Gitsentry.dev
GitHubPricingInstall AppSign in

Legal

Privacy Policy

Effective August 2026

Who we are

Gitsentry.dev is an AI-powered security scanner for GitHub repositories, built and operated as an open-source project. The scanning engine is MIT licensed and publicly auditable at github.com/d-beloved/gitsentry. The hosted dashboard at gitsentry.dev is proprietary.

Questions or requests: [email protected]

What we collect

From your GitHub account, when you sign in with OAuth:

  • ›Your GitHub user ID, login (username), email address, and avatar URL
  • ›The name and visibility (public or private) of repositories you grant us access to

From your code, at scan time. We read these through the GitHub API and hold them in memory for the length of the scan:

  • ›Pull request diffs: the lines your PR adds and removes, plus the unchanged lines around them that the scanner needs to judge whether a control is present
  • ›Security sweeps: a comparison of the last six commits on your default branch, when you start a sweep from the dashboard
  • ›Repo discovery: on a repository's first scan, and again when a diff touches an auth-related file or 90 days pass, we read the file tree, your auth-related source files, and your dependency manifests to work out how your app handles authentication. We also read .gitsentry/context.md if you have added one

What we keep after a scan finishes:

  • ›Security findings: vulnerability category, severity, file path, affected line, a short code snippet, and our plain-English description and fix suggestion
  • ›Scan metadata: commit SHA, branch name, author login, files changed, lines added, scan outcome, and AI token counts for billing
  • ›A written summary of your repository's auth patterns, stack, and key security helpers, derived during discovery and cached so later scans do not repeat the work
  • ›Which finding categories you have dismissed as false positives in a repository, and how often, so the scanner stops repeating them

We do not clone your repositories, store their full contents, or keep raw diffs and source files past the scan that read them.

How we use your data

  • ›To run security scans and display findings in your dashboard
  • ›To post findings as a comment on your pull request, and a check run on Pro
  • ›To send Slack or email alerts you configure in Settings
  • ›To track usage against your plan limits (scan counts per month)
  • ›To improve our AI detection model, see Training data below

We do not sell your data to third parties.

Training data

When you uninstall the GitHub App, we delete all of your identifiable operational data immediately: repository records, scan history, findings linked to your repos, and your installation record.

Before deletion, we archive a stripped, anonymized copy of your findings into a private training corpus used to improve our AI detection model. This copy contains only the structured signal vulnerability category, severity, plain-English description, and fix suggestion. We explicitly exclude:

  • ›Your repository name, organisation, or any GitHub identity
  • ›File paths and commit SHAs
  • ›Code snippets from your codebase
  • ›Author names and scan metadata

The retained language hint (e.g. ts, py) is derived from the file extension only, no path information is kept. If you object to this anonymized retention, contact us and we will remove it.

Third-party services

We use the following sub-processors:

  • ›Supabase, PostgreSQL database hosting (EU/US region)
  • ›Vercel, dashboard hosting
  • ›Render, backend webhook server hosting
  • ›Paddle, payment processing for Starter and Pro plans
  • ›Resend, delivery of the email alerts you turn on in Settings
  • ›Google Analytics, traffic measurement on our public pages
  • ›Third-party AI providers, security analysis. Your diffs and the source files described above are sent to the AI provider that runs our scans. We do not have a data-sharing agreement for model training in place with them.

Slack alerts go to the webhook URL you configure, so that data travels to your own workspace and nowhere else.

Cookies, analytics, and local storage

Three things are set in your browser:

  • ›A session cookie after you sign in with GitHub. It keeps you signed in and the dashboard does not work without it.
  • ›Google Analytics cookies on our public pages, which measure page views and referrers. They load on every visit; we do not run a consent banner today, so block them with your browser or an extension if you would rather not be counted.
  • ›A theme preference in local storage, which remembers whether you chose light or dark. It never leaves your browser.

We run no advertising trackers and no cross-site profiling.

Data retention and deletion

To delete your account: uninstall the Gitsentry.dev GitHub App from your account or organisation settings. This triggers immediate deletion of your repos, scans, findings, and installation record from our database. The anonymized training corpus entries (see above) are retained.

If you want your anonymized training data removed too, email [email protected] and we will purge it within 30 days.

Your rights

Depending on your jurisdiction (including GDPR for EU residents), you may have the right to access, correct, export, or erase your personal data. Contact us at [email protected] to exercise any of these rights. We will respond within 30 days.

Security

The Gitsentry.dev scanning engine is open source, anyone can audit exactly what runs on your code. We use HMAC-signed webhooks, Supabase Row Level Security, and short-lived GitHub installation tokens. If you discover a security issue in the service, email [email protected].

Changes to this policy

We may update this policy as the product evolves. Material changes will be announced via the dashboard or email. Continued use after the effective date constitutes acceptance of the updated policy.

Gitsentry.dev

Security scanning for the AI era.

Product

HomePricingStats

Legal

PrivacyTermsRefund

Connect

GitHub[email protected]

© 2026 Gitsentry.dev · a Charavol product

Payments processed by Paddle