Privacy Policy

Last updated: June 2026 · SecurePR is GDPR-compliant

What we collect

DataWhyRetention
Email addressAccount, notificationsUntil deletion
Organisation nameAPI key scopingUntil deletion
Repository metadataScan targeting90 days
Security findingsDashboard, history90 days
API usage metricsRate limiting, billing90 days

What we do not collect

We do not store your source code. Repositories are cloned into ephemeral containers, scanned, and the clone is deleted immediately. We do not use your code to train AI models.

Third-party processors

Your GDPR rights

As an EU/UK resident you have the right to access, rectify, port, or erase your data. To exercise any right, email privacy@securepr.dev. We respond within 30 days.

Cookies

We do not use tracking cookies. The API uses stateless JWT-style API keys for authentication.

Security

API keys are stored hashed. Scan findings are stored in a private PostgreSQL instance. All traffic is encrypted in transit via TLS 1.3.

Contact

Privacy enquiries: privacy@securepr.dev