Privacy
Privacy policy
What's collected, who else sees it, and why - see /security for the full trust and data-handling write-up.
What's collected
- From GitHub sign-in: your GitHub username, email address, and avatar URL - the minimum GitHub's OAuth flow provides.
- Scan reports: the score, findings, and summary for each scan you run, stored against your account so you can see your history. The cloned repo content itself is not retained - it's deleted once the scan finishes.
- Purchases: handled by Stripe - RepoSentry never sees or stores your card details. We keep a record of which credit pack you bought and when, not payment method data.
Where each piece of data actually lives, and how it's deleted
- The repo's file content: briefly written to a temporary directory on RepoSentry's server while the scan runs, and deleted the moment the report is finished - never written to the database at all.
- Your scan report (score, findings, summary) - kept in our Postgres database, encrypted at rest (AES-256-GCM). On the starter tier it's auto-deleted about an hour after the scan finishes; standard and pro keep it until you ask us to delete it.
- The downloaded PDF report: built entirely in your own browser from the report already on the page, then saved straight to your device - RepoSentry's server never generates, sees, or stores that file.
- Purchase history: which credit pack and when, kept even if you delete your account, for standard accounting/tax reasons.
Who else sees data, and why
- GitHub - for OAuth login, and to fetch the public repo you ask to scan.
- Anthropic - the flagged parts of a scanned repo are sent for the AI review step. Not your account details. Anthropic automatically deletes that content from its own systems within 30 days and never uses it to train its models - see Anthropic's own retention policy.
- Stripe - handles the actual payment; see Stripe's own privacy policy.
- Neon (Postgres hosting) - stores account and scan data on infrastructure we don't operate ourselves.
No data is sold, and there's no analytics/tracking SDK on this site beyond what's disclosed here.
Deleting your data
Reach out to request account and scan-history deletion. Purchase records may need to be retained separately for standard accounting/tax reasons.