Privacy Policy
Last updated: July 2026
The short version: Vast does not store file contents. We keep a dependency graph — file paths, import relationships, and exported symbol names. File bodies are read from GitHub at analysis time and discarded. Your source files stay on GitHub.
What we collect
When you create an account via GitHub OAuth, we store your GitHub username, email address, avatar URL, and an encrypted OAuth token. This is the minimum required to authenticate you and access the repositories you explicitly authorize.
When you import a repository, our system reads the file tree and parses import statements, YAML configurations, and dependency declarations. We store the resulting graph — nodes and edges, including file paths, import specifiers, and symbol names — not the source file bodies. Preview and AI explain fetch file contents live from GitHub; they are not saved.
We collect standard usage data: pages visited, features used, and errors encountered. Vercel Web Analytics provides privacy-friendly, first-party page views on our deployment — no cross-site advertising trackers.
What we don't do
We don't sell your data. We don't share it with advertisers. We don't use it to train machine learning models. We don't store file contents on our servers.
Third-party services
We use the following services to operate Vast: GitHub (OAuth and repository access), Polar (payment processing for Pro subscriptions), and Vercel (hosting and Web Analytics). Each operates under its own privacy policy.
Data deletion
You can delete your account and all associated data at any time from the Settings page. Deletion is permanent and takes effect within 24 hours.
Contact
For privacy-related questions: privacy@vast.app
