| Data | Why | Legal basis |
|---|---|---|
| Telegram user id & username | Identify your account, deliver alerts | Contract |
| Watch keywords / stack, filters | Match relevant CVEs | Contract |
| Domains / assets & ownership proof / authorisation attestations | Perform authorised assessments; legal audit trail | Contract; legal obligation / legitimate interest |
| Scan & dependency results, reports | Provide the Service, history, drift | Contract |
| Repository URL and a read-only access token (encrypted at rest) | Read dependency manifests for version-precise matching | Contract |
| Terms acceptance (version, timestamp) | Prove consent | Legal obligation / legitimate interest |
| Payment reference | Manage subscription (handled by the payment provider) | Contract |
We do not collect your source code. Only dependency manifest metadata (package names and versions) is read from connected repositories.
To provide and secure the Service, deliver alerts and reports, prevent abuse, comply with law, and improve the product. We do not sell personal data.
Access tokens are encrypted at rest; transport is over TLS; access is restricted. Tokens are read-only and never used to write to your repositories.
We keep data while your account is active and as needed for the purposes above. You can delete assets, repositories and tokens at any time in the app. To delete your account and associated data, contact [privacy email]; we retain minimal records (e.g. Terms-acceptance and authorisation logs) where required to establish legal compliance.
You may access, rectify, erase, restrict or port your data, and object to processing. Contact [privacy email]. You may lodge a complaint with the Spanish Data Protection Agency (AEPD) or your local authority.
Where data is processed outside the EEA (e.g. by a sub-processor), we rely on appropriate safeguards such as Standard Contractual Clauses.
We may update this Policy; the version/date appear above. Questions: [privacy email].