or we are committed to does. If you don't agree with a change, you can keep your standards (they are YAML in an open format) and close your workspace before it takes effect.
v1.010 October 2026First version, published with private early access.
Something unclear, or wrong?
Write to us and a person will answer. If a sentence here can be read two ways, tell us and we'll fix the sentence.