This policy explains how RedFlag("RedFlag", "we", "us") handles personal data when you use useredflag.com and the RedFlag security-scanning service. It should be read alongside our Security & Data Handling page, which documents how your source code is processed.
1. Who we are
RedFlag ("we", "us") operates useredflag.com and the RedFlag security-scanning service, and is the data controller for the personal data described in this policy. For any privacy question or request, contact privacy@useredflag.com.
2. Data we collect
Information you provide via GitHub
When you sign in with GitHub, we receive your GitHub account ID, name, username, email address, and avatar.
GitHub access token
We store an OAuth access token so we can fetch the repositories you scan. It is encrypted at rest and you can revoke it at any time from GitHub.
Repository and scan data
When you run a scan we process your repository's source code transiently and retain the resulting report, which includes file paths, line numbers, and short code excerpts, plus repository metadata (name, visibility, languages). We do not retain the full repository. See Security & Data Handling for detail.
Billing information
Payments are processed by Stripe. We store your subscription status and Stripe customer/subscription identifiers; we do not store your card number - Stripe holds that.
Usage and technical data
We collect limited, privacy-friendly, cookieless analytics (via Vercel Analytics) and standard server logs (such as IP address and request metadata) to operate and secure the service.
3. How we use your data
- To provide the service - authenticate you, fetch and scan your repositories, and show you reports.
- To process subscriptions and payments.
- To provide support and respond to your requests.
- To secure the service, prevent abuse, and debug problems.
- To send essential service communications (we do not send marketing without your consent).
4. Legal bases (GDPR / UK GDPR)
- Performance of a contract - to deliver the service you sign up for.
- Legitimate interests - to secure, maintain, and improve the service, balanced against your rights.
- Legal obligation - to meet accounting, tax, and legal requirements.
- Consent - where required; you can withdraw it at any time.
5. How your source code is handled
Your repository is analysed in ephemeral memory and is never written to disk or stored in our database. Only the scan report (findings with short excerpts) and repository metadata are retained. The full detail, including our subprocessors and encryption, is on the Security & Data Handling page.
6. Sharing & subprocessors
We do not sell your data. We share data only with the third-party providers that operate the service on our behalf (our "subprocessors"), such as our hosting, database, AI, and payment providers. The full list, with the purpose and data each processes, is maintained on the Security & Data Handling page. We may also disclose data where legally required.
7. International transfers
Some subprocessors are located in the United States, so your data may be transferred there. Where we transfer personal data out of the UK/EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum.
8. Retention
- Account data is kept for as long as your account is active.
- Scan reports are kept until you delete them or close your account.
- Your GitHub token is kept until you revoke access or delete your account.
- Billing records are kept as long as required for legal and accounting purposes.
When you delete your account, we delete associated personal data except where we must retain it by law.
9. Your rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- delete your data ("right to be forgotten");
- export your data in a portable format;
- restrict or object to certain processing;
- withdraw consent where processing relies on it.
To exercise any of these, email privacy@useredflag.com. You also have the right to lodge a complaint with your local data-protection authority.
10. Security
We use technical and organisational measures to protect your data, including TLS in transit, encryption of access tokens at rest, hashed API keys, and access controls. See Security & Data Handling for specifics. No system is perfectly secure, but we work to protect your data and to respond quickly to issues.
11. Children
RedFlag is not intended for anyone under 16, and we do not knowingly collect data from children.
12. Changes to this policy
We may update this policy from time to time. We will update the "last updated" date above and, for material changes, take reasonable steps to notify you.
13. Contact
Questions or requests: privacy@useredflag.com.