1. Who we are
CodeAuditAgent (codeauditagent.com and codeauditagent.dev) is operated by Lina Source LLC, a limited liability company registered in Wyoming, USA, at 30 N Gould St Ste N, Sheridan, WY 82801, USA. Lina Source LLC is the controller of the personal data described in this policy.
For any privacy question or request, email [email protected]. Email is the fastest way to reach us.
2. Data we collect
Account data from GitHub
You sign in with GitHub. With your permission, GitHub shares your GitHub account ID, name, primary email address and profile picture URL. We store these in our database to identify your account.
GitHub also issues an access token with read-only scopes for your profile and email. The token is kept only inside your encrypted session cookie and is used to request public repository files from the GitHub API on your behalf. We do not store it in our database.
Code you submit for audits
- Repository audits: we download a limited number of source files from the default branch of a public GitHub repository you provide.
- Snippet audits: the code you paste into the dashboard.
- This code is processed to produce the audit and is not stored in full. The resulting audit report is stored and may contain short excerpts of your code quoted as evidence for findings.
Audit and usage data
The repositories you track (name and URL), your audit reports, their status and timestamps, and the counts we use to apply your plan's limits.
Billing data
Payments are processed by Stripe. We store your Stripe customer ID, your plan and your subscription status. Card numbers and payment details are collected and stored by Stripe; we never see or store them.
Preferences
Your preferred language.
Technical and security data
When you use the site, our servers and our network provider Cloudflare process technical data such as IP address, browser user agent, requested URL and time. We use it to deliver the site, prevent abuse, enforce rate limits and investigate security incidents.
3. How we use your data and our legal bases
- To provide the service you signed up for: authentication, running audits, storing and showing your reports, and applying plan limits (performance of a contract).
- To process subscriptions and payments and keep records required by tax and accounting law (performance of a contract and legal obligation).
- To keep the service secure and reliable, prevent fraud and abuse, and enforce our Terms (legitimate interests).
- To respond to your requests and communicate with you about your account, security or material changes (performance of a contract and legitimate interests).
- To comply with applicable law and lawful requests from authorities (legal obligation).
We do not use your code or your personal data for advertising, and we do not build marketing profiles.
4. AI processing of your code
Audits are generated by Anthropic's Claude models through the Anthropic API. The code included in an audit is sent to Anthropic for processing, and the generated report is returned to us. Under Anthropic's commercial terms, content submitted through the API is not used to train its models.
Do not submit code containing secrets, credentials or personal data of others unless you are authorized to do so. If an audit reveals secrets in your code, rotate them.
6. International transfers
Lina Source LLC is based in the United States and some of our providers process data outside your country. Where the law requires it, transfers from the European Economic Area, the United Kingdom, Switzerland, Türkiye, Brazil and other countries with transfer rules rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or other mechanisms recognized by the applicable law.
7. How long we keep data
- Account data, tracked repositories and audit reports: until you delete them or delete your account.
- Deleting a repository deletes all of its audit reports. Deleting your account permanently deletes your account data, repositories and reports from our production database.
- Billing records: kept by Stripe and by us for as long as tax and accounting laws require.
- Server and security logs: kept for a limited period, generally no longer than 90 days, unless needed to investigate an incident.
8. Your rights and choices
Depending on where you live, including under the EU and UK GDPR, Türkiye's KVKK, Brazil's LGPD, US state privacy laws such as the CCPA/CPRA, and other laws such as Japan's APPI, South Korea's PIPA, India's DPDP Act and Indonesia's PDP Law, you have the right to:
- Access your personal data and receive a copy. You can download all of your data as JSON from Settings → Your data.
- Correct inaccurate data. Your name, email and avatar come from GitHub and update when you sign in.
- Delete your data. You can delete your account yourself from Settings → Delete account.
- Object to or restrict certain processing, and receive your data in a portable format.
- Know what we collect and how we use it, and not be discriminated against for exercising these rights. We do not sell or share personal information as defined by US state laws.
- Lodge a complaint with your local data protection authority, such as an EU supervisory authority, the UK ICO, Türkiye's Personal Data Protection Authority (KVKK) or Brazil's ANPD.
To make a request we cannot handle in the dashboard, email [email protected]. We will respond within the time required by applicable law, normally within 30 days, and may need to verify your identity first.
10. Security
We protect data with encryption in transit (TLS with HSTS), encrypted session cookies, row-level security in our database, restricted and least-privilege API keys, signature-verified payment webhooks and strict security headers. No system is perfectly secure; if you believe you have found a vulnerability, please report it to [email protected].
11. Children
CodeAuditAgent is a professional tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the service evolves. The date at the top shows the latest version. If we make material changes, we will notify you by email or in the dashboard before they take effect.
13. Contact
Lina Source LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA. Email: [email protected] (preferred).