When you use a free scan: your email address (if provided) and the public GitHub repository URL or ZIP file you submit for scanning.
When you purchase Launch Clearance ($149): your email address, the repository URL, payment details processed by Stripe (we never see or store your card number), and the generated security report.
When you contact us: your email address and message.
To scan your code, generate your report, deliver your signed badge, and process your payment. We use your email to send your report link and (if you leave feedback) to follow up. We do not sell your data.
Scan reports and order records are retained for 30 days in our edge storage. Payment records are retained by Stripe per their own policy. Lead/contact messages are retained for 45 days. Aggregate, anonymized scan counts may be retained indefinitely for social proof (e.g., "16 scans performed").
We do not run your code. We do not access your production environment. We do not sell or share your data with third parties except Stripe (for payment processing). We do not use your code to train models.
For public repositories, we clone the repository using standard anonymous git access. We do not require OAuth access for public repo scanning. Private repository scanning (via GitHub OAuth) is not yet available; when it launches, it will request read-only access to specific repositories you select, and the access token will be used once for cloning then discarded within 15 minutes.
You can request deletion of your data at any time by emailing the address below. EU/GDPR: you have the right to access, rectify, erase, restrict processing, and data portability.
Questions? Email peter@clira.dev.
← Back to Clira