Privacy Notice
Last updated: 12 August 2026
This notice explains what Jordan Sserugo collects when you use Villa Code, why, and what control you have. It covers the source code you submit for analysis, which we treat as confidential.
1. Who is responsible
Jordan Sserugo, based in Uganda is the data controller for the personal data described here. Contact us at jomodes82@gmail.com.
2. What we collect
- Account data — email address, name, password hash, and (if you sign in with GitHub) your GitHub account identifier.
- Source code and repository content — the files you choose to validate, and metadata such as file paths, commit references and diffs, submitted so we can analyse them.
- Validation output — the documentation and findings generated from your code.
- Usage and billing data — plan, credit balance and consumption, request counts, timestamps, and payment records (see section 5).
- Technical data — IP address, browser/extension version and error logs, used for security and debugging.
3. How we use it
- To provide the service: running validations and returning results to you.
- To operate your account, apply plan limits, and meter credit usage.
- To take payment and provide invoices and support.
- To secure the service — detecting abuse, fraud and technical faults.
- To comply with legal obligations, including tax and accounting rules.
Our legal bases are performance of our contract with you, our legitimate interests in securing and improving the service, and compliance with law. Where we rely on consent, you can withdraw it at any time.
4. Your source code — how it is handled
Code you submit is transmitted over encrypted connections and processed to produce your validation results. It is used only to provide the service to you.
- We do not use your code to train our own models, and we do not sell it or share it for advertising.
- To perform the analysis, code is sent to third-party AI model providers acting as our processors under contract. We use providers whose terms prohibit training on data submitted through their business APIs.
- If you supply your own provider API key ("bring your own key"), your code is sent directly to that provider under your account and their terms govern that processing.
- Validation results are stored in your account so you can revisit them, and are deleted when you delete them or close your account.
5. Who we share data with
We share data only with service providers who help us run the product:
- Payment providers (Paddle, PesaPal) — to take payment. A payment provider may act as merchant of record, meaning they are the seller for the transaction and handle billing data, tax and invoicing. We do not receive or store your full card details.
- AI model providers — to perform code analysis, as described above.
- Cloud hosting and database providers — to run and store the service.
- Email delivery providers — to send verification and service emails.
- Authorities — where we are legally required to disclose.
6. International transfers
Our providers may process data outside your country. Where required, transfers are covered by appropriate safeguards such as Standard Contractual Clauses.
7. Retention
- Account data — kept while your account is open, then deleted or anonymised.
- Submitted code and validation results — kept until you delete them or close your account.
- Payment and invoice records — kept for as long as tax and accounting law requires (typically 6–7 years).
- Security and error logs — kept for a limited period, then deleted.
8. Security
We use encryption in transit, hashed credentials, access controls and scoped API keys. No system is perfectly secure, but we work to protect your data and will notify you and any relevant regulator of a breach where the law requires it.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the use of your personal data, and to object to certain processing. To exercise any of these, email jomodes82@gmail.com. You can also complain to your local data protection authority.
10. Cookies
We use cookies that are strictly necessary to keep you signed in and to keep the service secure. We do not use advertising cookies.
11. Children
The service is not intended for anyone under 18, and we do not knowingly collect their data.
12. Changes
We will post any update here and change the date above. If a change materially affects how we use your data, we will notify account holders directly.