What we collect
- Account. When you sign in with GitHub we receive your GitHub handle, email, avatar, and numeric id — nothing more (we never ask for repository access).
- Scans. The app URLs you submit, and the findings we produce (issue type, severity, plain-language explanation, and a redacted location such as a column name or file name).
- Usage & billing. Scan counts for metering, your plan, and — if you subscribe — a Lemon Squeezy customer id. Lemon Squeezy is the seller of record for paid plans: your card details, billing address, and any tax identifiers go to Lemon Squeezy, and we never see or store them.
- Anonymous scan statistics. When a scan runs without an account, we keep the shape of the result and nothing else: which builder made the app, the verdict, the score, and how many issues of each severity. No URL, no IP address, no account — nothing that could identify you or your app. It tells us how often AI-built apps ship with an open database, and lets us publish that.
What we never store
- Secret values. If a scan finds a leaked key, we record whereit leaked, never the key itself — it’s redacted before anything is saved.
- Your users’ data. Our database checks confirm whether access is open or closed; they do not read, copy, or store the rows in your tables. Zero rows of user data are retained.
- Your source or page content.We analyze your app’s code in memory during a scan and keep only the findings — not the code or the page bodies.
How we use it, and why we’re allowed to
We don’t sell your data or use it for advertising. Under the GDPR every use needs a legal basis; here is ours, purpose by purpose.
- Running scans, storing your reports, keeping you signed in, and sending the alerts you asked for— performance of our contract with you. This is the service you signed up for.
- Metering and billing your plan— performance of the contract, and our legal obligation to keep tax records.
- Rate limiting, abuse prevention, and keeping the service secure— our legitimate interest in not having the service abused, which we consider not to override your rights since it uses the minimum data needed and protects every user.
- Anonymous scan statistics and page analytics— legitimate interest in understanding how the product is used. Neither identifies you.
Where your data goes
Assay is operated from Azerbaijan, and the providers listed above run mainly in the United States and the European Union. If you are in the EEA or the UK, that means your data leaves your region.
Each of those providers publishes a data processing agreement incorporating the European Commission’s Standard Contractual Clauses, and those clauses are the safeguard these transfers rely on. We use them under those terms and don’t transfer your data anywhere else.
Who processes it (sub-processors)
- Supabase — database, authentication.
- Vercel — hosting.
- Anthropic — generating plain-language explanations from findings (no secret values are sent).
- Lemon Squeezy — payments and tax, as seller of record (paid plans only).
- Resend — sending alert emails (paid plans only).
- Inngest — scheduling background re-checks.
- Vercel Analytics — page views and performance. It sets no cookies and collects no personal data, which is why this site has no cookie banner.
How long we keep it
- Account, scans, findings, and your conversations with the agent— while your account is open. Delete your account and these are deleted with it, within 30 days.
- A record of alert emails sent— 12 months, so we don’t send you the same alert twice.
- Rate-limiting counters— hours to days. They expire on their own.
- Billing records— held by Lemon Squeezy as seller of record, for as long as tax law requires them (generally several years). Deleting your Assay account does not erase these, because we aren’t permitted to destroy them.
- Anonymous scan statistics— kept indefinitely. They contain no URL, no address, and no account, so there is nothing in them to connect to you.
Your rights
You can ask us to give you a copy of your data, correct it, export it, delete it, or restrict what we do with it. You can also object to any processing we do on the basis of legitimate interests. Email hello@assaysecurity.comand we’ll act on it within 30 days. It’s free, and we won’t ask why.
If you are in the EEA or the UK and think we’ve handled your data badly, you can complain to your national data protection authority — you don’t have to come to us first, though we’d rather you did so we can fix it. If you are in California, the CCPA gives you comparable rights, and we don’t sell or share personal information as it defines those terms.
Security & cookies
Row-level security scopes every user to their own data; all privileged writes happen server-side. We use only the cookies needed to keep you signed in — no third-party advertising trackers.
Contact
Privacy questions go to hello@assaysecurity.com. Assay is operated by Aynur Əliyeva, based in Baku, Azerbaijan Republic, who is the data controller for the information described above.