Privacy Policy

Last updated: September 26, 2026

This Privacy Policy explains what A10N, Inc., a Delaware corporation doing business as "sloprail" ("sloprail", "we", "us"), collects, and doesn't collect, through the sloprail website at sloprail.com (the "Site") and the sloprail software (the "Software").

Legal framework

This Privacy Policy is prepared with the General Data Protection Regulation (GDPR) in mind, as well as the German Telemedia/Digital Services framework (DDG). See also our Impressum for our German-law legal notice.

Operator

A10N, Inc.
d/b/a "sloprail" (trade name registration in progress)
A Delaware corporation
Represented by: Mykyta Svyrydenko
Email: [email protected]

The Site

The Site is hosted on Cloudflare Pages and uses Cloudflare Web Analytics for aggregate page-view metrics. It has no sign-up forms, login, or accounts, so we don't collect names, emails, or other personal information through it.

Fonts are self-hosted with the Site's own build (not loaded from Google Fonts or another third-party font CDN), so visiting the Site doesn't send your browser's requests to a font provider.

Partner referral links (sloprail.com/r/<handle>) redirect you to the Site and log one row per click: the handle, a timestamp, and optionally your country — no IP address, no cookies, no user agent, and no other identifier.

Cloudflare Pages may also collect standard server logs (e.g. IP address, requested URL, timestamp, user agent) purely to operate and secure the Site, as most hosts do. We don't use it for tracking or marketing.

The Software

sloprail runs entirely on your own machine, as a plugin inside a coding agent harness (e.g. Claude Code). We don't operate a backend service that the Software calls, and the Software does not phone home: it makes no network calls to any server we control, and sends us no telemetry, usage data, or analytics.

Judging guardrails ("sr-agent") work by invoking a coding-agent harness that is already configured on your machine, using your own credentials (for example, an ANTHROPIC_API_KEY or equivalent environment variable you've already set). That harness then talks directly to the model provider you've configured — not to sloprail. Any data sent to a model provider (such as code or prompts) is governed by that provider's own terms and privacy policy, not by us.

Because the Software is open source under the MIT License, you're welcome to verify this directly by reading the source at github.com/sloprail/sloprail.

The Site links to that repository, and installs of the Software download releases directly from GitHub. GitHub, Inc. is not our sub-processor for this — it's an independent controller of any data it collects from you when you visit GitHub or download a release, under GitHub's own privacy statement (see "Third-party links" below).

Legal basis for processing

Server access logs: our legal basis is legitimate interest (GDPR Art. 6(1)(f)) in operating and securing the Site.

Cloudflare Web Analytics: because it is cookieless, stores nothing on your device, and only produces aggregate page-view metrics with no individual profile built, this does not require your consent — our legal basis is again legitimate interest (GDPR Art. 6(1)(f)) in understanding aggregate Site usage.

Partner referral link clicks (handle, timestamp, optional country — see "The Site" above): our legal basis is legitimate interest (GDPR Art. 6(1)(f)) in measuring which partner referral links are used. This data is not tied to an IP address, cookie, or any other identifier that could single out an individual visitor.

Email you send to [email protected]: our legal basis is legitimate interest (GDPR Art. 6(1)(f)) in receiving and responding to your message, or performance of a contract (GDPR Art. 6(1)(b)) where your message relates to one.

None of this processing is based on consent, and we don't use any of it for any other purpose.

Cookies and similar technologies

The Site sets no cookies and uses no local storage, device fingerprinting, or other persistent identifier — no essential cookies, no analytics cookies, no advertising or tracking cookies of any kind. Cloudflare Web Analytics is cookieless and stores nothing on your device; the partner referral links log only a handle, a timestamp, and optionally a country, with no cookie or other identifier involved. Because nothing is stored on your device and no consent-requiring technology is used, there is no cookie banner — there is nothing to consent to.

We have no plans to use marketing, advertising, or cross-site tracking cookies. If that ever changes, we will add a consent banner and update this section before the change takes effect.

Sub-processors

We use two sub-processors today:

Cloudflare, Inc. (United States), across three uses:

  • Cloudflare Pages — hosts the Site and serves standard server logs (see "The Site").
  • Cloudflare Web Analytics — aggregate, cookieless page-view metrics (see "Cookies and similar technologies").
  • A Cloudflare Pages Function, backed by Workers Analytics Engine — logs partner referral link clicks (handle, country, timestamp only; see "The Site").

Cloudflare's Privacy Policy and Customer DPA describe its own processing in detail.

Google LLC (United States), for Google Workspace, which hosts the mailbox that email sent to [email protected] is delivered to, so Google processes the contents of any message you send us. Our Google Workspace account is registered to a United States region, so Google LLC — not Google Ireland Limited — is the contracting and processing entity, including for messages from EEA senders. Google's Privacy Policy and Cloud Data Processing Addendum (which also covers Google Workspace) describe its own processing in detail.

GitHub, Inc. is not our sub-processor: the Site links to our GitHub repository and Software installs download releases from GitHub, but GitHub acts as an independent controller of any data it collects from you directly, not as a processor on our behalf. See "Third-party links" below and GitHub's General Privacy Statement.

If we add another third-party service that processes personal data on our behalf, we'll name it here along with what it processes and where it's based.

International data transfers

Cloudflare, Inc. is based in the United States, so the limited data described above (server logs, aggregate analytics, and referral-link click logs) can involve a transfer from the EU to the US. This is covered by the EU-U.S. Data Privacy Framework, which Cloudflare has self-certified to, with the European Commission's Standard Contractual Clauses as a fallback safeguard where the Framework doesn't apply — per Cloudflare's Customer DPA.

Google LLC is also based in the United States, so email you send to [email protected] can likewise involve a transfer from the EU to the US. This is covered the same way: the EU-U.S. Data Privacy Framework, to which Google LLC has self-certified (see Google's Data Privacy Framework page), with Standard Contractual Clauses as a fallback safeguard where the Framework doesn't apply — per the Google Workspace/Cloud Data Processing Addendum.

Data retention

Server access logs and Cloudflare Web Analytics data are retained only as long as Cloudflare's default policy provides, for operational, security, and aggregate-reporting purposes. Referral-link click logs (handle, timestamp, optional country) are kept only as long as useful for measuring partner referral performance. Email you send us is retained in our Google Workspace mailboxes for as long as needed to handle your inquiry and for our own records, per our standard mailbox retention settings.

Your rights

Under GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing
  • Withdraw consent (where processing is based on consent)

To exercise these rights, contact us at [email protected].

Supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. Given our founder's base in Berlin, the relevant authority is likely the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), though you may also contact the supervisory authority in your own EU member state. This does not affect any other administrative or judicial remedy you might have.

California visitors (CCPA/CPRA)

The CCPA/CPRA's business thresholds (revenue, data volume, or revenue share from selling personal information) don't currently apply to us. If that changes as we grow, we'll update this section accordingly.

Security

We rely on our hosting provider's standard security practices to protect the limited data the Site touches. If we ever become aware of a data breach affecting your personal data, we will notify affected users as required by applicable law.

Third-party links

The Site links to third-party sites — most notably GitHub, Inc., for our repository, issue tracker, and Software release downloads. GitHub is an independent controller for any data it collects when you visit github.com or download a release, not our sub-processor; see its General Privacy Statement. Third-party sites we link to have their own privacy practices, which we don't control.

Changes to this policy

If what we collect changes — for example, if we add cookies or accounts in the future — we'll update this page and the "Last updated" date above before the change takes effect.

Contact

Questions about this policy, or a GDPR data-subject request? Email [email protected] or open an issue on GitHub.

See also our Terms of Service and Impressum.