▸ CODESCAN
PricingDocsContactSign in
LEGAL

Privacy Policy

Last updated: 28 July 2026

1. Information We Collect

We collect the following information when you use CodeScan: • Account information: email address and hashed password when you register. • Usage data: number of files scanned, scan timestamps, and your subscription tier. • Website analytics: page path, visit timestamps, active time while a page is visible and focused, referring hostname, and approximate country, state/region, city, and timezone supplied by our network provider. • Anonymous daily visitor identifier: a one-way HMAC derived from network and browser request data. It rotates each Eastern calendar day and is used only to avoid counting the same daily visitor repeatedly. We do not store the raw IP address or full user-agent string in our analytics database. • Payment information: processed securely by Stripe. We never store credit card numbers. • Support tickets: name, email, phone (optional), and issue description submitted via our support form. • Technical data: IP address, browser type, and access timestamps may be processed transiently by our infrastructure for security and abuse prevention.

2. How We Use Your Information

We use the information we collect to: • Provide, operate, and improve the CodeScan service. • Measure daily visitors, page views, approximate visitor locations, visit times, and active engagement duration. • Process payments and manage your subscription. • Send transactional emails (receipts, subscription updates, support responses). • Enforce our Terms of Service and prevent abuse. • Analyse usage patterns to improve features.

3. Your Source Code

Files you upload or scan through the CodeScan web interface are: • Processed in-memory on isolated serverless functions. • Never written to disk or stored in any database. • Never used to train AI models. • Discarded immediately after the scan response is sent. For CLI users, files are transmitted over HTTPS directly from your machine to our API and are subject to the same protections.

4. Data Sharing

We do not sell your personal information. We share data only with: • Stripe (payment processing) • Supabase (authentication, usage, and privacy-first website analytics storage) • Anthropic (AI analysis — only file content during a scan, not your account data) • Resend (transactional email delivery) • Vercel (hosting infrastructure) • Cloudflare (network security, approximate geolocation, and aggregate web analytics) All sub-processors are contractually bound to protect your data.

5. Data Retention

• Account data: retained while your account is active. Deleted within 30 days of account closure. • Usage and website analytics logs: retained for up to 12 months for reporting, billing, and abuse prevention. • Support tickets: retained for 2 years. • Payment records: retained as required by applicable law (typically 7 years).

6. Your Rights

Depending on your jurisdiction, you may have the right to: • Access the personal data we hold about you. • Correct inaccurate data. • Request deletion of your data. • Export your data in a portable format. • Object to or restrict certain processing. To exercise these rights, contact us at support@flowlog.dev.

7. Cookies and Local Storage

We use only essential session cookies required for authentication. We do not use advertising cookies or third-party analytics cookies. Our first-party analytics uses temporary browser session storage to keep an anonymous visit together within one browser tab; it expires when the tab session ends and is not used for cross-site advertising.

8. Security

We use industry-standard security measures including TLS encryption in transit, encrypted storage at rest, and access controls. However, no system is 100% secure. If you discover a security vulnerability, please report it to support@flowlog.dev.

9. Children

CodeScan is not directed to children under 16. We do not knowingly collect personal information from anyone under 16.

10. Chrome Extension — Additional Disclosures

The CodeScan Chrome Extension ("the Extension") is subject to the following additional disclosures required by the Chrome Web Store: Data accessed by the Extension: • Active tab URL — to detect whether you are on a GitHub, Azure DevOps, or AWS CodeCommit repository page. The URL is read locally in your browser; it is never transmitted to our servers. • Tab title — used solely to extract the repository name displayed in the popup. • chrome.storage.local — stores your last scan result (grade, score, vulnerability counts) locally on your device for display in the popup. No personal data is stored. Data NOT collected by the Extension: • We do not read, collect, or transmit your source code through the Extension. • We do not track your browsing history. • We do not collect any personally identifiable information through the Extension. • We do not use cookies in the Extension context. How the Extension works: 1. When you visit a supported repository page, the Extension detects the repository URL locally. 2. Clicking "Scan This Repository" opens the CodeScan web application (codesscan.com) in a new tab with the repository pre-filled. The scan is performed by the web application — not by the Extension itself. 3. The Extension popup displays your most recent scan result retrieved from local storage. Permissions justification: • tabs / activeTab: Required to read the current tab's URL to detect repository pages. • storage: Required to save and display your last scan result in the popup. • Host permissions (github.com, dev.azure.com, visualstudio.com, console.aws.amazon.com): Required for the content script to inject the "⬡ Scan" button into repository pages. No data from these pages is transmitted externally. • codesscan.com: Required to open the scanner application and retrieve your scan history for display in the popup.

11. Changes to This Policy

We may update this Privacy Policy. We will notify you of material changes via email or a notice on the platform. Continued use of CodeScan after changes constitutes acceptance of the updated policy.

12. Contact

For privacy-related questions or requests: Email: support@flowlog.dev Website: codesscan.com/contact