ValidityCore Apply
← Back to overview

Privacy Policy

Last updated: January 2026

This policy explains what ValidityCore ("ValidityCore", "we") collects when you use validitycore.net, our documentation, and — for admitted design partners — the contract validation gateway at schema.validitycore.net. ValidityCore is currently in a design-partner phase and is not generally available.

1. Information we collect

Design Partner applications. When you apply to the program we collect the details you submit: name, work email, company, fleet size, contract formats in use, estimated validation volume, and any free-text notes.

Validated payloads. By default, ValidityCore does not retain the body of the requests, responses, or events it validates. Validation happens in memory and only the verdict metadata — ruleset name and version, field paths that were evaluated, rule IDs, pass/fail outcome, and latency — is written to your validation ledger. A design partner may opt in to bounded payload sampling for debugging; sampled payloads follow the retention you configure.

Account & usage data. For admitted partners: token identifiers, ruleset definitions you register, API request metadata, and dashboard activity.

Site analytics. Aggregate, privacy-preserving page analytics on the marketing site and docs. We do not build advertising profiles.

2. How we use it

To evaluate design-partner applications and schedule review cohorts; to operate, secure, and improve the validation gateway; to produce the validation ledger and usage reporting; and to communicate with you about the program. Verdict metadata is used to run validation and populate your ledger — not for any secondary purpose.

3. Data sharing

We do not sell your data. We share it only with infrastructure subprocessors that operate the service under contract (hosting, error monitoring, email), and where required by law. We never share validated payloads or verdict metadata across customers.

4. Security & ledger integrity

Data is encrypted in transit (TLS 1.2+) and at rest. The validation ledger is append-only; entries are hash-chained so tampering is detectable, and Fleet-tier exports are cryptographically signed. Access to production systems is least-privilege and audited.

5. Data residency

Marketing and application data is processed in the United States. Design partners on the Fleet track may pin gateway and ledger processing to a specific region; contact us for the current region list.

6. Retention

Application data is retained for up to 24 months to manage cohort review, then deleted or anonymized. Validation-ledger retention follows your tier: 30 days (Observe), 1 year (Enforce), or a custom period (Fleet). You can request deletion of your ledger at any time.

7. Cookies

We use strictly-necessary cookies for the dashboard session and a single privacy-preserving analytics cookie. No third-party advertising cookies.

8. Your rights

Depending on your jurisdiction, you may request access, correction, export, or deletion of your personal data. Email us and we'll respond within 30 days.

9. Contact

Questions about this policy: [email protected].