RedFlag
Trust & legal

Privacy policy

What personal data RedFlag collects, why, who we share it with, and the rights you have over it.

Last updated: 28 July 2026

Security & dataPrivacy policy

This policy explains how RedFlag("RedFlag", "we", "us") handles personal data when you use useredflag.com and the RedFlag security-scanning service. It should be read alongside our Security & Data Handling page, which documents how your source code is processed.

1. Who we are

RedFlag ("we", "us") operates useredflag.com and the RedFlag security-scanning service, and is the data controller for the personal data described in this policy. For any privacy question or request, contact privacy@useredflag.com.

2. Data we collect

Information you provide via GitHub

When you sign in with GitHub, we receive your GitHub account ID, name, username, email address, and avatar.

GitHub access token

We store an OAuth access token so we can fetch the repositories you scan. It is encrypted at rest and you can revoke it at any time from GitHub.

Repository and scan data

When you run a scan we process your repository's source code transiently and retain the resulting report, which includes file paths, line numbers, and short code excerpts, plus repository metadata (name, visibility, languages). We do not retain the full repository. See Security & Data Handling for detail.

Billing information

Payments are processed by Stripe. We store your subscription status and Stripe customer/subscription identifiers; we do not store your card number - Stripe holds that.

Usage and technical data

We collect limited, privacy-friendly, cookieless analytics (via Vercel Analytics) and standard server logs (such as IP address and request metadata) to operate and secure the service.

3. How we use your data

4. Legal bases (GDPR / UK GDPR)

5. How your source code is handled

Your repository is analysed in ephemeral memory and is never written to disk or stored in our database. Only the scan report (findings with short excerpts) and repository metadata are retained. The full detail, including our subprocessors and encryption, is on the Security & Data Handling page.

6. Sharing & subprocessors

We do not sell your data. We share data only with the third-party providers that operate the service on our behalf (our "subprocessors"), such as our hosting, database, AI, and payment providers. The full list, with the purpose and data each processes, is maintained on the Security & Data Handling page. We may also disclose data where legally required.

7. International transfers

Some subprocessors are located in the United States, so your data may be transferred there. Where we transfer personal data out of the UK/EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum.

8. Retention

When you delete your account, we delete associated personal data except where we must retain it by law.

9. Your rights

Subject to applicable law, you have the right to:

To exercise any of these, email privacy@useredflag.com. You also have the right to lodge a complaint with your local data-protection authority.

10. Security

We use technical and organisational measures to protect your data, including TLS in transit, encryption of access tokens at rest, hashed API keys, and access controls. See Security & Data Handling for specifics. No system is perfectly secure, but we work to protect your data and to respond quickly to issues.

11. Children

RedFlag is not intended for anyone under 16, and we do not knowingly collect data from children.

12. Changes to this policy

We may update this policy from time to time. We will update the "last updated" date above and, for material changes, take reasonable steps to notify you.

13. Contact

Questions or requests: privacy@useredflag.com.