Legal center
Privacy Policy
Policies for SecureRepos accounts, GitHub App access, billing, repository scanning, privacy, and support.
1. Overview
This Privacy Policy explains how Secure Repos and SecureRepos collect, use, disclose, and protect information when you visit the website, create an account, connect GitHub repositories, use scans, contact support, or interact with our services.
2. Information We Collect
We may collect account information such as name, email address, password hash, notification preferences, support messages, billing status, and plan information.
We may also collect technical and product information such as IP address, browser, device data, login sessions, audit logs, page activity, repository IDs, repository names, default branches, GitHub App installation metadata, scan status, findings, and error logs.
3. Repository Data
Repository access is used to run security checks, create findings, track repository health, and support workflow features. Depending on the scan, SecureRepos may process repository file paths, selected file contents, configuration files, dependency files, workflow files, and detected patterns. Temporary scanner workspaces are intended to be removed after scan output is parsed; finding metadata and scan history remain stored for your account.
We do not sell repository code. You control repository access through the GitHub App installation and should limit access to repositories you want monitored.
4. How We Use Information
We use information to create and operate accounts, authenticate users, connect GitHub, run scans, generate findings, send emails and in-app notifications, enforce plan limits, improve reliability, prevent abuse, investigate errors, respond to support requests, process billing status, and comply with legal obligations.
5. Service Providers
We may use trusted providers for hosting, databases, infrastructure, email delivery, analytics, logging, security monitoring, payment processing, fraud prevention, and customer support. These providers process information only as needed to provide services to us.
For dependency vulnerability checks, package names, exact versions, ecosystems, and dependency file paths may be sent to a vulnerability intelligence provider. Repository source code and dependency file contents are not sent for this lookup.
6. Cookies and Analytics
We use cookies and similar technologies for login sessions, security, preferences, product analytics, fraud prevention, and performance measurement. You can control cookies through browser settings, but some features may not work correctly if required cookies are blocked.
7. Data Retention
We retain information while your account is active and as needed for security, audit, legal, billing, dispute, tax, backup, and operational purposes. Some records may be retained after cancellation where required for compliance, fraud prevention, dispute handling, or legitimate business records.
8. Your Rights
Depending on your location, you may request access, correction, deletion, portability, restriction, or opt-out of certain processing. We may verify your identity before processing a request.
9. Security
We use reasonable operational, technical, and organizational safeguards designed to protect information. No online service is completely secure, and you are responsible for managing GitHub permissions and account access carefully.
10. International Processing
Your information may be processed in countries where we or our service providers operate. By using the service, you understand that information may be transferred and processed outside your country of residence where permitted by law.
11. Contact
For privacy requests, contact [email protected].