Legal
Privacy Policy
This policy explains how vetkit (“vetkit”, “we”, “us”) handles personal data when you use vetkit.dev, the vetkit app, the API, the MCP server and the vetkit GitHub App.
Summary
- We read your code only to audit it, never execute it, and delete each checkout when the audit ends.
- We store findings, not repositories. Secret values are never stored.
- We do not sell personal data, show ads, or use your code to train AI models.
- This website sets no cookies and loads no third-party analytics or trackers.
What we collect
Account data from GitHub
When you sign in with GitHub we receive your GitHub user id, username, display name, avatar URL and email address, plus the list of vetkit GitHub App installations you can access. We use your GitHub authorization only during sign-in; we do not store your GitHub user access token.
Repository and installation data
For repositories you connect: installation id, repository id, owner and name, visibility and default branch, and GitHub events about installation changes and pushes.
Audit data
For each audit: the ref and commit SHA, timing and status of each analyzer, tool versions, scores and grades, and findings. A finding contains the rule, category, severity, file path, line numbers, a short code snippet (up to 1 KB) and remediation guidance. Snippets for secret findings are redacted; to recognize the same secret across audits we store a one-way cryptographic hash of it, not the value. Analyzer logs are truncated and kept with the audit to help you debug failures.
API keys and sessions
For API keys: name, prefix, scopes, rate limit, expiry and last-used time. Key secrets and session tokens are stored only as hashes.
Security and usage logs
Our servers log request metadata — IP address, user agent, timestamps, request id and response status — to operate the service and prevent abuse. Security-relevant actions in an organization (for example, creating or revoking an API key) are recorded in an audit log visible to organization admins.
Communications
If you email us — for example to request early access — we keep the correspondence to respond and follow up.
What we do not collect
- Your repository contents. Code is fetched into a temporary directory for the duration of an audit and deleted afterwards, whether the audit succeeds or fails. Only findings, as described above, are kept.
- Secret values. Detected credentials are redacted before storage.
- Long-lived GitHub tokens. Repository access tokens are requested per audit, scoped to one repository, expire within an hour and are never persisted.
- Payment data. vetkit is free during the beta and does not process payments.
How we use data
- To provide the service: authenticate you, run audits you request, and show and export reports.
- To keep it secure: detect abuse, enforce rate limits and investigate incidents.
- To support you and send essential service messages, such as security or policy notices.
- To improve vetkit using aggregated, de-identified metrics such as audit durations or rule hit rates.
Our legal bases, where the GDPR or UK GDPR applies, are performance of our contract with you, legitimate interests in securing and improving the service, and compliance with legal obligations.
Service providers
We use a small number of providers who process data on our behalf, under contract:
- GitHub — sign-in, GitHub App installations and repository access.
- Supabase — managed PostgreSQL database that stores account and audit data.
- Railway — hosting for the vetkit API and the audit workers that process checkouts.
- Vercel — hosting for the vetkit web app.
- Cloudflare — DNS, hosting and content delivery for vetkit.dev, and forwarding of email sent to vetkit.dev addresses.
- OSV.dev (operated by Google) — dependency scanning sends package names and versions from your lockfiles, not your source code.
- Anthropic — only when the AI-authorship signal (beta) runs: a small, deterministic sample of files (at most 16 files, each truncated to 8,000 characters) and commit metadata are sent to Anthropic’s API for analysis. Under Anthropic’s commercial terms, API inputs are not used to train models.
Retention
- Repository checkouts: deleted when each audit ends.
- Audits, findings and reports: kept until you delete them. You can delete individual audits in the app; disconnecting a repository keeps its audit history. When you ask us to delete your account or an organization, we delete the associated data within 30 days.
- GitHub webhook payloads: pruned after 30 days.
- Sessions: expire after 30 days of inactivity or when you sign out.
- Server logs: kept for a limited period, normally no longer than 30 days.
- Backups: deleted data may remain in encrypted backups until they roll over.
Cookies & local storage
vetkit.dev sets no cookies. Your light/dark mode and language choices are saved in your browser’s local storage and never sent to us. The vetkit app uses only strictly necessary cookies: a session cookie that keeps you signed in, and preference cookies that remember your active organization, language and time zone.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing. You can delete audits and disconnect repositories in the app, and uninstall the GitHub App from your GitHub settings at any time. To delete your account or an organization, or for anything else, email privacy@vetkit.dev; we respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
International transfers
Our providers may process data in the European Union and the United States. Where data leaves the EEA or UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
Children
vetkit is a developer tool and is not directed at children under 16.
Changes & contact
We will post changes on this page and update the date above; material changes will also be announced in the app or by email. Questions about privacy: privacy@vetkit.dev. Security issues: see our security page.