Privacy Policy
What personal data we hold, why we hold it, how long it stays, and what you can ask us to do with it.
What this says.
The short version, which the clauses below then say precisely.
- We hold account data, organization and billing data, and product data such as session records and the memories your agents write.
- Your source code is never sent to us, because agents run on your machines and we never execute customer code.
- We do not sell personal data, and we do not use your content to train models.
- A small number of subprocessors handle payments, infrastructure, and email, and each one is listed publicly.
- You can ask for a copy of your data, ask us to correct it, or ask us to delete it.
- Data is encrypted in transit and at rest, and isolated per organization at the database layer.
This summary is here to be readable. The numbered clauses below are the operative text.
Policy
Who we are
Virex Systems LLC provides Virex Remote and Virex Memory. For the personal data described here, we act as controller for account and billing data, and as processor for the product data your organization creates through the service.
What we collect
We collect the following categories, and no more than we need for each purpose.
- Account data: name, email address, authentication identifiers, and the organization you belong to.
- Organization and billing data: organization name, subscription and seat records, invoices, and payment status. Card details are handled by our payment processor and are not stored by us.
- Product data: session activity and decision records from Virex Remote, and the memories your agents write in Virex Memory, along with the project and machine context attached to them.
- Operational data: security and audit events, service logs, and diagnostic information needed to keep the service running.
What we never receive
Your source repositories, your model provider credentials, and your build artefacts are not sent to Virex. Coding agents run on machines you control, and we never execute customer code.
This is an architectural property rather than a policy choice, which is why it appears in both this document and on our security page.
Why we process it
Account and organization data is processed to provide the service, authenticate members, and administer subscriptions. Product data is processed to deliver the features you subscribed to, such as showing session activity or retrieving a memory.
Operational data is processed for security, fraud prevention, debugging, and service reliability. Where a legal basis is required, we rely on performance of our contract with you, our legitimate interests in operating a secure service, and consent where consent applies.
What we do not do
We do not sell personal data. We do not share it with advertisers. We do not use your content, including memories your agents write, to train models.
Subprocessors and international transfers
A small number of third parties process data on our behalf, covering payments, infrastructure and data storage, transactional email, and error monitoring. Each is listed on our subprocessors page with what it does.
Where processing involves a transfer across borders, we rely on appropriate safeguards. If your organization has a specific residency requirement, contact us before you subscribe and we will tell you plainly whether we can meet it.
Retention
Account and billing records are kept while your organization is active and afterwards for as long as we are required to keep them for tax and legal purposes.
Product data is kept under your organization retention settings. Memories are additionally subject to lifecycle cleanup, which expires stale entries automatically. When an organization is removed, tenant-scoped data held for it is removed.
Security
Data is encrypted in transit and at rest. Per-organization isolation is enforced at the database layer with row-level security, so isolation does not depend on application code being written correctly every time.
Sessions are managed server-side behind an opaque cookie, so browsers never hold tokens. Security events are audit-logged with the actor, the target, and the timestamp.
Your rights
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to processing, or receive a copy in a portable form.
To exercise any of these, contact us. We will respond within the period your law requires. If you are a member of a customer organization, some requests may need to be routed through that organization administrators, and we will tell you if that is the case.
Changes and contact
We will update this policy as the service changes, and each version carries an effective date and version number. Material changes will be notified before they take effect.
Privacy questions go through our contact page and reach a person, not a queue.
Ask before you sign.
If your legal or procurement team needs something changed, clarified, or evidenced, contact us and we will answer specifically rather than pointing at this page again.