Introduction
Tech Debt Radar ("the Service") is operated by Arkyvion ("we", "us", "our"). This Privacy Policy explains what data we collect, how we use it, and your rights regarding your personal information.
By using the Service, you consent to the data practices described in this policy.
We Do NOT Store Your Source Code
Important
Tech Debt Radar clones your repository temporarily into an ephemeral container solely for the purpose of running static analysis. Once the analysis is complete, the source code is immediately and permanently deleted. We only store the resulting analysis metadata — metrics, scores, file paths, and aggregated statistics.
Data We Collect
- Account Information: Email address, full name, and authentication credentials (hashed passwords or OAuth tokens).
- Analysis Metadata: File paths, complexity scores, churn metrics, risk scores, and aggregated statistics generated from your repository analysis.
- Subscription Data: Plan tier, subscription status, and billing history (payment details are handled exclusively by Paddle).
- Usage Analytics: Pages visited, features used, and general interaction patterns to improve the Service.
Data We Do NOT Collect
- Source code content or file contents.
- Proprietary algorithms or business logic.
- Secrets, credentials, API keys, or environment variables from your repositories.
Third-Party Services
We integrate with the following third-party services:
- GitHub: We use GitHub’s API to access public (or user-authorized private) repositories for analysis.
- OpenAI: We use OpenAI’s API to generate AI-powered summaries from aggregated metrics. No source code is transmitted to OpenAI.
- Paddle: All payment processing is handled exclusively by Paddle, our Merchant of Record. We do not store credit card numbers or payment details.
- Google OAuth: If you sign in with Google, we receive your email address and profile name from Google. We do not access any other Google data.
Data Retention
Analysis results are retained for the duration of your account plus 30 days after account deletion. You may request data export or deletion at any time by contacting support@arkyvion.com.
Cookies & Local Storage
We use browser local storage to persist your authentication token for a seamless login experience. We do not use third-party tracking cookies. Essential cookies may be used to maintain session state and preferences.
Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS/HTTPS), encrypted database credentials, and access controls. While no system can guarantee absolute security, we are committed to protecting your information.
Your Rights
You have the right to:
- Access the personal data we hold about you.
- Correct any inaccurate personal data.
- Delete your account and all associated data.
- Export your analysis data in a portable format.
To exercise any of these rights, contact us at support@arkyvion.com.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically.
Contact Us
If you have any questions about this Privacy Policy, please contact us at support@arkyvion.com.