Privacy Policy
Last updated: 22 July 2026
1. Information We Collect
1.1 Information You Provide
- Account information: Name, email address, and billing details when you create an account or subscribe.
- API keys: We generate and store API keys to authenticate your requests.
- Repository URLs: The GitHub repository URLs you submit for scanning.
1.2 Information Collected Automatically
- Usage data: Scan counts, API endpoint access patterns, and timestamps.
- Log data: IP address, browser type, operating system, and request metadata.
- Cookies: See our Cookie Policy for details.
2. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve the Service
- Process payments and manage subscriptions
- Enforce rate limits and prevent abuse
- Send service-related communications
- Comply with legal obligations
3. Data Sharing & Disclosure
We do not sell your personal information. We may share data with:
- Service providers: Third parties that help us operate the Service (e.g., payment processors, hosting providers)
- Legal requirements: When required by law or to protect our rights
- Business transfers: In connection with a merger, acquisition, or sale of assets
4. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Scan results are retained according to your plan's retention policy. You may request deletion of your data by contacting us.
5. Data Security
We implement industry-standard security measures, including encryption at rest and in transit, to protect your data. However, no method of transmission over the Internet is 100% secure.
6. Your Rights
Under the UK General Data Protection Regulation (UK GDPR), you have the following rights:
- Access, correct, or delete your personal data
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
7. Third-Party Services
The Service integrates with GitHub to scan repositories. GitHub's privacy policy governs how they handle data shared through their API. We also use Stripe for payment processing.
8. Children's Privacy
The Service is not intended for users under 13 years of age. We do not knowingly collect personal information from children.
9. International Data Transfers
Your information may be transferred to and processed in countries where we or our service providers operate. We take appropriate safeguards, including UK International Data Transfer Agreements (IDTA) where required, to ensure your data is protected in accordance with UK data protection law.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service.
11. Contact
For privacy-related inquiries, please contact us through our contact page.