Last updated 9 September 2026. We will post any material change on this page and, where it affects how we handle your data, tell account owners by email before it takes effect.
Monterva is operated by Antypas Ventures LLC, a limited liability company registered in Wyoming, United States, which is the data controller for the personal data described here. This policy explains what we collect, what we do with it, and — because it is the question that matters most for a product like this — exactly what happens to your source code.
What happens to your source code
When you start a review, we download the repository at the commit you chose, as an archive, using a token scoped to the repositories you chose to connect. We extract it to a working directory on our scanner host and run a fixed set of analysis tools over the files.
- We never execute your code, and never install its dependencies. Analysis is static: the tools read your files. Nothing in your repository is run, and no package named in your lockfiles is fetched or installed.
- The copy is deleted when the review ends — on success and on failure alike. We do not keep a copy of your repository, and we have no archive of your source.
- We keep short excerpts, not files. A finding stores the file path, the line numbers, and a snippet of at most 2,000 characters around the match, so the finding can be understood. Anything that looks like a credential is masked in that snippet before it is stored.
- The scan runs in an isolated container with no network access, so your code cannot reach the internet from inside our analysis.
What we collect about you
- Account: your email address, your name if you give one, and the workspaces you belong to.
- Repositories: the owner and name of each repository you connect, its default branch, and the commit each review ran against.
- Reviews: findings, coverage, severity counts and timings for each review you run.
- Operational logs: request identifiers, timestamps and errors. Our logs deliberately exclude anything derived from the content of your repository.
We do not use third-party advertising or tracking, and we do not sell or share your data with anyone for their own purposes.
The GitHub connection
Monterva connects through a GitHub App that you install, and you choose which repositories it can see. Its permissions are read-only: it can read repository contents and metadata for the repositories you selected. It cannot write to your code, open pull requests, or act on your behalf. You can revoke the installation from GitHub at any time, which immediately ends our access.
Automated explanations
Where explanations are enabled, we may send a description of a finding — its rule, severity, file path and the stored snippet — to a language model provider, which returns a plain-language explanation. The model receives only that finding, never your repository. It has no ability to change a finding, its severity, or anything else in your account: every finding is produced by a deterministic scanner, and the model only writes prose about findings that already exist. Reports mark clearly which text was written this way.
Who processes your data
- Supabase — database and authentication, hosted in the European Union (Frankfurt).
- DigitalOcean — application and scanner hosting, in Frankfurt and Amsterdam.
- Resend — transactional email, such as confirming your address and telling you a review has finished.
- GitHub — the source of the repositories you connect.
- Stripe — payments, once paid plans are available. Monterva never sees or stores your card details.
- A language model provider, where explanations are enabled, on the narrow basis described above.
Your account and review data are stored in the European Union. A sub-processor may process data elsewhere in the course of providing its service; we will update this list before adding a new one.
Antypas Ventures LLC is registered in the United States, so although your data is stored in the EU, it may be accessed from the United States by us in the course of operating and supporting the service. Where we transfer personal data out of the UK or the European Economic Area, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum. If you need a copy of those, ask us.
How long we keep things
- Your source code: only for the duration of a review.
- Reviews and findings: until you delete them, or until you close your account.
- Account records: until you close your account.
- Backups: our database is backed up daily; a deleted record can persist in a backup for a short period before it ages out.
Your rights
If you are in the UK or the European Economic Area, you have the right to access the personal data we hold about you, to have it corrected or deleted, to object to or restrict how we use it, and to receive a copy in a portable form. You can also complain to your data protection authority.
You can delete your account from your profile settings, which removes your account and the workspaces you solely own, along with their reviews and findings. To exercise any other right, or to ask what we hold, write to us and we will respond within one month.
Security
Access to your data is enforced in the database itself, so one workspace's reviews cannot be read from another. Traffic is encrypted in transit. We keep the number of people and systems that can reach production data as small as we practically can.
No system is immune. If we become aware of a breach affecting your personal data, we will tell affected account owners and, where required, the relevant regulator.
Cookies
We set the cookies needed to keep you signed in and to remember your interface preferences. We do not use advertising or analytics cookies.
Children
Monterva is for professional use and is not directed at anyone under 16.
Contact
Antypas Ventures LLC — write to us at hello@monterva.com with any question about this policy or your data.