Viruxa Studio

Privacy

Last changed 29 September 2026 · applies to Viruxa Studio 0.9.35 and later

This describes what the software does, not what a lawyer would like it to say. Everything below can be checked against the program you are running: each claim names the flag that causes it and the host it talks to, and a scan tells you at the top which of them are switched on.

The short version

Your code stays on your machine. Scanning happens locally, and the scanner works with the network unplugged. You never need an account: signing in with Google is optional, only keeps a copy of your plans so a reinstall gets them back, and never sees your code.

There is no telemetry. No analytics, no usage counting, no crash reporting, no "anonymous statistics". We do not know how many people run this, how often, or on what. That is not a setting you can turn off, because it was never written.

Two things leave by default, and everything else only when you ask. A scan asks public advisory databases about the packages you have installed, and the desktop app asks our download host whether there is a newer release. Both are listed below with exactly what goes, along with each thing you can switch on. One of those sends parts of your code, is off unless you ask for it, and says so on screen before it runs.

What leaves, and when

What When What is sent
Vulnerable dependencies On by default. --offline stops it. The name, ecosystem and version of each installed package, to api.osv.dev. Nothing else — not the path the lockfile was found at, not the project name, not a line of code. The same names and versions go to api.deps.dev, which says whether a package has been deprecated and what licence it carries. The list of vulnerabilities being exploited right now is downloaded from cisa.gov, sending nothing; and the CVE numbers of the advisories found go to api.first.org, which says how likely each is to be exploited.
Update check The desktop app, once, a few seconds after it opens. VIRUXA_NO_UPDATE_CHECK=1 stops it. A request for the signed release manifest from our download host, pub-87d2e02a43ee408286459f8387d56809.r2.dev, naming the version you run in its user agent (ViruxaStudio/ and the version number). Nothing about your code, your projects or your machine — only what any web request carries, which includes your IP address.
Sign-in Only if you sign in. Until you answer the app's sign-in prompt, it also asks viruxacloud.pages.dev/api/health, once per launch, whether sign-in is available. Signing in happens in your browser, with Google, who tell us your email address and name — never your password or anything else in your Google account. Signed in, the app asks viruxacloud.pages.dev for the licences kept under your address when it opens, and sends the licence it holds so it is kept there too. Nothing about your code, projects or scans.
Credential checks Only with --verify. A credential the scan found, sent to the vendor it belongs to and nobody else, to ask whether it still works. A GitHub token goes to GitHub; a Stripe key goes to Stripe. Never in a URL, always over HTTPS, and a redirect is refused rather than followed.
Container images Only with --layers. A request to the registry your Dockerfile already names, for the image it already names, to read the package list inside it. Six public registries are allowed; a private one is reported as not-checked rather than reached for.
Cloud accounts Only with --cloud. Read-only calls to your own AWS, Azure, GCP or other account, using credentials already on your machine. Those calls go to your provider. They do not come to us.
Alerts Only once you add a channel, under Settings → Alerts or with viruxa alerts. When an attack is detected or refused: the rule, how many times, the address it came from and when — to the webhook, mail relay or WhatsApp number you configured. Never the request itself, because an attacker's payload is where a captured credential would be.
Repository settings Only with --repo. Questions about the repository's own settings — branch protection, what a workflow may do — to api.github.com, with the token you give it.
Repositories and fixes Only with viruxa repo or viruxa fix --pr. A clone from the host you name, deleted when the scan ends; and, when you ask for one, a pull request carrying the fixes, opened on that repository with your own credentials.
A server, over SSH Only with viruxa ssh, or A server in the window. Nothing is sent to anybody but your own server, over the SSH your machine already uses, signed in with your key or agent — never a password. The folder you name is copied here, scanned, and the copy deleted when the scan ends; nothing is installed or written on the server. To suggest servers, the window reads the Host names in your own ~/.ssh/config on this machine; they are not sent anywhere.
Buying a licence Only when you press Buy, in the app or on this site. The app makes a random purchase code and sends it to this site's own address to ask whether it has been paid — nothing else about you or your machine. The name you want on the licence and the email for the receipt go to Razorpay, which takes the payment; this site asks Razorpay whether that code was paid and, when it was, signs the licence. Nothing is stored here: Razorpay's record is the only one.
Sending a scan Only when you choose Send, and pick where. The report — each finding's title, place and one line of evidence, and the report file by email — to the address, Slack, Discord, Teams or WhatsApp channel you configured under Alerts, or to your own Viruxa server. Never a source file.
Other programs (API and MCP) Only with viruxa api or viruxa mcp, or once switched on under Settings → API & MCP. Nothing leaves this machine. The server listens on 127.0.0.1 only, refuses any request without the key, and refuses requests from web pages. What it answers goes to the program you connected — so if that program is an AI application that uses a hosted model, what it reads from Viruxa is sent on to that model by that application, under its own terms.

The one that sends your code

The second reader asks a language model to read up to forty source files a scan — the ones with findings first, then the ones handling requests, then the rest. From the command line it is --review; in the window it is Settings → Second reader. Set to the Anthropic API, the contents of those files are sent to api.anthropic.com. Set to Any API — OpenAI, Google Gemini, Mistral, Groq, OpenRouter, DeepSeek, xAI, or an address you type — they are sent to that service's address, which the line printed before the review names.

It is off unless you switch it on, --offline overrides it, and before it runs the command line prints a line saying how many files are about to be sent and where; the window says the same beside the switch. The API key you give the window is kept encrypted by the operating system — DPAPI on Windows, the keychain on macOS — and never shown again. Pointed at a model running on your own machine instead, nothing leaves.

If you connect a cloud account

--push sends finished scans to a server you have configured with viruxa connect — one you run, or one we host if you have asked us to. It is off unless you set it up.

Be clear about what a finding contains: the rule, the severity, the file path, the line number, and up to 200 characters of the matching line. That last part is a fragment of your code. It is there because a dashboard listing findings with no evidence is a dashboard nobody can act on — but it is a fragment of your code leaving your machine, and a page that told you otherwise would be lying to you.

The scan also sends your machine's hostname and the project name, so the dashboard can tell two machines apart.

Licences

A licence key is an Ed25519 signature checked on your own machine. Installing one, and every check afterwards, contacts nobody. It works on a disconnected network, and we cannot see when, where or whether you are using it.

That is not a convenience. A tool that would not read your code until it had phoned a licence server would have broken the promise at the top of this page before it started — and it would break it for exactly the people who most need the promise kept.

When you buy, the payment is handled by Razorpay, who receive your payment details; we never see a card number. The name and email you give at checkout are kept with Razorpay's record of the payment, because a licence is issued to a name and a receipt is sent to an address, and we need those to reissue a key you have lost.

Buying from the app sends the licence you already hold, if you have one, to viruxacloud.pages.dev along with the purchase, so the days left on it can be carried into the new one. The site checks it and keeps nothing.

If you sign in (optional), we keep your email address, the name Google gives us, and the licence keys issued to that address — the last twenty — so signing in on another computer, or after a reinstall, brings your plan back. They are stored with Cloudflare, who host this site, under a one-way hash of your address. Every licence we issue is also filed under the email on its receipt, so a plan bought before you signed in is found when that address signs in. Signing out removes the sign-in from your computer; to have your account deleted, write to [email protected].

What is kept on your machine

Deleting the .viruxa directory removes all of it. The desktop app has a way to forget its tabs, because somebody who scanned a client's repository on a shared machine should be able to remove the record of having done it.

Children

This is a developer tool and is not directed at children. We do not knowingly collect anything from anybody under 16 — which is easier to promise than usual, because we do not knowingly collect anything from anybody.

Changes

If this page changes, the date at the top changes with it, and the version it applies to is named beside it. A change that makes the software send something it did not send before will be described here in the same terms as the rest — the flag that causes it and the host it goes to.

Contact

[email protected] — for anything here, including a request to delete what we hold. Viruxa Studio is a product of Brainybolt, India.