Privacy policy
Last updated 2026-10-06
VDB (vdb.ai.kr) is operated by Opstech Inc. This page says what the service records about you, why, who else receives it, and how to have it removed. Questions and requests: customer@opstech.kr.
What we collect, and why
- Your account. Email address, password (stored only as a hash), whether you agreed to product email, when you signed up and last signed in. API keys are stored as hashes; only a short prefix is kept to show you which key is which.
- API requests. For each request: the endpoint, the response status, the time, your IP address and a hash of it, your User-Agent, the page language, which package ecosystems were asked about, and your account if you used a key. This runs rate limits, blocks abuse, and counts usage. Sign-up and key requests are recorded the same way, without the email address.
- Page views. The page, a hash of your IP address, the language, and your browser's User-Agent — to count visits. Not linked to your account.
- Abuse blocks. If an address or account trips a rate limit, we record the block: the address (and its hash) or the account, why, and until when.
- Packages you check. Names and versions sent to the package gate are looked up to answer you. We record the request as above, not the list you sent.
- SBOM scans. An uploaded file is parsed in memory to match its components and is not stored.
- SBOM Watch. The component list (package names and versions) of an SBOM you register, kept until you delete the watch, so we can tell you when one of them gets a new advisory.
- Hardening analyses. The abstracted representation the client builds on your machine (never your source text), the dependency manifest you send, a project name (your folder's name unless you pass
--project), and the result — kept so the analysis can be re-checked when a dependency's summary changes. A VEX document you generate is stored and gets a URL, so it can be shared; anyone with the URL can read it. - Bug reports and blog comments. What you write and attach. A comment is shown with the first two characters of your email address.
We send account email (verification, keys, password links), alerts you set up (SBOM Watch, hardening risk paths), and product email only if you agreed to it. Mail is delivered through Google's mail service. Risk-path mail carries a link that stops it; for anything else, write to us.
Cookies
- Session. After you sign in, a signed, HttpOnly cookie holds your account id and email so the site knows it is you. It is not used for anything else.
- Advertising. Pages with content show ads from Google AdSense. Ads are not shown on sign-in, sign-up, account or verification pages.
- Ad measurement. We advertise VDB on Google. A Google Ads tag on our pages tells us whether a visit that came from one of our ads led to a sign-up. It sets Google advertising cookies and is covered by the opt-outs below.
Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to this site and/or other sites on the Internet. You can opt out of personalised advertising in Google's Ads Settings, or opt out of some third-party vendors' use of cookies for personalised advertising at aboutads.info. How Google uses data from sites that use its services: policies.google.com/technologies/partner-sites.
Who else receives data
- Google — advertising (above) and email delivery.
- ip-api.com — to count traffic by country and network, visitor IP addresses are sent to ip-api.com. That request is currently made over plain HTTP, which means the addresses travel unencrypted. We are replacing it with a lookup that stays on our server, and this line will change when that ships.
- Package registries (npm, PyPI, crates.io, the Go module proxy, Hugging Face) — when we check a package we ask the registry about it by name. Nothing about you is sent.
- Vultr — our servers are hosted there.
We do not sell personal data.
How long we keep it
- IP addresses in API request records and abuse blocks are erased after 30 days; only a one-way hash stays, so traffic can still be counted.
- API request records and page views are deleted after one year; abuse blocks one year after they end.
- Account data, SBOM Watch registrations and hardening analyses are kept until you delete them or ask us to.
- The country lookup cache keyed by IP address expires after 30 days.
These limits are applied by a job that runs every day.
Your choices
- Delete your account and the data tied to it: email customer@opstech.kr from the address on the account.
- Stop alerts with the link in the mail, or delete the watch.
- Ask what we hold about you, or have it corrected — same address.
- Turn off personalised ads in Google's Ads Settings (above).
Changes
When what the service collects changes, this page changes with it and the date at the top moves. Material changes are also listed in the changelog.