Breaklytix← Back to home

Privacy Policy

Last updated: September 8, 2026

This policy explains what Breaklytix collects, why we collect it, and how it is protected. It applies to the Breaklytix website and service.

1. Information We Collect

  • Account information. When you sign in with GitHub, we receive and store your email address, GitHub user ID, and GitHub username. We do not store passwords — sign-in is handled through GitHub OAuth.
  • Repository information. For repositories you connect, we store repository names and metadata, scan results (detected third-party API usage, dependency versions, and reliability findings), and the issues/alerts derived from them. We fetch source file contents only to perform a scan; scan results are stored, not the full file contents.
  • Provider connection metadata. When you connect an API provider (for example OpenAI or GitHub), we store the provider name, connection status, a masked identifier, and metadata about usage, quota, and rate-limit snapshots.
  • API credentials. Provider API keys and GitHub access tokens you authorize are encrypted before being stored (Fernet, AES-128-CBC with HMAC). Full credentials are never returned to the browser and never exposed in URLs, emails, or logs.
  • Usage information. We store snapshots of usage and rate-limit data for connected providers, alert delivery records, and email preferences.
  • Logs. We keep limited diagnostic logs (for example error traces) to operate and debug the service. Credentials and secrets are never written to these logs.
  • Cookies. The application does not use tracking cookies. See our Cookie Policy for details.

2. How We Use Your Information

We use the information above to:

  • Operate the service: authenticate you, scan repositories you connect, monitor provider changelogs for breaking changes, and raise alerts.
  • Generate auto-fix pull requests in repositories you connect and you have authorized — you remain responsible for reviewing and merging them.
  • Send transactional email (alerts, digests, and product updates) through our email provider.
  • Process billing if you subscribe to a paid plan.
  • Secure the service, investigate errors, and respond to support requests.

We do not sell your personal information. We do not use your data for advertising.

3. Storage & Security

  • Data is stored in a hosted PostgreSQL database (Supabase) with encryption at rest.
  • GitHub access tokens and provider API keys are encrypted before storage (Fernet, AES-128-CBC with HMAC); the encryption key exists only in the server environment.
  • All traffic uses HTTPS in transit.
  • Database credentials (service-role key) exist only on the server and are never shipped to the browser.
  • Provider credentials are shown in the UI only as masked metadata (e.g. a short identifier), never as full keys.

4. Data Retention

We retain your account data while your account is active. Deleting your account removes your account, repository connections, provider connections, scan results, and alerts. Global provider-incident records are not attributable to any individual user and may be retained for service operation. Records may be kept for a limited additional period where required for legal, accounting, or abuse-prevention purposes.

5. Third-Party Services

We work with the following processors to operate the service:

  • GitHub — OAuth sign-in and repository access (including opening auto-fix pull requests only in repositories you connect, with your review).
  • Supabase — hosted PostgreSQL database.
  • Vercel — hosting for the web application and API.
  • Resend — transactional email delivery.
  • Stripe — payment processing, only if you subscribe to a paid plan.

6. Analytics & Cookies

We do not run third-party visitor analytics and we do not use advertising or tracking cookies. Authentication state is kept in your browser's local/session storage (not cookies). See our Cookie Policy for details.

7. Your Rights & Data Deletion

  • Access & correction. You can view and update your account data in the application, or request a copy by contacting us.
  • Deletion. You can disconnect repositories and providers at any time, and delete your account (which removes your data as described in section 4).
  • Revoke GitHub access. You can revoke the application's GitHub access at any time from your GitHub account settings.

If you are in a jurisdiction with data-protection rights (such as the GDPR or CCPA), we honour those rights: access, correction, deletion, restriction, portability, and objection. We do not engage in automated decision-making that produces legal effects about you. To exercise any right, contact us using the details in section 9.

8. Changes to This Policy

We may update this policy as the service evolves. Material changes will be announced on this page with an updated “Last updated” date, and where practical we will notify you by email.

9. Contact

This policy is provided by Breaklytix (registered address available on request).

Questions or privacy requests: hashirattari73@gmail.com or visit our Contact page.