Privacy Policy
Last updated July 18, 2026. This policy explains what [Legal Entity] ("Snytchr", "we", "us") collects when you use snytchr.com and our scanning services, why we collect it, and the choices you have. By using Snytchr you agree to this policy.
Information you give us
We collect the information needed to run your scans and manage your account:
- Account details — your email address, used to sign in (authentication is handled by Supabase) and to send you service messages.
- Scan inputs — the URLs you ask us to scan, and, for a Deep Scan, any test credentials you choose to provide so we can check the signed-in experience.
- Connected code — if you install the Snytchr GitHub App, the repositories you select and the source code we read during a scan or to prepare an Auto-Fix pull request.
- Payment details — handled by Stripe when you subscribe. We receive confirmation and subscription status; we never see or store your full card number.
- Communications — messages you send us for support.
Information we collect automatically
When you use the site we collect standard technical data such as your IP address, browser and device type, pages viewed, and timestamps. This is used to operate the service, keep it secure, and understand aggregate usage. Our hosting and infrastructure providers process this on our behalf.
How we use your information
We use your information to run and deliver your scans and reports, maintain your account and subscription, send transactional and lifecycle emails (such as scan results, payment notices, and monitoring updates), provide support, keep the service secure and prevent abuse, and comply with our legal obligations. We do not sell your personal information.
How we handle scan data
Scanning is designed to hold as little of your data as possible. When we read your repository source for a white-box Deep Scan or Auto-Fix, that source is used to run the scan and is deleted from our systems afterward; we retain the findings, not a copy of your codebase.
Test credentials you provide for an on-demand Deep Scan are used only to perform that scan session and are not stored for reuse. If you choose to schedule a Deep Scan to run automatically each week, we store those test credentials encrypted at rest (AES-256-GCM) so the scheduled scan can sign in; turning weekly scanning off for that target deletes the stored credentials. We keep the scan results — findings, scores, and reports — associated with your account so you can revisit them, prove fixes, and track changes over time.
Service providers and sub-processors
We rely on a small set of trusted providers to run Snytchr. They process data only to provide their service to us:
- Supabase — database and authentication.
- Stripe — subscription billing and payment processing.
- Vercel — application hosting and delivery.
- GitHub — repository access for white-box scans and Auto-Fix (only for repositories you grant).
- Resend — delivery of transactional and lifecycle email.
- Google (Gemini) — AI analysis of scan data to generate plain-English explanations and reports.
- Public vulnerability databases (such as OSV.dev and GitHub Advisory) — queried to identify known-vulnerable dependencies.
AI processing
Parts of your scan data are sent to our AI provider (currently Google's Gemini) to analyze findings and produce the explanations, severity summaries, and fix guidance in your report. This processing is to deliver the service you requested.
Data retention
We keep your account information and scan results for as long as your account is active. Repository source read during a scan is deleted after the scan completes. When you delete your account or ask us to remove your data, we delete or anonymize it except where we must retain limited records to meet legal, accounting, or security obligations.
Your rights and choices
You can access and update your account information, cancel your subscription at any time from the billing portal, revoke the Snytchr GitHub App's access from your GitHub settings or in-app, and request a copy or deletion of your personal data by contacting us. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; we honor those rights for eligible users.
Security
We use industry-standard measures to protect your data, including encryption in transit, scoped access to connected repositories, and not persisting test credentials for on-demand scans. Test credentials stored for scheduled scanning are encrypted at rest and deleted when you turn that schedule off. No system is perfectly secure, but we work to protect your information and to limit what we hold in the first place.
Cookies
We use cookies and similar technologies that are necessary to sign you in and keep the app working. We do not use them to sell your data.
Children's privacy
Snytchr is not intended for anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
International transfers
We and our providers may process your information in countries other than where you live. Where required, we use appropriate safeguards for those transfers.
Changes to this policy
We may update this policy as the service evolves. When we make material changes, we will update the date above and, where appropriate, notify you. Continued use of Snytchr after an update means you accept the revised policy.
Contact us
Questions about this policy or your data? Email us at privacy@snytchr.com.