Legal
Privacy Policy
What groundre collects, why, and the choices you have. Short version: your binaries stay yours.
Last updated 1 July 2026
01What we process
- Account data: name, email, organization, and billing details.
- Uploaded binaries and reports: processed to produce ground truth and verdicts; stored keyed by SHA-256 for cache reuse and deleted on request.
- Usage telemetry: endpoints called, job durations, and error traces — never the contents of your binaries.
02Your binaries
Samples are read only from paths or uploads you provide; remote and UNC sources are refused. Analysis happens behind an isolation boundary and only schema-validated facts cross back. We do not sell, share, or train models on your binaries.
Self-hosting keeps everything on your infrastructure — the binary never touches groundre’s servers at all.
03Retention & deletion
Cached ground truth and blobs expire on a rolling window and can be purged on demand. Deleting a job removes its verdicts and cached facts.
04Requests
For access, correction, or deletion requests, contact privacy@groundre.dev. We respond within statutory timelines under GDPR/CCPA.