RebarRebar

Privacy Policy

Last updated June 14, 2026

This Privacy Policy explains how Rebar (“Rebar”, “we”, “us”), operated by Grayhaven, collects, uses, and protects information when you use the Rebar service and operator console at rebarcore.com (the “Service”). Rebar is an autonomous production-software monitoring and repair tool: it observes the systems you connect, diagnoses breakage, and proposes reversible fixes for your approval.

Information we collect

  • Account and identity. When you sign in, our authentication provider (Clerk) processes your email address, name, and organization membership. We use this to authenticate you and to scope your data to your organization.
  • Connection credentials. When you connect a provider (such as Vercel or GitHub), we store the access token or installation grant you authorize. These credentials are encrypted at rest and are used only to observe and repair the systems you connect.
  • Operational data. From your connected systems we process deploy events, runtime observations, error signals, and detected breakage, along with the diagnoses, proposed fixes, approvals, and outcomes Rebar generates. This is the data the Service exists to act on.
  • Usage and log data. Standard technical data such as IP address, request metadata, and timestamps, used for security and to operate the Service.

How we use information

  • To provide the Service: detect divergence from your systems’ expected behavior, diagnose causes, and propose reversible fixes.
  • To present proposed changes for your review and approval. Rebar does not modify your production systems without your authorization.
  • To secure, maintain, and improve the Service.
  • To communicate with you about your account and service-related notices.

We do not sell your personal information, and we do not use your code, operational data, or credentials to train our own models.

Legal bases (where applicable)

Where the GDPR or similar laws apply, we process personal data to perform our contract with you, on the basis of our legitimate interest in operating and securing the Service, to comply with legal obligations, and, where required, with your consent.

Service providers and sub-processors

We share data with infrastructure providers that help us run the Service, under agreements that limit their use of the data:

  • Clerk: authentication and organization management.
  • Supabase: primary database (PostgreSQL).
  • Vercel: application hosting.
  • Trigger.dev: background task execution.
  • Anthropic and OpenAI: the model provider you select processes the breakage signals needed to produce a diagnosis. Diagnosis runs under the provider’s zero-retention / no-training terms where available.

Security

Connection credentials are encrypted at rest (AES-256-GCM). Data is transmitted over TLS. Each organization’s data is logically isolated (per-tenant scoping), and the access you grant is scoped and revocable at any time from the console.

Data retention and deletion

We retain your data for as long as your account is active or as needed to provide the Service. Connection credentials are retained until you revoke the connection. You may request deletion of your account and associated data by contacting us; we will delete it except where retention is required by law.

Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at the address below.

Cookies

We use strictly necessary cookies to keep you signed in (set by Clerk). We do not use advertising cookies.

Children

The Service is intended for businesses and is not directed to individuals under 18. We do not knowingly collect data from children.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “last updated” date above, and where appropriate we will notify you.

Contact

Questions or requests regarding this policy or your data: privacy@rebarcore.com.