Privacy Policy

Last updated: January 2026

01

Introduction

At Repoloom, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our security scanning platform.

This policy complies with the Swiss Federal Act on Data Protection (FADP/DSG) and is aligned with the EU General Data Protection Regulation (GDPR). By using Repoloom, you acknowledge the data practices described in this policy.

Tim Fischer

Switzerland

Email: [email protected]

Repoloom is operated as a sole proprietorship (Einzelunternehmen), not a registered company.

03

Information We Collect

We collect the following types of information:

Account Information

  • Email address: Used for account identification and notifications
  • Display name: Your public username from GitHub/GitLab
  • Avatar URL: Your profile picture from GitHub/GitLab
  • OAuth provider ID: Your unique identifier from GitHub/GitLab

OAuth Connection Data

  • Access tokens: Encrypted and stored to access your repositories
  • Refresh tokens: Encrypted and stored for token renewal
  • Token expiration: Used to manage token lifecycle
  • OAuth scopes: The permissions you granted us

Repository Data

  • Repository metadata: Name, description, URL, visibility, default branch
  • GitHub metadata: Primary language, stars, forks, size
  • Dependency manifests: package.json, requirements.txt, etc.
  • Source code: Temporarily accessed for SAST analysis (not stored long-term)

Scan Results

  • Vulnerability findings: CVE IDs, severity, affected packages
  • Secret detections: Type and location of detected secrets (values are masked)
  • SAST findings: Code issues, file paths, line numbers, code snippets
  • Outdated packages: Package names, versions, update recommendations
  • Container findings: Image vulnerabilities and recommendations

Subscription and Billing

  • Stripe Customer ID: Your identifier in our payment system
  • Subscription tier: Your current plan (Small, Medium, Pro)
  • Trial information: Trial start and end dates
  • Subscription status: Active, canceled, or expired

Payment card details are processed and stored directly by Stripe. We never have access to your full card number.

Usage Data

  • Repository changes per month: Number of repos added/removed
  • Manual scans per month: Number of scans triggered manually
  • Scan history: When scans were performed and their results

Server Logs

For security and operational purposes, our servers automatically log certain request information:

  • Anonymized IP address: The last octet of IPv4 addresses is zeroed (e.g., 192.168.1.x → 192.168.1.0). For IPv6, only the first 48 bits are retained
  • Request paths: URLs you access (sensitive query parameters like OAuth codes and tokens are automatically redacted)
  • Timestamps: When requests were made
  • Response status codes: HTTP status codes (200, 404, etc.)
  • Response times: How long requests took to process

We never log OAuth authorization codes, access tokens, refresh tokens, passwords, API keys, or other authentication credentials. These are automatically redacted at the application level.

04

How We Use Your Information

We use the collected information to:

  • Provide and maintain our security scanning service
  • Authenticate you and manage your account
  • Access your repositories for security analysis
  • Generate security reports and vulnerability alerts
  • Process payments and manage subscriptions
  • Enforce usage limits based on your subscription tier
  • Send important service notifications
  • Improve and optimize our scanning algorithms
  • Comply with legal obligations
05

Data Storage and Security

We implement industry-standard security measures to protect your data:

  • Encryption at rest: OAuth tokens are encrypted before storage
  • Encryption in transit: All data is transmitted over HTTPS
  • HTTP-only cookies: Session tokens cannot be accessed by JavaScript
  • Secure credential storage: Database credentials use environment variables
  • Access controls: Strict authentication required for all API endpoints

Source Code Handling

When performing SAST scans, we temporarily clone your repository to analyze the code. After the scan completes, the cloned repository is deleted. We do not permanently store your source code. Only scan results (findings, file paths, code snippets around issues) are retained.

06

Data Retention

We retain your data as follows:

  • Account data: Retained until you delete your account
  • Repository data: Retained until you remove the repository
  • Scan results: Retained for 12 months, then automatically deleted (we always keep the most recent scan per repository)
  • Email notifications: Retained for 3 months, then automatically deleted
  • Server logs: Stored on our own servers with automatic rotation. Logs contain only anonymized data (masked IPs, redacted tokens) and are retained for a maximum of 90 days before deletion.
  • OAuth tokens: Retained until revoked or expired
  • Billing records: Retained as required by law (typically 7 years)

Automatic cleanup: We run daily automated processes to enforce these retention periods, ensuring data is deleted according to schedule.

You can request deletion of your data at any time by contacting us or deleting your account through the settings page.

07

Third-Party Services

We use the following third-party services:

GitHub / GitLab

We use OAuth to authenticate you and access your repositories. Your relationship with GitHub/GitLab is governed by their respective privacy policies.

Stripe

Payment processing is handled by Stripe. Your payment information is collected and processed directly by Stripe according to their Privacy Policy.

Vulnerability Databases

We use public vulnerability databases (OSV, NVD) to match your dependencies against known vulnerabilities. No personal data is shared with these services.

08

Cookies

We use the following cookies:

  • Session cookie (HTTP-only): Contains an encrypted session token for authentication. Essential for the service to function.
  • Refresh token cookie (HTTP-only): Used to refresh expired session tokens without requiring re-login.

We do not use tracking cookies, advertising cookies, or third-party analytics that track you across websites.

09

Your Rights

Under the Swiss FADP and GDPR, you have the following rights regarding your personal data:

  • Right of access: Request information about your personal data we hold
  • Right to rectification: Request correction of inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent
  • Right to restriction: Request restriction of processing in certain circumstances

Opt-out right: You may opt out of non-essential data processing at any time by adjusting your account settings or contacting us. You can revoke GitHub/GitLab access by disconnecting your OAuth connection in the settings.

Self-service options: You can exercise several rights directly:

  • Data export: Download all your data in JSON format from your account settings
  • Account deletion: Delete your account and all associated data from your account settings
  • Revoke access: Disconnect OAuth connections in your account settings

For other requests or if you need assistance, contact us at [email protected]. We will respond within 30 days as required by law.

10

Data Sharing

We do not sell your personal data. We may share data only in these cases:

  • Service providers: With Stripe for payment processing
  • Legal requirements: When required by law or legal process
  • Business transfers: In connection with a merger or acquisition
  • With your consent: When you explicitly agree to share data
11

International Transfers

Your data may be transferred to and processed in countries outside Switzerland or the EEA. We ensure appropriate safeguards are in place:

  • USA: Transfers to certified US companies are covered by the Swiss-US Data Privacy Framework, recognized by the Swiss Federal Council as providing adequate data protection (since September 2024)
  • EU/EEA: The European Commission recognizes Switzerland as providing adequate data protection
  • Other countries: We use Standard Contractual Clauses (SCCs) approved by the Swiss FDPIC and EU Commission
12

Data Breach Notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will:

  • Notify the Swiss Federal Data Protection and Information Commissioner (FDPIC) as soon as possible
  • Inform affected users without undue delay when required
  • Document all breaches including facts, effects, and remedial actions taken
13

Children's Privacy

Repoloom is not intended for use by children under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

14

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.

15

Supervisory Authority

If you believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with a supervisory authority:

Federal Data Protection and Information Commissioner (FDPIC)

Feldeggweg 1
CH-3003 Bern
Switzerland

Website: www.edoeb.admin.ch

16

Contact

If you have any questions about this Privacy Policy or our data practices, please contact:

Tim Fischer

Switzerland

Email: [email protected]

We aim to respond to all privacy-related inquiries within 30 days.