Privacy Policy

Last updated: December 2025

Our Commitment

We believe in transparency and data minimization. We collect only what's necessary to provide the service, and we never sell your data.

1. Information We Collect

Account Information

When you sign up using GitHub OAuth, we receive:

  • GitHub username
  • Email address
  • Profile picture URL
  • GitHub user ID (for authentication)

Project Data

When you use project features, we store:

  • Project manifest files you upload (package.json, requirements.txt, etc.)
  • Dependency information extracted from manifests
  • Project configuration and labels

Usage Data

We collect anonymized usage data to improve the service:

  • Pages visited and features used
  • Search queries (anonymized)
  • API and MCP tool usage statistics
  • Error logs for debugging

Technical Data

Standard web service data:

  • IP address (for rate limiting and security)
  • Browser type and version
  • Device information

2. How We Use Your Information

We use collected information to:

  • Provide and maintain the Service
  • Authenticate your identity
  • Analyze your project dependencies
  • Improve the Service based on usage patterns
  • Prevent abuse and enforce rate limits
  • Communicate service updates (if you opt in)

3. Data Sharing

We do not sell your data.

We may share data only in these circumstances:

  • Service providers: Infrastructure and hosting services that help us operate (e.g., cloud hosting)
  • Legal requirements: When required by law or to protect our rights
  • With your consent: When you explicitly agree to share

4. Data Security

We implement security measures including:

  • HTTPS encryption for all connections
  • Encrypted data storage
  • Access controls and authentication
  • Regular security reviews

However, no method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

5. Data Retention

  • Account data: Retained while your account is active
  • Project data: Retained until you delete the project or your account
  • Usage logs: Typically retained for 90 days

Note: As an alpha service, data retention practices may evolve.

6. Your Rights

You have the right to:

  • Access: View the data we have about you
  • Delete: Request deletion of your account and data
  • Export: Download your project data
  • Correct: Update inaccurate information

To exercise these rights, contact us or use the account settings.

7. Cookies and Local Storage

We use:

  • Session cookies: Essential for authentication
  • Preference cookies: Remember your settings (e.g., selected registry)
  • Local storage: CLI token storage on your machine

We do not use third-party advertising or tracking cookies.

8. Third-Party Services

The Service integrates with:

9. Children's Privacy

The Service is not intended for users under 13 years of age. We do not knowingly collect data from children.

10. International Data

Your data may be processed in countries other than your own. By using the Service, you consent to this transfer.

11. Changes to This Policy

We may update this Privacy Policy as our practices evolve. We will notify users of significant changes. The "Last updated" date indicates when the policy was last revised.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us through the GitHub repository or other official channels.