Privacy
Last updated: August 12, 2026
The short version
The open-source package stores everything in your own database and sends us nothing. Vizra Cloud stores the results of eval runs you choose to report. We never receive your model API keys, your source code or your database credentials, and we never execute your code.
Two products, two answers
vizra/evals and its dashboard run entirely inside your application. Eval runs, prompts, responses and judge reasoning are written to your database and stay there. Installing the package sends us nothing at all — there is no telemetry, no phone-home and no account required.
Vizra Cloud is opt-in. It starts working when you add an API key to your environment, and it only ever receives what a finished run reports.
What we store when you use the cloud
Always
- ✓Run results — scores, pass rates, sample counts, durations and cost
- ✓Which suite ran, and a stable key identifying it
- ✓Git metadata: commit SHA, branch, whether the tree was dirty
- ✓CI context: the provider, a link to the build, and the pull request number
- ✓Your account: name, email address, and the team you belong to
By default, and you can switch it off
Per-sample detail is the input, the model's response, any structured output, tool calls and the judge's reasoning. This is verbatim model input and output, so if your eval datasets contain personal or confidential data, so does this. It is what makes the drill-down work — being able to read why a row scored what it did — and it is sent by default.
To send scores and nothing else, set
VIZRA_CLOUD_SAMPLES=false.
You keep trends, baselines, gates and CI checks, and lose only the ability to click into
a row and read what the model said.
What we never store
- ×Model API keys — OpenAI, Anthropic or anyone else. Your evals call the model, not us.
- ×Your source code, or any access to your repository.
- ×Database credentials, or any connection to your database.
- ×Card details. Payments go directly to Stripe and never touch our servers.
When you press Run in the dashboard we queue a request. Your own application collects it and runs the eval in your environment. We ask; we do not execute.
Cookies and analytics
The marketing pages use Google Analytics to count visits and see which pages people actually read. It sets cookies, so we ask before loading it — choose Reject and nothing is requested from Google at all. Your choice is stored in your browser; clear your site data to be asked again.
The signed-in product does not run analytics. The only cookies there are the session cookie that keeps you logged in and the CSRF token that protects forms — both strictly necessary, neither used for tracking.
We also record how you first arrived — the referring site, and any campaign tags on the link — against your team, so we know which channels are worth continuing. That is stored with your account rather than in a third-party profile, and it is deleted when your account is.
Payments
Subscriptions are handled by Stripe, who act as our payment processor. Card details are entered on Stripe's own checkout and are never seen by, or stored on, Vizra servers. We keep a Stripe customer reference, your plan, and your invoice history. VAT and sales tax are calculated by Stripe at checkout based on your location.
How long we keep it
Runs are kept for as long as your account exists, on every tier including free — the run, its score and pass rate, its per-row scores, and your baselines and trend history. Knowing whether something is worse than it was a year ago is the point of the product, so we do not age that out.
Per-sample detail is deleted once it is past your plan's window — see pricing for the window on each tier. That is the verbatim model input, the response, structured output, tool calls and judge reasoning: the part most likely to contain personal or confidential data. A scheduled job removes it daily.
One exception: the run currently marked as a baseline keeps its sample detail past the window, because every comparison is measured against it and losing the detail would make those comparisons unreadable. This is one run per suite — the first run a suite reports becomes its baseline, and promoting a different run demotes the old one, which then ages out normally. If a baseline holds data you need removed, delete the run or promote another in its place.
Deleting a project deletes its suites, runs, samples and API keys. Deleting your account removes it and everything belonging to it.
Your rights
You can delete your account and everything belonging to it at any time from your account settings, and revoking an API key stops anything still using it from reporting immediately. Datasets can be exported from the dataset screen; for a copy of everything else on your account, email us and we will put it together. If you are in the UK or EU you have the usual rights of access, correction, erasure and portability under UK GDPR and GDPR — email us and we will action it.
Questions
Email privacy@vizra.ai. If something here is unclear, that is a bug — tell us and we will fix the wording.