{"doc":"privacy","title":"Privacy Policy","revisions":[{"sha":"36b3434","date":"2026-06-03","label":"First published","note":"The policy Vega launched with. It names what the cache processes, says which of it is public because verification depends on it being public, and states what Vega does not keep: no precise location, no retained IP, no stored OIDC token and no behavioural tracking.","text":" Vega Cache is a verifiable Nix binary cache operated by Ad Astra Computing Inc. It is free to use. This policy describes what data Vega processes and why. What Vega processes GitHub identity — your numeric GitHub user id and login, from GitHub Actions OIDC tokens, the owner credential created by vega login, and the Vega GitHub App. Build provenance — the repository, commit SHA, workflow run id, flake reference, revision, and the output store paths with their NAR hashes. Build artifacts — the compressed NAR bytes of builds you publish, stored in Cloudflare R2. Attestation continent — continent granularity only, derived from the request's geolocation; never a city, precise location, or retained IP. It is on by default. Set privacy.continent: false in vega.yaml to opt out, after which you are recorded as unknown and excluded from every geographic aggregate. View tokens and trust edges — opaque per-consumer substituter tokens and the scoped trust relationships you create. Public by design Vega's purpose is verifiability, so attestations are public. The append-only RFC 9162 transparency log, per-output /status pages, shared-tier signatures, and the aggregate, k-anonymous Network Health view are all public. An attestation records the build's provenance, output hashes, builder identity, and continent. What Vega does not collect No precise location or IP is retained for the social graph (continent only). OIDC tokens are verified and not stored. CI authenticates with short-lived OIDC, with no long-lived stored secret. There is no advertising or behavioral tracking. Third-party processors Vega runs on Cloudflare (Workers compute, R2 object storage, Pages hosting, CDN) and Fly.io (Vega-operated reproduction workers), and uses GitHub for OIDC identity verification, the GitHub App that posts commit checks, and the API used to check account age for attester eligibility. Vega fetches build dependencies from the upstream mirror cache.nixos.org; no user data is shared with it. Your controls Rotate your view token at any time (this instantly revokes the old one), revoke trust edges, opt out of continent publication, and note that vega push artifacts live only in your own tenant namespace. Not an AI system Vega is not an AI system; there is no model in its trust, signing, or moderation path. Contact Security and privacy: security@adastracomputing.com. General: vega@adastracomputing.com."},{"sha":"a8a3b42","date":"2026-06-03","label":"Processors named on their own page","note":"The section listing third parties became a pointer to a standalone page. Before this you had to trust a summary; now every processor is named with what it does and which data reaches it, and that list can be kept current without editing the policy.","text":" Vega Cache is a verifiable Nix binary cache operated by Ad Astra Computing Inc. It is free to use. This policy describes what data Vega processes and why. What Vega processes GitHub identity — your numeric GitHub user id and login, from GitHub Actions OIDC tokens, the owner credential created by vega login, and the Vega GitHub App. Build provenance — the repository, commit SHA, workflow run id, flake reference, revision, and the output store paths with their NAR hashes. Build artifacts — the compressed NAR bytes of builds you publish, stored in Cloudflare R2. Attestation continent — continent granularity only, derived from the request's geolocation; never a city, precise location, or retained IP. It is on by default. Set privacy.continent: false in vega.yaml to opt out, after which you are recorded as unknown and excluded from every geographic aggregate. View tokens and trust edges — opaque per-consumer substituter tokens and the scoped trust relationships you create. Public by design Vega's purpose is verifiability, so attestations are public. The append-only RFC 9162 transparency log, per-output /status pages, shared-tier signatures, and the aggregate, k-anonymous Network Health view are all public. An attestation records the build's provenance, output hashes, builder identity, and continent. What Vega does not collect No precise location or IP is retained for the social graph (continent only). OIDC tokens are verified and not stored. CI authenticates with short-lived OIDC, with no long-lived stored secret. There is no advertising or behavioral tracking. Subprocessors Vega relies on a small set of third parties to operate the cache. The current list, with the purpose and data handled by each, is published at /subprocessors. Your controls Rotate your view token at any time (this instantly revokes the old one), revoke trust edges, opt out of continent publication, and note that vega push artifacts live only in your own tenant namespace. Not an AI system Vega is not an AI system; there is no model in its trust, signing, or moderation path. Contact Security and privacy: security@adastracomputing.com. General: vega@adastracomputing.com."},{"sha":"f2cc3d7","date":"2026-07-21","label":"Sticker addresses disclosed","note":"Requesting a free sticker collects a name and a US postal address, and the policy did not say so. This adds the section that does. It is the only place Vega asks for a postal address, it is only used to post that one sticker, and it is deleted once the sticker is marked shipped.","text":" Vega Cache is a verifiable Nix binary cache operated by Ad Astra Computing Inc. It is free to use. This policy describes what data Vega processes and why. What Vega processes GitHub identity — your numeric GitHub user id and login, from GitHub Actions OIDC tokens, the owner credential created by vega login, and the Vega GitHub App. Build provenance — the repository, commit SHA, workflow run id, flake reference, revision, and the output store paths with their NAR hashes. Build artifacts — the compressed NAR bytes of builds you publish, stored in Cloudflare R2. Attestation continent — continent granularity only, derived from the request's geolocation; never a city, precise location, or retained IP. It is on by default. Set privacy.continent: false in vega.yaml to opt out, after which you are recorded as unknown and excluded from every geographic aggregate. View tokens and trust edges — opaque per-consumer substituter tokens and the scoped trust relationships you create. Public by design Vega's purpose is verifiability, so attestations are public. The append-only RFC 9162 transparency log, per-output /status pages, shared-tier signatures, and the aggregate, k-anonymous Network Health view are all public. An attestation records the build's provenance, output hashes, builder identity, and continent. What Vega does not collect No precise location or IP is retained for the social graph (continent only). OIDC tokens are verified and not stored. CI authenticates with short-lived OIDC, with no long-lived stored secret. There is no advertising or behavioral tracking. Subprocessors Vega relies on a small set of third parties to operate the cache. The current list, with the purpose and data handled by each, is published at /subprocessors. Free stickers If you request a free sticker at /stickers, Vega collects the name and US postal address you enter, and your GitHub account age, solely to ship that one sticker. This is the only place Vega collects a postal address, and only if you choose to ask for one. The address is stored by Cloudflare and sent to the Ad Astra operator mailbox to fulfil the order. It is deleted from Vega's store once the sticker is marked shipped, is never published, sold, or shared beyond shipping the sticker, and is limited to one request per GitHub user. Your controls Rotate your view token at any time (this instantly revokes the old one), revoke trust edges, opt out of continent publication, and note that vega push artifacts live only in your own tenant namespace. Not an AI system Vega is not an AI system; there is no model in its trust, signing, or moderation path. Contact Security and privacy: security@adastracomputing.com. General: vega@adastracomputing.com."},{"sha":"1789223","date":"2026-09-08","label":"Website measurement disclosed","note":"The site counts page views with Cloudflare Web Analytics, and the policy did not say so. This adds the section that does: what a single page view records, that no cookie is set and no identifier ties two visits together, and that the cache endpoints Nix talks to are not measured at all.","text":" Vega Cache is a verifiable Nix binary cache operated by Ad Astra Computing Inc. It is free to use. This policy describes what data Vega processes and why. What Vega processes GitHub identity — your numeric GitHub user id and login, from GitHub Actions OIDC tokens, the owner credential created by vega login, and the Vega GitHub App. Build provenance — the repository, commit SHA, workflow run id, flake reference, revision, and the output store paths with their NAR hashes. Build artifacts — the compressed NAR bytes of builds you publish, stored in Cloudflare R2. Attestation continent — continent granularity only, derived from the request's geolocation; never a city, precise location, or retained IP. It is on by default. Set privacy.continent: false in vega.yaml to opt out, after which you are recorded as unknown and excluded from every geographic aggregate. View tokens and trust edges — opaque per-consumer substituter tokens and the scoped trust relationships you create. Public by design Vega's purpose is verifiability, so attestations are public. The append-only RFC 9162 transparency log, per-output /status pages, shared-tier signatures, and the aggregate, k-anonymous Network Health view are all public. An attestation records the build's provenance, output hashes, builder identity, and continent. What Vega does not collect No precise location or IP is retained for the social graph (continent only). OIDC tokens are verified and not stored. CI authenticates with short-lived OIDC, with no long-lived stored secret. There is no advertising or behavioral tracking. Website measurement Pages on this website are counted with Cloudflare Web Analytics, which sets no cookie and builds no cross-site profile. A page view reports the address of the page, the referring address and the browser, operating system and country Cloudflare derives from the request. There is no identifier that ties two visits together, and nothing measured here reaches your Vega account or any attestation. The cache endpoints Nix talks to return no HTML and are not measured at all. Subprocessors Vega relies on a small set of third parties to operate the cache. The current list, with the purpose and data handled by each, is published at /subprocessors. Free stickers If you request a free sticker at /stickers, Vega collects the name and US postal address you enter, and your GitHub account age, solely to ship that one sticker. This is the only place Vega collects a postal address, and only if you choose to ask for one. The address is stored by Cloudflare and sent to the Ad Astra operator mailbox to fulfil the order. It is deleted from Vega's store once the sticker is marked shipped, is never published, sold, or shared beyond shipping the sticker, and is limited to one request per GitHub user. Your controls Rotate your view token at any time (this instantly revokes the old one), revoke trust edges, opt out of continent publication, and note that vega push artifacts live only in your own tenant namespace. Not an AI system Vega is not an AI system; there is no model in its trust, signing, or moderation path. Contact Security and privacy: security@adastracomputing.com. General: vega@adastracomputing.com."}]}