CodanopySecurity scanning for AI-generated apps
Legal

Privacy Policy

Last updated 2 October 2026.

You hand us source code and an email address, which is more trust than most services ask for. This page says exactly what happens to both.

Who controls your data

Bendegúz Szatmári, egyéni vállalkozó (sole trader), Liptó utca 9, Building B, ground floor, door 2, 1124 Budapest, Hungary. Registration number 62462161, VAT number HU92150650. For anything on this page, email bendeguz@codanopy.com.

What we collect

  • Your email address, because a scan takes minutes and we deliver the report by email.
  • The code you submit — a public GitHub URL we clone, or a ZIP you upload. We keep the URL; we do not keep the code.
  • What the scan concluded about your code — the languages and frameworks we detected, and one record per problem found, including the file path and line number it sits at. This is the report, and we keep it. See below.
  • Your IP address, as a salted hash only. We hash it on arrival and store the hash. The raw address is never written down. It exists to count scans against the rate limits and for nothing else.
  • Usage events — that a scan started, finished, or failed, what languages were detected, how many findings of each severity, whether a report was unlocked.

What we do not collect

No accounts, so no passwords. No card details — those go to Stripe and never touch our servers. No raw IP addresses. No tracking of you across other websites. We never capture what you type or the text on your screen. We never sell anything to anyone, and we do not send marketing email.

Your code, specifically

We clone or extract your source into a temporary working directory, analyse it, and delete that directory when the scan ends. The repository itself is never stored.

The only fragments we keep are the specific lines each finding refers to, because writing a useful fix prompt requires them. Those lines are sent to Anthropic, who run the AI model that writes the explanations and fix prompts. Anthropic processes them on our instructions and does not train models on them. If your code is sensitive enough that this is a problem, do not submit it.

What we keep about your code, and for how long

This is the part worth reading twice. The code goes away; the conclusions do not.

Your report is a list of the security weaknesses in your application, and we keep it indefinitely. Each finding records what kind of problem it is, how severe it is, which file and line it is on, which scanner rule fired, and — once you unlock the report — an explanation and a fix prompt. The URL of the repository you submitted is kept too. Only the quoted code sections are deleted; everything else survives, because a scorecard whose link stops working is not a scorecard.

The consequence is worth stating plainly: anyone who obtains a report link obtains a map of where that application is weak. We keep report pages out of search engines, but the link is the only thing standing between the report and whoever holds it. If you would rather that record did not exist, ask us to delete it and we will.

We also keep which languages and frameworks the scan detected. Those, and counts of findings by severity and category, are the only things that reach our analytics — never a file path, a repository URL, a report link or the text of a finding.

Why we are allowed to

  • To do what you asked (running the scan, producing the report, emailing you the link, taking payment) — performing our contract with you.
  • To keep the service standing up (rate limits on a hashed IP, bot checks, anonymous usage statistics) — our legitimate interest in not being flooded off the internet by automated abuse, weighed against how little the data says about you.
  • To keep our books (payment records) — a legal obligation under Hungarian accounting law.

How long we keep it

WhatHow long
Your repository or uploaded ZIPNever stored. Deleted when the scan ends.
The code sections a finding refers toUntil your unlocked report is delivered, or one week — whichever is first.
Your report and its findings — severity, category, file path, line number, rule, and the explanation and fix prompt once unlockedIndefinitely, so the link you share keeps working. Deleted on request.
The repository URL you submitted, and the languages and frameworks detected in itAs long as the scan record exists.
Your email addressAs long as the report it delivered exists.
Hashed IP addressAs long as the scan record exists.
Payment recordsEight years, because Hungarian accounting law requires it.

If you unlock a report more than a week after the scan, the code sections are already gone and the fix prompts are written from the finding details alone. They will be less specific. That is the retention policy working as intended.

Who else touches it

These companies process data on our behalf. Nobody else does.

WhoWhat forWhere
HetznerHosting, database, backupsGermany (EU)
AnthropicAI analysis of your code sections and findingsUnited States — standard contractual clauses
StripePayment processingIreland / United States — standard contractual clauses
ResendSending your report and status emailsUnited States — standard contractual clauses
PostHog Cloud EUProduct analyticsEuropean Union
Cloudflare TurnstileBlocking bots on the scan formUnited States — standard contractual clauses

Where a processor is outside the EU, the transfer runs on the European Commission's standard contractual clauses. Stripe is a separate controller for your card details, under its own privacy policy — we never receive them.

Cloning a public GitHub repository is an outbound request to GitHub. No personal data of yours goes with it.

Cookies

We set none. Our analytics keeps its state in memory for the length of your visit and writes nothing to your browser, which is why this site has no cookie banner to click away.

Analytics, and what it is not allowed to see

We count what happens — pages visited, links clicked, scans started, reports viewed, reports unlocked — so we know whether the product works. If the link you arrived by carries campaign tags (the utm_ parameters), we note those along with the first page you landed on, for that visit only. Report IDs, email addresses, repository URLs, file paths and finding text are stripped before anything is sent, because a report ID is the key to a report and analytics is not the place for keys.

We also record how the site is used during a visit: which buttons and links are clicked, scrolling and mouse movement, as a replay of the page layout. Every piece of text and every form field is masked before it leaves your browser, so a replay shows boxes where your email, your repository and your report would be. The recording ends when you close or reload the tab.

Your rights

You can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop processing it, or ask for it in a portable form. Reply to the email that delivered your report, or write to bendeguz@codanopy.com, and we will handle it by hand within 30 days. Deleting a report deletes its findings with it, and the link stops working.

If we get it wrong, you can complain to the Hungarian supervisory authority: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), Falk Miksa utca 9-11, 1055 Budapest, Hungary — naih.hu. If you live elsewhere in the EU you can complain to your own country's authority instead. We would rather you emailed us first.

Changes

If this policy changes, the date at the top changes with it. See also the Terms of Service and the plain-English summary of what we do with your code.

Adapted from the 37signals policies, used under CC BY 4.0.