← Home

Privacy Policy

Last updated July 2026

Assay is a security tool, so restraint with data is the whole point. This explains exactly what we collect, what we deliberately never store, and who helps us run the service.

What we collect

  • Account. When you sign in with GitHub we receive your GitHub handle, email, avatar, and numeric id — nothing more (we never ask for repository access).
  • Scans. The app URLs you submit, and the findings we produce (issue type, severity, plain-language explanation, and a redacted location such as a column name or file name).
  • Usage & billing. Scan counts for metering, your plan, and — if you subscribe — a Stripe customer id. Card details go straight to Stripe; we never see or store them.

What we never store

  • Secret values. If a scan finds a leaked key, we record whereit leaked, never the key itself — it’s redacted before anything is saved.
  • Your users’ data. Our database checks confirm whether access is open or closed; they do not read, copy, or store the rows in your tables. Zero rows of user data are retained.
  • Your source or page content.We analyze your app’s code in memory during a scan and keep only the findings — not the code or the page bodies.

How we use it

To run scans, show you your reports, meter and bill your plan, send the alerts you asked for by watching an app, and keep the service secure. We don’t sell your data or use it for advertising.

Who processes it (sub-processors)

  • Supabase — database, authentication.
  • Vercel — hosting.
  • Anthropic — generating plain-language explanations from findings (no secret values are sent).
  • Stripe — payments (paid plans only).
  • Resend — sending alert emails (paid plans only).
  • Inngest — scheduling background re-checks.

Retention

We keep your scans and account data while your account is active. Delete your account and we remove your personal data, except where we must keep limited records (for example, billing history) to meet legal obligations.

Your rights

You can access, correct, export, or delete your data. Email hello@assay.devand we’ll help. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA.

Security & cookies

Row-level security scopes every user to their own data; all privileged writes happen server-side. We use only the cookies needed to keep you signed in — no third-party advertising trackers.

Contact

Privacy questions go to hello@assay.dev. Assay is operated by [legal entity].

Questions? Email hello@assay.dev.