Privacy Policy

Privacy Policy

Effective date: July 31, 2026

This Privacy Policy (“Policy”) describes the information practices of Auron Labs (“Auron Labs,” “Company,” “we,” “us,” or “our”) in connection with our autonomous security research platform, smart-contract and blockchain security services, software, applications, websites, and related offerings (collectively, the “Service”). It applies to information collected from visitors, account holders, customers, prospective customers, and anyone who communicates with or uses the Service. By accessing or using the Service, you acknowledge that you have read and understood this Policy. This Policy should be read together with our Terms & Conditions.

1. Definitions

“Personal Information” means information that identifies, relates to, describes, or can reasonably be linked with an individual or household. “Processing” means any operation performed on information, including collection, storage, use, analysis, disclosure, transfer, or deletion. “Repository Data” means source code, files, metadata, commit history, configuration, documentation, and other content associated with repositories connected to the Service. “Scan Data” means vulnerability findings, security reports, risk assessments, remediation guidance, and analytical outputs generated through the Service. “Service Providers” means third parties that process information for us or provide technology necessary to operate the Service.

2. Categories of information collected

We collect account and authentication information, including names, email addresses, profile details, account identifiers, login timestamps, authentication tokens, account settings, and security logs received through Google, GitHub, or other sign-in providers. We collect billing contact details, transaction history, credit usage, payment status, refunds, and tax information; payment card details are processed by Stripe and are not stored directly by us. When repositories are connected, we process complete repository contents, source code, documentation, configuration files, dependencies, commit history, branch information, contributor metadata, and repository settings. We also collect device, browser, IP address, operating system, usage analytics, feature interactions, performance metrics, API activity, error logs, support communications, and security events. The Service generates and stores Scan Data, including vulnerability findings, severity classifications, reports, risk assessments, remediation recommendations, historical comparisons, and aggregated statistics.

3. Methods of information collection

We collect information directly when you create an account, connect a repository, purchase credits, request an audit, submit a form, configure settings, communicate with our team, or provide feedback. We collect information automatically through cookies, server logs, analytics tools, APIs, monitoring systems, and security technologies. We also receive information from authentication providers, GitHub and other repository hosts, Stripe, infrastructure providers, and third-party artificial intelligence services used in code analysis.

4. Purposes for information processing

We process information to authenticate users, manage accounts and permissions, connect and analyse repositories, perform vulnerability scanning, generate reports and remediation guidance, process payments and credits, provide customer support, and communicate service or policy updates. We also use information to secure the Service, investigate abuse, prevent fraud, maintain audit trails, troubleshoot errors, measure performance, improve detection quality, develop features, conduct research, create aggregated insights, comply with law, and administer our business. Repository Data and Scan Data may be used to improve our systems, algorithms, and models, subject to access controls and contractual commitments applicable to the Service.

5. Information sharing and disclosure

Repository Data, source code, metadata, prompts, and related information may be transmitted to and processed by third-party artificial intelligence providers, including OpenAI, Anthropic, Google, Microsoft Azure, and other model or infrastructure providers engaged from time to time. These providers operate under their own terms, privacy practices, security controls, and retention arrangements. Stripe processes payment and billing information. We may also share information with hosting, analytics, communications, monitoring, security, customer-support, professional-adviser, contractor, and business-operation providers that need it to perform services for us. We may disclose information to comply with law, subpoenas, court orders, regulatory requests, or legal proceedings; enforce agreements; investigate misuse; or protect the rights, property, and safety of Auron Labs, users, and the public. Information may transfer as part of a financing, merger, acquisition, reorganisation, bankruptcy, or sale of assets. We may use and disclose aggregated or de-identified information that cannot reasonably identify an individual.

6. Data retention and security

We may retain account records, Repository Data, Scan Data, transaction records, communications, technical logs, analytics, and security records for as long as reasonably necessary to provide and improve the Service, preserve business continuity, maintain audit trails, comply with legal, tax, accounting, and regulatory obligations, resolve disputes, enforce agreements, and defend legal claims. Disconnecting a repository or closing an account does not necessarily cause immediate deletion from active systems, archives, logs, or backups. We may delete, aggregate, or de-identify information when it is no longer required. We use reasonable technical, administrative, and organisational safeguards, including encryption where appropriate, authentication, access controls, logging, monitoring, least-privilege access, personnel controls, and incident-response procedures. No system is completely secure. If a security incident affects Personal Information, we will investigate, mitigate, and provide notices where required by law.

7. International data transfers

Information may be transferred to, processed in, or stored in countries other than your country of residence, including locations where Auron Labs, cloud infrastructure, repository hosts, payment processors, analytics providers, or AI providers operate. Those countries may have different data-protection laws. Where required, we use recognised safeguards such as contractual protections, approved transfer mechanisms, or adequacy decisions.

8. Your rights and choices

Depending on applicable law, you may request access to Personal Information we maintain about you, a portable copy of certain information, correction of inaccurate information, deletion or erasure, restriction of processing, or objection to particular uses. You may opt out of promotional communications while continuing to receive operational or security notices. Rights may be limited where retention is required by law, necessary to protect security or legitimate business interests, technically infeasible, or likely to affect another person’s rights. We may require identity and authority verification before completing a request. Requests may be sent to contact@auron.xyz.

9. California privacy rights

California residents may have rights to know the categories and specific pieces of Personal Information collected, the sources and purposes of collection, and the categories of recipients; to request correction or deletion; to receive a portable copy; and to receive non-discriminatory treatment for exercising privacy rights. Auron Labs does not sell Personal Information for monetary consideration. Where applicable law treats certain advertising or analytics disclosures as “sharing,” you may have a right to opt out. We will verify requests and respond within legally required timeframes. An authorised agent may submit a request where permitted, subject to proof of authority and identity verification.

10. Children’s privacy

The Service is intended for business users and is not directed to individuals under 18. We do not knowingly collect Personal Information from children. If we learn that information was collected from a child without appropriate authorisation, we will take reasonable steps to delete it. Parents or guardians who believe a child has provided information should contact us promptly.

11. Policy updates and modifications

We may modify this Policy to reflect changes in the Service, our practices, technology, legal requirements, or business operations. The revised Policy becomes effective when posted unless another date is stated. We will update the effective date and may provide additional notice through the Service or by email where changes are material. Continued use of the Service after an update constitutes acknowledgement of the revised Policy.

12. Contact information and privacy inquiries

Questions, concerns, and privacy-rights requests may be sent to Auron Labs at contact@auron.xyz. We will endeavour to respond within a reasonable timeframe and in accordance with applicable law. Complex requests may require additional time. For security, we may ask for information necessary to verify your identity, account ownership, or authority to act for another person before disclosing, correcting, or deleting information.