Privacy
Privacy policy
What we collect when you use ossscanner.org, why, and how long we keep it.
Last updated: October 9, 2026.
Scans
When you start a scan we store the repository URL, branch and commit, the report and a salted hash of your IP address for rate limiting. We don't store your IP address itself. The cloned source code is deleted when the scan ends; reports contain short snippets of the affected lines.
To analyse code we send selected source files from the public repository to Claude models through OpenRouter, which may route requests to Anthropic, Amazon Bedrock or Google Vertex AI. Only public code is processed.
Enrollment
If you enroll a project we store the email addresses you give us, the project details and threat model, and the history of scans. We use the emails only to send confirmation and scan reports. You can delete the project and its data at any time from your management link.
Analytics and cookies
We use Google Analytics 4 to understand how many people visit the site and which pages are useful. Google Analytics sets cookies and processes your IP address and browser data; see Google's privacy policy for details. We don't use advertising cookies. Report and management pages don't send repository names or finding details to analytics beyond the page address.
Retention
Quick scan reports are kept for 90 days. Rate-limit records are kept for a few days. Enrolled projects' data is kept until you delete the project.
Your rights
You can ask us to access, correct or delete your data by writing to hello@ossscanner.org. If you are in the EU or UK you also have the right to complain to your data protection authority.