Last updated · June 25, 2026
Privacy Policy
This policy explains what Cairn collects, why, who we share it with, and the choices you have. It applies to the hosted Cairn service operated by Vela Partners. If you self-host Cairn, you are the controller of your own data and this policy does not apply.
1. Who we are
Cairn is an agentic end-to-end testing platform operated by Vela Partners(“we”, “us”). For privacy questions, contact privacy@cairn.dev.
2. Information we collect
Account information
When you sign in with GitHub, we receive your name, email address, avatar, and GitHub account identifier. We never receive your GitHub password.
Repository & code data
With your authorization (via the GitHub App you install), we access the repositories you connect: source files, routes, components, commit diffs, and related metadata. We use this to map user flows and generate tests. We do not use your private code to train machine-learning models.
Test & run artifacts
Running your tests produces artifacts we store on your behalf: generated test specs, run videos, Playwright traces, captured network requests and responses (HAR), screenshots, logs, and the issues and pull requests Cairn opens. These can incidentally contain data that appears in your application (including personal data) during a test run.
Usage data
We collect standard product and device telemetry — pages visited, actions taken, timestamps, IP address, and browser type — to operate and secure the service.
3. How we use your information
- Provide the service — map flows, generate and run tests, file issues, and draft fix PRs.
- Send transactional and recap emails you have configured.
- Maintain security, prevent abuse, and debug problems.
- Improve Cairn in aggregate, without using your private code to train models.
- Comply with legal obligations.
4. Legal bases (EEA/UK)
Where GDPR applies, we process personal data to perform our contract with you, on the basis of our legitimate interests in operating and securing the service, to comply with legal obligations, and — where required — with your consent.
5. Subprocessors & sharing
We share data with vendors who process it on our behalf, only as needed to run the service:
- GitHub, Inc. — repository access, authentication, issue and PR creation.
- Anthropic, PBC — Claude models used to triage failures and draft fixes.
- Google LLC — Gemini models used to map flows and draft issues.
- Railway Corp. — application hosting and managed PostgreSQL.
- Cloudflare, Inc. — object storage for run videos and traces.
- Resend — transactional and weekly-recap email delivery.
- Inngest, Inc. — background job orchestration.
- Vercel Inc. — hosting of the web application.
We do not sell your personal data. We may disclose information if required by law or to protect our rights and users.
6. Data retention
We keep account data while your account is active. Run artifacts are retained according to your plan and settings and are deleted when you delete the associated run, environment, or account. On account deletion we remove or anonymize your personal data within a reasonable period, except where retention is legally required.
7. Security
We use encryption in transit, scoped access tokens, and least-privilege access controls. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify you of incidents as required by law.
8. International transfers
We and our subprocessors may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object or withdraw consent. To exercise them, email privacy@cairn.dev. You may also complain to your local data protection authority.
10. Cookies
We use strictly necessary cookies to keep you signed in and to secure the service. We do not use advertising cookies.
11. Children
Cairn is not directed to children under 16, and we do not knowingly collect their personal data.
12. Changes
We may update this policy from time to time. Material changes will be posted here with a new “last updated” date.
13. Contact
Questions? Email privacy@cairn.dev.