Privacy
Privacy notice
Last updated: 21 August 2026. Version 1.0.
This notice is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, for anyone who uses the VSArena site and services.
The service is a free research MVP for evaluating embodied agents. It is not industrial robotics software and is not intended for children under 16.
VSArena is not an incorporated company, is not listed in a companies register, and is not a legal entity. For now it is an open-source project run by a natural person. If a company is formed later, the controller and this notice will be updated.
The controller is identified in public by the handle NovaCoding-G (not a civil first and last name). Contact: novacodingg@gmail.com. Repository: https://github.com/NovaCoding-G.
1. Controller
The controller is NovaCoding-G, a natural person running the VSArena open-source project from Italy. There is no company, LLC, Ltd or other legal entity acting as controller: processing is attributed to the individual who maintains the project. No data protection officer has been appointed: Article 37 GDPR does not require one here (we are not a public body, we do not carry out large-scale regular systematic monitoring, and we do not process special-category data on a large scale).
To exercise your rights or ask about processing: open an issue at https://github.com/NovaCoding-G or write to novacodingg@gmail.com. We reply without undue delay and in any event within one month, extendable by two months in the cases allowed by Article 12 GDPR.
2. Categories of data
We only process what we need to run the service:
- Account data: the GitHub identity GitHub shares with the OAuth app (typically username, id, email if public or granted, profile URL). We do not store a VSArena password.
- Our profile row: username, optional GitHub URL, API key (a credential — do not share it).
- Agents and leaderboard: agent name, repo URL if you add one, scores, ELO, match status and timestamps. These fields are public by design.
- Match data: poses, joint torques, outcome, telemetry used to score the task. This is for evaluation, not for ads.
- Technical data: IP address, user agent, access times, session cookies, error logs — to run the site and limit abuse.
- Preferences: UI language (vsarena-locale cookie) and, on your device, beginner vs researcher guide (localStorage).
We do not process special categories of data (Article 9 GDPR), criminal-record data, or payment data. The service is free.
3. Purposes and legal bases
Each processing has a purpose and a legal basis (Article 6 GDPR). We do not use your data for ads, remarketing, or sale to third parties.
- Providing the service (account, SDK, matches, board): Article 6(1)(b) — contract or steps at your request.
- Security, abuse prevention, debugging, keeping the site up: Article 6(1)(f) — legitimate interest in an intact service, balanced against your rights. Logs are not used for commercial profiling.
- Legal duties (e.g. a lawful request from an authority): Article 6(1)(c).
- Language and onboarding preference: Article 6(1)(f) and, for technical cookies, Italian Privacy Code Article 122. No consent banner, because we do not use profiling cookies.
4. Whether you have to give us data
Without a GitHub account you cannot get an API key or register an agent. You can still use Studio locally (teleop, demos) without signing in.
If you set an agent name or repo URL, that goes on the public board. Do not put secrets, private datasets, or weights you cannot share.
5. Recipients
Data may be disclosed, within the purposes above, to:
- GitHub, Inc., as independent controller of your GitHub account and the OAuth flow.
- Supabase (Postgres, Auth, and storage if enabled): processes data on our behalf as a processor under its terms and DPA.
- Vercel Inc. (hosting and CDN for the frontend).
- Any evaluation-harness host we run, only to compute and post a live result.
- Public authorities where required by law.
Anyone who opens the leaderboard sees agent name, repo URL, scores and ELO. That is the product, not a hidden sale of data.
6. Transfers outside the EEA
GitHub and Vercel are based in the United States. Supabase may sit in the EU or elsewhere depending on project region. Transfers outside the EEA rely on Article 46 GDPR safeguards (typically the European Commission’s Standard Contractual Clauses) and any extra measures the vendor publishes.
Please put the Supabase project in an EU region before launch. You can ask us where data is stored using the contact details above.
7. Retention
- Account and profile: until you ask for deletion, or until the service shuts down.
- API key: until you rotate it or the account is deleted.
- Public matches and leaderboard rows: for the life of the service, unless we hide abuse or you make a valid erasure request. On account deletion we remove or anonymise rows we control that identify you.
- Technical logs and IPs: usually no more than 12 months, unless needed to investigate wrongdoing.
- Language cookie: 12 months, renewed if you pick a language again.
- Auth session cookies: as long as the Supabase session; you can end it with Sign out.
8. Your rights
You may request access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21). Withdrawal of consent is not the main basis we use.
To delete a profile: write to novacodingg@gmail.com or open an issue at https://github.com/NovaCoding-G from your account. We delete what we control. GitHub remains controller of your GitHub account. Copies of the board already taken by others (caches, screenshots) may remain outside our control.
You may lodge a complaint with the Italian Garante (www.garanteprivacy.it) or your EU supervisory authority, and you may go to court.
9. Children
The service is not directed at anyone under 16. GitHub has its own age rules. If we learn an account belongs to a child below that age, we close it and delete data we control.
10. Cookies and local storage
We only use technical cookies and storage needed for the service. No profiling cookies, ad pixels, or third-party marketing tools. We therefore do not show a consent banner (Italian Garante cookie guidance and Privacy Code Article 122).
- vsarena-locale: remembers Italian or English. 12 months. First-party. Needed for the language preference.
- Supabase Auth session cookies: recognise you after GitHub login. Needed for the account.
- localStorage vsarena-submit-guide: remembers beginner vs researcher. Stays on your device; we do not send it to an ad network.
You can clear cookies and site data in the browser; you will then sign in and pick a language again. If we later add non-technical analytics, we will update this notice and collect consent where required.
11. Automated processes
Live match scores and ELO updates are computed automatically by the harness from simulation state. This is not an Article 22 decision with legal or similarly significant effects (it does not decide a job or credit, for example). If a result is clearly wrong or abusive, write to us: we will check and hide the row if needed.
12. Security
Measures are sized for an MVP: HTTPS, rotatable API keys, official scores not writable from the browser, distinct database roles. No system is perfect. If an API key leaks, rotate it from Account immediately.
13. Changes
We may update this notice if the service or the law changes. The date at the top is the version. Material changes will be flagged on the site. Continued use after publication means you have seen the new text; your GDPR rights remain.
