Legal
Privacy policy
Last updated October 6, 2026
$ cat privacy-policy.md ✓ status ✓ updated questions: [email protected] $
Draft. Replace the bracketed details and have this reviewed by legal counsel before publishing.
This policy explains what [Company legal name] (“OpenRouting”, “we”) collects when you use OpenRouting, why, and what control you have over it. It describes how the product actually works today.
What we collect
- Your Google account basics. When you sign in with Google we receive your name, email address, profile photo and a stable account ID. We don't receive your Google password or access to other Google services.
- Repositories you connect. The repository URL, its name and the branch you choose.
- Scan results. For each finding: the rule that fired, the file path, line numbers, the flagged lines of code, the scanner's message and the history of status changes you make (who, when and any note).
- A session cookie. One signed cookie,
codered_session, keeps you signed in. It holds only your user ID. We don't use advertising or analytics cookies.
What we don't keep
We clone your repository only for the length of a scan and delete the copy when the scan finishes. We store the few flagged lines for each finding, not your source code. Your code is never executed: we don't install dependencies, build it or run its scripts.
AI review
When AI review is enabled, the lines around each finding are sent to Anthropic's Claude API so it can assess the finding. Secrets such as keys, tokens and passwords in those lines are replaced with [REDACTED] before anything is sent. Anthropic processes this data under its commercial terms. [Describe the data processing agreement and retention terms in place with Anthropic.]
Service providers
- Google, for sign-in.
- Anthropic, for AI review (when enabled).
- [Hosting provider and region], where OpenRouting and its database run.
How long we keep data
Your account, repositories and findings are kept until you delete them. Removing a repository deletes its scans and findings. Deleting your account from Settings deletes your account, and if you're the only member of your workspace, all of its repositories, scans and findings. [State backup retention periods.]
Your rights
You can see, export or delete your data at any time. Most of this is available in the product; for anything else, contact us at [privacy contact email]. [Add jurisdiction-specific rights, for example under GDPR or CCPA, as applicable.]
Changes and contact
If we make material changes we'll update this page and the date above. Questions: [privacy contact email], [postal address].