Privacy Policy
Last updated: August 30, 2026
This Privacy Policy explains how Audify ("we", "us") collects and uses information when you use our website and security audit service at audify.xyz (the "Service").
1. Data controller
Jakub Hajdamach (sole proprietor / OSVČ)
Czech Republic
Email: jakubhajdamach@gmail.com
2. What we collect
- Account data: email address and authentication credentials when you register (via email/password or GitHub OAuth through Supabase).
- Usage data: audit credits, subscription status, and rate-limit counters needed to run the Service.
- Payment data: processed by Stripe. We do not store your full card number — Stripe handles payment details.
- Code you submit: source code, files, or ZIP archives you paste or upload for analysis.
- Technical data: standard server logs (e.g. IP address, browser type, timestamps) for security and debugging.
3. How we use your code
When you run a security audit, your submitted code is sent to OpenAI for AI-powered analysis during that request. We do not store your source code in our database after the audit completes.
We do not use your audits to train our own models. OpenAI API data is not used for model training by default under OpenAI's API terms.
4. Third-party processors
- Supabase — authentication, user profiles, and billing-related account data.
- Stripe — payment processing and subscription management.
- OpenAI — code analysis during active audit requests.
- Vercel — website hosting and application delivery.
These providers process data on our behalf under their own terms and privacy policies.
5. Legal basis (GDPR)
If you are in the European Economic Area, we process personal data based on:
- Contract — to provide the Service you signed up for.
- Legitimate interest — to secure the Service, prevent abuse, and improve reliability.
- Legal obligation — where required (e.g. tax and accounting records for payments).
6. Data retention
- Submitted source code: not retained on our servers after the audit request ends.
- Account and billing records: kept while your account is active and as required by law.
- Server logs: retained for a limited period for security purposes.
7. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Object to or restrict certain processing
- Data portability
- Lodge a complaint with your local data protection authority
To exercise these rights, contact us at jakubhajdamach@gmail.com. We will respond within 30 days.
8. Cookies
We use essential cookies for authentication and session management (e.g. Supabase auth cookies and anonymous free-tier identifiers). We do not use advertising cookies.
9. Children
The Service is not intended for users under 16. We do not knowingly collect data from children.
10. Changes
We may update this policy from time to time. The "Last updated" date at the top will reflect the latest version. Continued use of the Service after changes constitutes acceptance.
11. Contact
Questions about this policy: jakubhajdamach@gmail.com