{"doc":"subprocessors","title":"Subprocessors","revisions":[{"sha":"a8a3b42","date":"2026-06-03","label":"First published","note":"The page the privacy policy points at. It names Cloudflare, Fly.io and GitHub, what each one does for Vega and which data reaches it, so you can see the list rather than take a summary on trust.","text":" Vega Cache is operated by Ad Astra Computing Inc. The third parties below process data on Vega's behalf. We keep this list current; a material change is reflected here. See the Privacy Policy for what Vega processes and why. Cloudflare, Inc. Edge compute, storage, hosting, CDN, DNS Runs the Vega Worker, stores published NAR artifacts in R2 object storage, hosts the documentation on Pages, and serves the cache and its DNS over Cloudflare's CDN. Processes request metadata and the continent-level geolocation Vega records (never a precise location or retained IP). United States; global edge network Fly.io, Inc. Reproduction-worker microVMs Runs Vega-operated reproduction workers: ephemeral, per-job microVMs that rebuild public source from scratch to verify a build. These machines hold no Vega credential and process only public source and build outputs, not user data. United States; configurable regions GitHub, Inc. (Microsoft Corporation) Identity, commit checks, eligibility Verifies builder identity through GitHub Actions OIDC, hosts the Vega GitHub App that posts commit checks, and provides the API Vega queries to check an attester's account age for eligibility. Processes your numeric GitHub user id, login, and build provenance (repository, commit, workflow run). OIDC tokens are verified and not stored. United States Upstream dependency (no data shared) Vega fetches public build dependencies from cache.nixos.org, the upstream Nix binary cache operated by the NixOS Foundation. Vega sends it no user data; it is listed here for completeness, not as a subprocessor. Changes When Vega adds or replaces a subprocessor, this page is updated before the change takes effect for new data. Contact Privacy questions: security@adastracomputing.com."},{"sha":"29debcc","date":"2026-06-03","label":"Where reproduction workers run","note":"Fly.io's locations were given as configurable regions, which told you nothing you could check. They are now named: United States, Europe and Asia. These machines rebuild public source and hold no user data, so the change is about being able to verify the claim rather than about new processing.","text":" Vega Cache is operated by Ad Astra Computing Inc. The third parties below process data on Vega's behalf. We keep this list current; a material change is reflected here. See the Privacy Policy for what Vega processes and why. Cloudflare, Inc. Edge compute, storage, hosting, CDN, DNS Runs the Vega Worker, stores published NAR artifacts in R2 object storage, hosts the documentation on Pages, and serves the cache and its DNS over Cloudflare's CDN. Processes request metadata and the continent-level geolocation Vega records (never a precise location or retained IP). United States; global edge network Fly.io, Inc. Reproduction-worker microVMs Runs Vega-operated reproduction workers: ephemeral, per-job microVMs that rebuild public source from scratch to verify a build. These machines hold no Vega credential and process only public source and build outputs, not user data. United States; Europe; Asia GitHub, Inc. (Microsoft Corporation) Identity, commit checks, eligibility Verifies builder identity through GitHub Actions OIDC, hosts the Vega GitHub App that posts commit checks, and provides the API Vega queries to check an attester's account age for eligibility. Processes your numeric GitHub user id, login, and build provenance (repository, commit, workflow run). OIDC tokens are verified and not stored. United States Upstream dependency (no data shared) Vega fetches public build dependencies from cache.nixos.org, the upstream Nix binary cache operated by the NixOS Foundation. Vega sends it no user data; it is listed here for completeness, not as a subprocessor. Changes When Vega adds or replaces a subprocessor, this page is updated before the change takes effect for new data. Contact Privacy questions: security@adastracomputing.com."},{"sha":"f2cc3d7","date":"2026-07-21","label":"The mailbox that ships stickers","note":"Adding the free sticker put a name and a postal address through two processors that were not listed. Zoho hosts the mailbox that receives the shipping details, and Cloudflare's entry now says it stores the request and routes that mail. Nothing else about Vega sends data to either.","text":" Vega Cache is operated by Ad Astra Computing Inc. The third parties below process data on Vega's behalf. We keep this list current; a material change is reflected here. See the Privacy Policy for what Vega processes and why. Cloudflare, Inc. Edge compute, storage, hosting, CDN, DNS Runs the Vega Worker, stores published NAR artifacts in R2 object storage, hosts the documentation on Pages, and serves the cache and its DNS over Cloudflare's CDN. Processes request metadata and the continent-level geolocation Vega records (never a precise location or retained IP). For the free-sticker feature it also stores sticker requests and routes the operator notification email. United States; global edge network Zoho Corporation Operator mailbox (sticker fulfilment) Hosts the Ad Astra operator mailbox that receives a notification, including the name and shipping address you enter, when you request a free sticker at /stickers, so the operator can mail it. Processes sticker shipping details only; no other Vega data flows through it. United States Fly.io, Inc. Reproduction-worker microVMs Runs Vega-operated reproduction workers: ephemeral, per-job microVMs that rebuild public source from scratch to verify a build. These machines hold no Vega credential and process only public source and build outputs, not user data. United States; Europe; Asia GitHub, Inc. (Microsoft Corporation) Identity, commit checks, eligibility Verifies builder identity through GitHub Actions OIDC, hosts the Vega GitHub App that posts commit checks, and provides the API Vega queries to check an attester's account age for eligibility. Processes your numeric GitHub user id, login, and build provenance (repository, commit, workflow run). OIDC tokens are verified and not stored. United States Upstream dependency (no data shared) Vega fetches public build dependencies from cache.nixos.org, the upstream Nix binary cache operated by the NixOS Foundation. Vega sends it no user data; it is listed here for completeness, not as a subprocessor. Changes When Vega adds or replaces a subprocessor, this page is updated before the change takes effect for new data. Contact Privacy questions: security@adastracomputing.com."},{"sha":"1789223","date":"2026-09-08","label":"Cloudflare counts page views","note":"Cloudflare was already listed for compute, storage and DNS. Its entry now also names the page-view counting it does for this website, so the processor doing the measuring is on the page rather than implied by it.","text":" Vega Cache is operated by Ad Astra Computing Inc. The third parties below process data on Vega's behalf. We keep this list current; a material change is reflected here. See the Privacy Policy for what Vega processes and why. Cloudflare, Inc. Edge compute, storage, hosting, CDN, DNS, website analytics Runs the Vega Worker, stores published NAR artifacts in R2 object storage, hosts the documentation on Pages, and serves the cache and its DNS over Cloudflare's CDN. Processes request metadata and the continent-level geolocation Vega records (never a precise location or retained IP). For the free-sticker feature it also stores sticker requests and routes the operator notification email. Counts page views on this website with its cookieless Web Analytics. United States; global edge network Zoho Corporation Operator mailbox (sticker fulfilment) Hosts the Ad Astra operator mailbox that receives a notification, including the name and shipping address you enter, when you request a free sticker at /stickers, so the operator can mail it. Processes sticker shipping details only; no other Vega data flows through it. United States Fly.io, Inc. Reproduction-worker microVMs Runs Vega-operated reproduction workers: ephemeral, per-job microVMs that rebuild public source from scratch to verify a build. These machines hold no Vega credential and process only public source and build outputs, not user data. United States; Europe; Asia GitHub, Inc. (Microsoft Corporation) Identity, commit checks, eligibility Verifies builder identity through GitHub Actions OIDC, hosts the Vega GitHub App that posts commit checks, and provides the API Vega queries to check an attester's account age for eligibility. Processes your numeric GitHub user id, login, and build provenance (repository, commit, workflow run). OIDC tokens are verified and not stored. United States Upstream dependency (no data shared) Vega fetches public build dependencies from cache.nixos.org, the upstream Nix binary cache operated by the NixOS Foundation. Vega sends it no user data; it is listed here for completeness, not as a subprocessor. Changes When Vega adds or replaces a subprocessor, this page is updated before the change takes effect for new data. Contact Privacy questions: security@adastracomputing.com."}]}