---
titel: "Privacy Policy"
adresse: https://anvil-coder.tech/en/privacy
beschreibung: "This website sets no cookie, measures nothing and delivers no JavaScript. The service behind it runs on the Infomaniak Public Cloud in Switzerland. Data leaves Switzerland at two points: at the language model provider and when writing back to the customer's repository and ticket system."
sprache: en
---

Legal

# Privacy Policy

This policy describes which data arises when you visit this website and when you use the service we operate, where it is stored and to whom it goes. It describes what actually happens — not what could happen.

## What this policy covers

Responsible for the processing described here is**Halvic Labs GmbH**, Nünenenweg 45, 3123 Belp, Switzerland —[hello@halvic.ch](mailto:hello@halvic.ch). The complete details are in the[legal notice](https://anvil-coder.tech/en/legal-notice).

It covers two things: this website at anvil-coder.tech and the service we operate at app.anvil-coder.tech.

It does **not** cover a self-operated installation. Anyone operating Anvil Coder on their own infrastructure processes source code, jobs and model requests in their own environment; that data does not reach us and we do not see it. Responsible for it is then whoever operates — not us.

The revised Swiss Data Protection Act (revFADP) governs. To the extent the EU General Data Protection Regulation (GDPR) is applicable to a processing operation, its requirements apply in addition.

## This website: no script, no cookie, no tracking

The pages you are reading right now are prebuilt HTML. They execute no JavaScript — the delivered security policy explicitly forbids scripts and additionally allows only content from this domain. There are therefore no embedded third-party fonts, maps or counters, no cookie, no consent banner and no audience measurement. There is also no form: anyone writing to us writes from their own mailbox to[hello@halvic.ch](mailto:hello@halvic.ch).

What does arise on access is the web server's log: IP address, time, requested address, status code, referrer and browser identifier. We need it for operations and troubleshooting; it is not combined with other data and not condensed into profiles. The applications' logs flow into a collection inside the cluster that deletes them after 72 hours.

## The hosted service

Anyone using the service at app.anvil-coder.tech signs in. Sign-in runs through Keycloak; this creates an account with email address and name as well as membership of an organisation. A cookie is set for the signed-in session — it serves sign-in only. On this website, that cookie does not exist.

In operation, the service then processes what it is there for: the source code of the connected repositories, the jobs, the requests to a language model formed from them and their responses. Where the ticket or pull request integration is switched on, it additionally reads the tickets and comments intended for it. It writes the result back to where the job came from: as a commit into the repository, as a pull request, as a ticket state — that is, into your own systems.

Added to this are the operational data of a run: which run started when, which steps it went through, how it ended, and what it consumed in model and compute time. This consumption is metered and is the basis of the invoice; it is retained as evidence.

## Where the data lives

Operations run on the Infomaniak Public Cloud, Switzerland region. Databases, storage, logs and sign-in live there — for teams that have to justify data sovereignty, that is often the first question, and the answer is not a declaration of intent but the place where the machines stand.

The models themselves live with their respective providers. **That is one of two points at which data leaves Switzerland.** What is transmitted is what the model needs for the job: the relevant excerpt of the source code and the description of the task. In the hosted service, Anthropic is configured for this today; the connection is interchangeable and also covers local models — which provider runs is decided by the deployment's configuration (see[Integrations](https://anvil-coder.tech/en/integrations)).

The second point is the writing back. The service places the result where the job came from — as a pull request in the repository and as a state on the ticket. If those systems are located abroad — and with an account on github.com they are — the data thereby also leaves Switzerland. Our service establishes the connection there; where it leads is determined by your choice of repository and ticket environment.

## Disclosure to third parties

Disclosure occurs only to: (a) the provider of the language model, to the extent described above; (b) the operator of your repository and your ticket system, to which the service writes the result back; (c) the operator of the infrastructure, for technical provision; (d) authorities, where we are legally obliged to do so. There is no disclosure for advertising purposes, no sale of data and no disclosure to third parties not involved in providing the service.

## Retention

The applications' logs are deleted by the collection in the cluster after 72 hours. Account and run data persist as long as the account exists; deletion can be requested by email.

A shorter period applies to the most sensitive part. The requests to the model and its responses are recorded in a run's evidence, and they contain your source code. Their**verbatim content** is removed automatically after 30 days. What remains is the bookkeeping around it — time, organisation, model, quantity consumed and result: the basis of the invoice, without the content. For the consumption and billing data, the statutory retention periods additionally apply — they are the evidence for the invoice and are therefore retained even when an account ends.

## Data security — and what we do not claim about it

Traffic to this website and to the service runs over TLS. In the hosted service, the stored credentials for the models are kept encrypted instead of in plain text, every access to the factory carries its tenant, and foreign code is executed during building and testing in an unprivileged, throwaway pod. This is described in detail on[Security](https://anvil-coder.tech/en/security).

There you will also find the flip side, and it applies here word for word: Anvil Coder carries no security certification, and it has no published penetration test. Whether a processing operation satisfies the requirements of the GDPR in an individual case is a legal assessment — we do not make it here and do not promise it. What we can show is the construction: which point aborts on a missing value, where data lives and where it goes.

## Your rights

You have the right to information about the data processed about you, and to rectification, deletion and restriction of processing; to the extent the GDPR applies, additionally to data portability and to objection. Please send requests to[hello@halvic.ch](mailto:hello@halvic.ch) — the same address as everything else.

You can also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if you reside in the EU, your national data protection authority.

## Changes and version

As of: 8 August 2026. If operations change, this text changes with them — it describes the state of the service, not an intention. The version published at the time of your visit applies.
