Privacy Policy

LAST UPDATED 2026-08-08

Draft. Not yet reviewed by counsel — see build spec §9 on the open GDPR erasure question for maintainer contact data.

§1What we collect

Site analytics

Aggregate, privacy-friendly traffic analytics via Plausible or Vercel Analytics (final vendor selection pending) — no cross-site tracking, no ad identifiers.

Maintainer contact information

Where publicly available (e.g. a repository's listed maintainer), used solely to notify you before we publish a finding about your server, per our disclosure policy.

Dispute and rescan submissions

The email and identity-verification details you provide when disputing a grade or requesting a re-scan.

§2What we don't do

We don't sell data, and we don't give paying customers earlier or fuller access to anyone's personal information than free users get.

§3How long we keep it

Site analytics are aggregate and not tied to an individual, so there's no per-user retention window to disclose. Maintainer contact information and dispute or rescan submission details are kept for as long as the associated listing is active, plus a reasonable window after a Legacy tag or dispute resolution to support any follow-up — see data deletion below to request removal sooner.

§4Data deletion

You can request deletion of contact information we hold about you as a maintainer. For EU-based requests specifically: whether an erasure request can be honored without impairing a documented security-research purpose is an open legal question we have not yet resolved with counsel — we are not asserting a blanket exemption. Contact us and we'll respond on a case-by-case basis while that gets settled.

A dedicated contact channel for privacy requests isn't live yet — this section will link directly to it once it ships.