Privacy

How the public beta handles data.

This notice describes the privacy boundaries for Hirdesh Viikram, trading as Errorcore and operating individually in India.

Effective publication version: privacy-2026-08-13.1.

Who operates Errorcore.

Hirdesh Viikram operates Errorcore individually in India under the trading name Errorcore. Privacy and grievance questions go to [email protected], the same published contact used for support.

Two different data roles.

For the site, account, organization, security, and service-administration information, Errorcore determines why that information is used. For runtime evidence submitted by a customer workspace, the customer decides what its software captures and why; Errorcore processes that evidence only to provide and secure the service on the customer's instructions.

Information the service may handle.

  • Website request and security metadata. Cookie, analytics, and precise website-log practices still require operator confirmation before a general launch.
  • Account and organization identifiers supplied through the identity provider.
  • Project, environment, configuration, usage, authentication, and security-event metadata.
  • Organization evaluation timestamps and per-envelope usage-ledger records used to enforce the one-time Free evaluation and paid allowances.
  • Customer-submitted runtime evidence such as stack frames, local values, ordered database or HTTP work, request and trace context, process metadata, error messages, and related identifiers.
  • Billing and transaction metadata only if paid billing through Polar is later verified and enabled.
  • Support messages, appointment details, and any information a requester deliberately sends.

Service providers and sharing.

Clerk provides authentication and organization identity. Polar is used only if paid products, prices, checkout, and billing processing are independently verified and enabled; paid checkout is disabled today. Google receives the IP address and request metadata of anyone who opens the appointment schedule embedded on the support page, because that schedule is served by Google Calendar. These providers operate outside India, so the information they receive is processed internationally. The current repository does not evidence an advertising integration. The operator must verify actual data practices and jurisdiction-specific definitions before publishing any categorical claim about sale, sharing, or targeted advertising.

Railway is used for current service deployment, but its contracting legal entity, deployed regions, and role-specific processing locations have not yet been confirmed for publication. PostgreSQL, Redis/Valkey, S3-compatible storage, KMS, and OTLP identify technologies, not confirmed vendors. The current evidenced integration list and unresolved facts are described in the review-required vendor record; no unevidenced provider is represented as a subprocessor.

Scrubbing reduces risk but cannot remove every sensitive value.

SDK scrubbing runs before payload encryption and server-side checks may run again during worker processing. Rules can redact known headers, credential patterns, and configured fields, but no rule set can guarantee that customer code, error messages, local values, query text, or custom payloads contain no personal, confidential, regulated, or secret data. Customers must configure capture and scrubbing lawfully and avoid sending data they are not permitted to process.

Workspace evidence-retention settings.

Current per-plan workspace evidence-retention settings appear on the live pricing page. Those values describe only that workspace setting. They are not a promise about account records, operational logs, derived artifacts, backups, billing records, deletion completion, or every copy of data.

Choices and rights.

People may request access, correction, deletion, restriction, objection, portability, or withdrawal where applicable law provides those rights. Send requests to [email protected]. Errorcore may need to verify identity before acting on a request; the verification workflow is not yet finalized, and no response time is committed during the beta. Requests about runtime evidence submitted by a customer workspace are directed to the customer organization that controls that evidence, because Errorcore processes it on that organization's instructions rather than its own.

Business use only.

The beta is intended only for organizations and adults acting in a business or professional capacity. It is not intended for children, consumer household use, or anyone under 18.

What this notice does not yet state.

Retention periods for account records, operational logs, derived artifacts, backups, and billing records are not published here, and neither is a deletion-completion period. Only the workspace evidence-retention setting described above is stated. Ask at [email protected] if you need a commitment this notice does not make.

The operator has also not yet published final facts for hosting and backup locations, cookie inventory, analytics use, purpose-by-purpose legal bases, or international-transfer safeguards. Those are factual and jurisdiction-specific launch decisions, not promises supplied by this notice. The notice must be updated and reviewed before any of those details are represented as settled.