Privacy Policy

Last updated: May 21, 2026

Delphik ("we", "us") operates the benchmark defect hub at posttrain.dev. This policy explains what we collect, why we collect it, and the choices you have.

1. Information We Collect

  • Account data: email address and display name. If you sign in with GitHub or another supported OAuth provider, we receive the profile data required to authenticate you, such as email, name, handle, and avatar.
  • Defect activity: reports you submit, upstream URLs, evidence text, task identifiers, trajectories you attach, source channel, routing status, and public contribution statistics.
  • Operational logs: standard server logs (timestamp, IP, user-agent) for security and abuse prevention. Retained up to 90 days.

2. How We Use Information

  • Authenticate your account and keep you signed in.
  • Route defect reports, prevent spam, and show public contribution history.
  • Publish confirmed defect records as an open dataset to improve AI evaluation. Public exports focus on benchmark, task, evidence, taxonomy, and fix status.
  • Investigate abuse and enforce the Terms of Service.

3. Sharing

We do not sell personal data. We share with:

  • Supabase: managed authentication and Postgres hosting for our application data.
  • Vercel: application hosting and edge runtime.
  • OAuth providers: authentication, only when you choose to sign in with that provider.

Public benchmark pages may show reporter handles, evidence links, and summaries when those are part of the confirmed public record. Private-program data, if introduced later, may be governed by additional agreements.

4. Data Retention and Deletion

We keep your account and defect activity while your account is active. To delete your account and personal data, email us at jongwon.park@posttrain.dev. We will delete or anonymize your data within 30 days. Defect records that have already been included in a public dataset release remain in that release, but are not linked to your identity.

5. Security

Passwords are managed by Supabase Auth (bcrypt-hashed). Application traffic is served over HTTPS. We use scoped service tokens for server-to-database access. No system is perfectly secure; report suspected issues to jongwon.park@posttrain.dev.

6. Children

Delphik is not directed to anyone under 16. We do not knowingly collect data from children. If you believe a minor has registered, contact us and we will remove the account.

7. International Users

Our infrastructure is hosted in regions chosen by Vercel and Supabase. By using Delphik you consent to processing of your data in those regions.

8. Changes

We may update this policy as the product evolves. Material changes are announced on the site and in the "Last updated" date above.

9. Contact

Questions or requests: jongwon.park@posttrain.dev.

See also our Terms of Service.