VIRCAAgenticOps
The problemWhat it fixesHow it worksWhy nowHow we comparePlatformFAQ
Sign inInstall the Agent
HomeThe problemWhat it fixesHow it worksWhy nowHow we comparePlatformFAQSign in

Legal

Privacy Policy

Last updated 7 September 2026 · Whatap Global Inc., 8 The Green, Ste A, Dover, DE 19901, USA · ask@virca.ai

1. What this policy covers2. What we collect3. Why we use it4. Who else touches it5. Where it is kept, and how it is protected6. Cookies and analytics7. How long we keep it8. Your choices9. Changes, governing law, contact

1. What this policy covers

This policy explains what Virca collects, why, and what you can ask us to do about it. It covers the Virca website at virca.ai, which anyone can browse, and the Early Access program, in which a team creates an account and installs the Virca Agent on its own hosts.

Virca is in early access. It is not generally available, and there is no charge for it today. If that changes, we will say so before it does.

2. What we collect

When you browse the website. Standard web and analytics data: pages viewed, links followed, approximate location derived from IP address, browser and device type, and the time of your visit. We collect this through Google Analytics 4 — see section 6.

When you contact us. Whatever you send — your name, your email address, your company, and the content of your message.

When you join Early Access. The name and work email address of the people on your account, your organization name, and the domain you sign up with. We do not take payment details, because there is nothing to pay.

When you install the Agent. The Agent runs on hosts you control and sends Virca operational data about those hosts — resource metrics, process and service state, log lines and configuration relevant to the checks you set up, and, when a condition you configured is detected, additional diagnostic detail about that condition. It also sends a record of every action it ran: what triggered it, what ran, on which host, and what happened afterwards.

One thing to know about that. Process command lines, file paths and network connection details can contain whatever your own systems put there. If a secret or a personal identifier is passed as a command-line argument on a monitored host, it can end up in what the Agent collects. Please do not put secrets in command-line arguments on hosts you connect.

What we do not collect. We do not ask for payment card details. We do not collect data from anyone under 18, and the Service is not directed at them. We do not run advertising trackers.

3. Why we use it

To run the Service — to raise events, to run the actions you approved, to keep the record of what was done, and to show that record to you. To operate and improve the site and the product — to see which pages are read, to find broken things, and to decide what to build. To talk to you — to answer what you send us, to send service and security notices, and, if you asked for them or are an Early Access participant, to send product updates. You can opt out of product updates at any time; service and security notices are not optional while your account exists. To meet legal obligations and to protect our rights and yours.

AI model training. We do not use your operational data, your action set, or the record of what ran to train general-purpose AI models made available to anyone else. AI processing on your data is done to produce a result for you.

Aggregated data. We may derive statistics from data across all customers, aggregated and de-identified so that no customer, person or host can reasonably be identified, and use those for product work. We do not attempt to re-identify that data.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are used in California law.

4. Who else touches it

We use a small number of service providers, and they are bound to protect your data.

Amazon Web Services, Inc. — cloud infrastructure, where the Service runs and where data is stored.

Google LLC — Google Analytics 4, website and product analytics.

Ollama Inc. — AI inference; the model that drafts and answers runs on their service.

To be clear about the AI provider. AI processing in Virca runs on a third-party inference service, named above. It is not run entirely on infrastructure we own. What reaches it is what the feature you used needs in order to answer.

We will also disclose data where the law requires it, and, if Virca is ever acquired or merged, to the acquiring party under the same protections described here — we will tell you if that happens.

5. Where it is kept, and how it is protected

Virca runs in the United States, on Amazon Web Services, and data is stored in AWS US regions. The Service is offered to organizations in the United States; if you access it from elsewhere, your data is transferred to and processed in the United States.

We apply access controls to our own systems and restrict who can reach customer data. Credentials the Agent uses to run commands on your hosts stay on your hosts — they are not stored on Virca's servers. The Agent opens a single outbound connection to Virca and authenticates it with a key derived from your workspace; nothing listens for inbound traffic on your side.

No security measure is perfect. We do not promise the Service will be free from unauthorized access or disruption, and we do not want you to rely on such a promise. The security of your own hosts, networks and credentials remains yours. If we discover a security incident affecting your data, we will tell you without undue delay, describe what we know, and cooperate with what you have to do about it.

6. Cookies and analytics

The website uses Google Analytics 4 to understand how the site is used — which pages are read, which links are followed, and where visitors arrive from. That is the only analytics tool on the site, and it sets cookies in your browser. We do not serve advertising cookies and we do not share site data with ad networks.

You can opt out using your browser's cookie controls, or by installing Google's own opt-out browser add-on. You can also write to ask@virca.ai and we will exclude you.

7. How long we keep it

We keep data for as long as we need it for the purpose we collected it, and no longer. In practice: website analytics for as long as it is useful for understanding traffic, and then it ages out; what you send us for as long as the conversation is live, and afterwards for our own records; your account and the data from your hosts for as long as your Early Access account is open; and anything the law requires us to keep, for as long as it requires.

We are deliberately not publishing a fixed retention schedule while the Service is in early access, because we would rather tell you the truth about how long data lives than publish a number we cannot yet guarantee. You can ask us to delete your data at any time — see section 8 — and we will, except where the law requires us to keep it.

8. Your choices

You can ask us to tell you what personal information we hold about you; correct it if it is wrong; delete it; send you a copy in a portable form; stop or limit certain uses of it; or stop sending you marketing email — every marketing email also carries an unsubscribe link.

If you are in California, you also have the right to know what we collect and how it is used, to opt out of any sale or sharing of personal information (we do neither), to limit the use of sensitive personal information where it applies, and not to be treated differently for exercising any of these rights.

How to ask: write to ask@virca.ai. We will verify who you are before acting on a request about someone's personal information, and we will respond within the time applicable law requires.

9. Changes, governing law, contact

We may update this policy. If a change materially affects how we handle your data, we will post the updated policy here and, where required, tell you before it takes effect. The date above always says when it last changed.

This policy is governed by the laws of the State of California, United States, without regard to its conflict-of-law principles. Disputes are handled as described in the Virca Terms of Use. Questions: ask@virca.ai.

Also here

Terms of Use →Early Access Terms →Disclaimer →

VIRCAAgenticOps

AgenticOps — your engineer knows it, AI writes it, your team approves it, the agent takes the night.

Why it matters

The problemWhat it fixesWhy nowHow we compare

How it works

How it works1 · Validate2 · Investigate3 · Act4 · ConfirmBuilding an ActionBookWhat observing is forWho the alert is for

Under the hood

PlatformThe boundaryConversation & MCP

More

FAQContact — ask@virca.ai

Legal

Privacy PolicyTerms of UseEarly Access TermsDisclaimer
Copyright © Whatap Global Inc. All rights reserved.