VAST
Back to Home

Privacy Policy

Last updated: January 2025

The short version: Vast never stores your source code. We analyze the structure of your codebase - the dependency graph - not the contents. Your code stays on your machine and on GitHub.

What we collect

When you create an account via GitHub OAuth, we store your GitHub username, email address, avatar URL, and an encrypted OAuth token. This is the minimum required to authenticate you and access the repositories you explicitly authorize.

When you import a repository, our system reads the file tree and parses import statements, YAML configurations, and dependency declarations. We store the resulting graph - nodes and edges - not the source files themselves. We never copy, cache, or retain your code.

We collect standard usage data: pages visited, features used, and errors encountered. Vercel Web Analytics provides privacy-friendly, first-party page views on our deployment — no cross-site advertising trackers.

What we don't do

We don't sell your data. We don't share it with advertisers. We don't use it to train machine learning models. We don't store your source code on our servers under any circumstances.

Third-party services

We use the following services to operate Vast: GitHub (OAuth and repository access), Polar (payment processing for Pro subscriptions), and Vercel (hosting and Web Analytics). Each operates under its own privacy policy.

Data deletion

You can delete your account and all associated data at any time from the Settings page. Deletion is permanent and takes effect within 24 hours.

Contact

For privacy-related questions: privacy@vast.app