CARL

Last updated: 2026-04-22

Privacy Policy

This Privacy Policy explains how Wentzel.ai ("Wentzel.ai," "we," "our") collects, uses, and safeguards information when you use the CARL Assessor App at app.carl.wentzel.ai.

This page is a draft. It is intentionally high-level until final legal review; consult our Privacy Architecture page for the engineering-level description of how CARL handles code.

Information we collect

  • Repository identifiers (e.g., vercel/next.js) that you submit.
  • Assessment reports we generate on your behalf.
  • Email address you provide when downloading a report as PDF.
  • Server-side access logs retained for security and debugging.
  • Account information if you authenticate via GitHub OAuth.

What we do not collect

We do not store source code from assessed repositories. We do not log file contents. We do not use your code for training models. See our Privacy Architecture page for the technical enforcement of these guarantees.

How we use information

  • Produce and display your assessment reports.
  • Send you a PDF copy when you request one.
  • Operate, secure, and improve the service.
  • Communicate service updates when you've explicitly opted in.

Sharing

We do not sell personal data. We share data only with service providers that power the app (hosting, email delivery) under appropriate contracts, and with authorities when legally required.

Retention

We keep reports for the lifetime of your account or the retention window in effect at the time, whichever is shorter. You may delete reports at any time via your dashboard.

Your choices

  • Opt out of marketing emails via the unsubscribe link in any message.
  • Request account deletion by emailing privacy@wentzel.ai.
  • Use the self-hosted Docker image for air-gapped operation.

Contact

Privacy questions: privacy@wentzel.ai. Security disclosures: security@wentzel.ai.