legal
Privacy Policy
Last Updated: 2026-07-09
1. Information We Collect
- Account — Email address (for sign-in and account management)
- Scanning — GitHub repository URLs you scan
- Results — Scan findings, scores, vulnerabilities discovered
- Usage — Domain where your badge is embedded, session data
2. How We Use Your Data
- Provide the scanning and reporting service
- Store scan history in your dashboard
- Send account verification and service emails
- Improve the scanner (anonymized data only)
3. Data Storage & Security
- All data stored in a managed database, encrypted at rest
- GitHub repos cloned read-only, never stored or executed
- Cloned repositories deleted immediately after scanning
- Session data encrypted (HttpOnly cookies)
4. Third-Party Services
We rely on a small number of service providers to operate GreenLit:
- Database & authentication provider — stores account and scan data
- AI analysis providers — receive code snippets from scanned repositories for vulnerability analysis; snippets are not used to train their models
- Email delivery service — sends transactional emails
- Cloud hosting provider — runs the application
Each provider processes data only as needed to deliver its service and is bound by its own privacy and security commitments. We never sell personal data, and we never share it with third parties except as required to operate these services.
5. Data Retention
- Scan results — Stored indefinitely until you delete your account
- Session cookies — 7 days
- Email verification — 24 hours
6. Your Rights
- Access your scan history anytime
- Delete individual scans or your entire account
- Request data export — contact support@greenlit.cc
7. GDPR / EU Users
If you're in the EU, you have the right to:
- Access, correct, or delete your data
- Request data portability
- Opt-out of processing
Contact support@greenlit.cc to exercise these rights.
8. Contact
For privacy questions: support@greenlit.cc