Privacy Policy
Last updated July 15, 2026
Plain-language summary (the full policy below governs): We collect your email and account details, payment records (Stripe handles the card), and, briefly, the code you submit. Your code is analyzed in an isolated environment, never executed, and deleted when the scan completes. Your report, including short code snippets that evidence each finding, is kept so you can access it. We use PostHog to understand how the product is used, and, only with your consent, advertising tags to measure whether our ads work. We never sell your data, and nothing beyond the scan itself ever touches your code. You have the full set of GDPR rights.
1. Who is responsible
The data controller is Adventure Software SRL, ("Ascertify", "we"). Contact for privacy matters: vali@ascertify.io.
2. What we collect, why, and on what legal basis
| Data | Source | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Account data: email, name (optional), password hash or OAuth identity | You | Creating and securing your account; service emails | Contract (6(1)(b)) |
| Payment data: transaction amount, date, status, last-4 and card brand (held by Stripe; we never receive the full card number) | You, via Stripe | Processing payment, invoicing, refunds, fraud prevention | Contract (6(1)(b)); legal obligation (6(1)(c)) for accounting records |
| Submitted code (repository contents or uploaded archive) | You / your GitHub account | Performing the scan you requested | Contract (6(1)(b)) |
| Report data: findings, severities, file/line references, short code snippets evidencing each finding | Generated by us | Delivering the report you purchased and keeping it accessible to you | Contract (6(1)(b)) |
| GitHub integration data: installation ID, repository names, commit metadata | GitHub, with your authorization | Fetching code read-only; the commit-history checks you requested | Contract (6(1)(b)) |
| Technical logs: IP address, browser data, timestamps, scan job status | Automatic | Security, abuse prevention, debugging | Legitimate interest (6(1)(f)): running the service safely |
| Product analytics: page views, feature usage, device/browser type, approximate location (country), collected via PostHog | Automatic | Understanding how the product is used and improving it | Legitimate interest (6(1)(f)) where collected without cookies/identifiers; consent (6(1)(a)) for identified tracking |
| Advertising measurement: conversion events shared with ad platforms via their tags/pixels | Automatic, with your consent | Measuring whether our advertising works | Consent (6(1)(a)): via the cookie banner; you can decline or withdraw at any time |
| Support correspondence | You | Answering you | Contract / legitimate interest |
We do not sell your personal data. We never use the code you submit for advertising, analytics, or any purpose other than producing your report. Advertising-related processing, where present, applies only to website visit and conversion data, never to your code or your reports, and only with your consent.
3. Your code, specifically
- Submitted code is transferred into an isolated, access-restricted processing environment.
- It is analyzed statically, never executed, built, or installed.
- It is deleted immediately after the scan completes or failsin any case within 1 day.
- What survives deletion is the report: findings plus the short snippets of code that evidence them. Snippets are excerpts, not the codebase.
- Code you submit may include personal data belonging to third parties (e.g., in comments, seeds, or fixtures). You are responsible for being entitled to submit it (see Terms, Section 4). We process such content only as needed to perform the scan and delete it on the schedule above.
4. Processors and recipients
We share data only with processors who help us run the service, under data processing agreements:
| Recipient | Role | Data |
|---|---|---|
| Stripe | Payments | Payment and billing data |
| GitHub (Microsoft) | Code source, when you connect a repo | Repository access via the permissions you grant |
| Anthropic | AI processing: turning structured findings into plain-language explanations | Structured findings and short code excerpts, never your full codebase; contractually not used for model training |
| Supabase | Hosting, database, storage of uploads and reports | Account, report, and job data; uploaded archives pending scan |
| Brevo | Transactional email | Email address, report links |
| PostHog | Product analytics | Usage events, device/browser data |
| Google (Google Ads) | Advertising measurement; acts partly as an independent controller for its own purposes | Conversion events, ad-click identifiers, with your consent |
Where recipients are outside the EU/EEA, transfers rely on the EU–US Data Privacy Framework or Standard Contractual Clauses, as noted. We will disclose data if required by law, and will tell you unless prohibited.
5. Retention
| Data | Kept for |
|---|---|
| Submitted code | Deleted at scan completion/failure, max 1 hour. |
| Reports (incl. snippets) | Until you delete them or your account |
| Account data | Until account deletion, then removed within 30 days |
| Payment/accounting records | 10 years, as required by accounting law |
| Technical logs | 30 days |
| Analytics data (PostHog) | 12months, then deleted or aggregated |
| Advertising consent records & conversion events | Consent records: 24 months; event data per Google/Meta retention, which we cap where their tools allow |
6. Your rights (GDPR)
You have the right to access, rectify, and erase your data; to restrict or object to processing; to data portability; and to withdraw consent where processing is based on consent. Exercise them at vali@ascertify.io; we respond within one month. You also have the right to lodge a complaint with a supervisory authority; ours is Romania's ANSPDCP (dataprotection.ro), but you may complain to the authority in your own country.
7. Security
Scans run in isolated, network-restricted environments; access to production data is limited and logged; data in transit is encrypted (TLS) and at rest. No system is perfectly secure; if a breach affects your data, we will notify you and the supervisory authority as required by Art. 33–34 GDPR.
8. Cookies and similar technologies
We use three categories:
- Essential (always on): session and authentication cookies required for the service to function. No consent needed.
- Analytics: PostHog usage measurement.
We do not use cross-site tracking beyond the marketing tags described above, and none of these technologies ever touch the code you submit.
9. Children
The service is not directed at anyone under 18 and we do not knowingly collect their data.
10. Changes
We will post updates here and, for material changes, notify you by email or in-product. The "last updated" date at the top reflects the current version.
11. Contact
Adventure Software · vali@ascertify.io