RepoGuard
HomePrivacyTermsInstall Free →

Privacy Policy

Last updated: July 1, 2026

Overview

RepoGuard-IfeCodes (“RepoGuard”, “we”, “us”) is a GitHub App that scans your repositories for malicious code, security vulnerabilities, and suspicious patterns. This Privacy Policy explains what data we collect, how we use it, and your rights.

1. What Data We Collect

1.1 GitHub Installation Data

When you install RepoGuard, we collect and store:

  • Your GitHub account or organisation login name
  • Your GitHub installation ID (assigned by GitHub)
  • The names of repositories you grant RepoGuard access to
  • Installation date and status

1.2 Scan Results

When RepoGuard scans your repositories, we store the names of files that triggered a finding, the rule matched, the severity level, and the scan timestamp. We do not store the contents of your files. File contents are read temporarily in memory and immediately discarded. Only findings are persisted.

1.3 Marketplace and Billing Data

If you install through the GitHub Marketplace, we collect your plan name, billing cycle, free trial status, and dates of plan changes or cancellations. We do not process or store payment information — all billing is handled by GitHub.

1.4 Usage Data

We collect basic operational logs including webhook event types, error messages for debugging, and scan completion status per repository.

2. How We Use Your Data

We use collected data solely to perform security scans, track scan progress, send security alerts (if you configure them), display scan history via the API, and maintain your installation and plan status. We do not use your data for advertising, profiling, or any purpose unrelated to the RepoGuard service.

3. Data Sharing

We do not sell, rent, or share your data with third parties except:

  • GitHub — to read repository contents and post check runs, issues, and pull requests on your behalf
  • MongoDB Atlas — where scan results and installation data are stored
  • Railway — where RepoGuard's server infrastructure is hosted
  • Slack — if you configure notifications, finding summaries (no file contents) are sent to your channel
  • Legal requirements — if required by law

4. Data Retention

  • Installation data — retained while active; deleted 90 days after uninstallation
  • Scan results and findings — retained for 12 months, then permanently deleted
  • Logs — retained for 30 days

You may request deletion of your data at any time by contacting us.

5. Security

We protect your data using TLS encryption in transit, HMAC-SHA256 webhook signature verification, API key authentication on all endpoints, and private key storage as environment variables — never on disk or in version control.

6. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data. Contact us to exercise these rights. We will respond within 30 days.

7. Contact

Fortune Ife Aladetan (IfeCodes)
GitHub: github.com/ALADETAN-IFE

8. Changes to This Policy

We may update this policy from time to time. We will notify users of significant changes by updating the date above. Continued use of RepoGuard after changes are posted constitutes acceptance of the revised policy.

9. Children's Privacy

RepoGuard is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, please contact us immediately.

RepoGuard
HomeHow it worksCompareWhat we detectFAQPrivacyTermsGitHub

© 2026 RepoGuard. Built by IfeCodes.