Privacy Policy

Last updated October 1, 2026

DebtDraft (“DebtDraft,” “we,” “us,” or “our”) provides a GitHub Action and hosted dashboard that scans pull requests for code health signals (complexity, test coverage, duplication, outdated dependencies, and known vulnerabilities) and displays the results over time. This Privacy Policy explains what personal data we collect, why, and what rights you have over it.

If you have questions about this policy or want to exercise any of the rights described below, contact us at support@debtdraft.dev.

1. What We Collect

We collect the following, all through GitHub's OAuth sign-in and your own use of the Service. We never ask you to fill out a separate registration form:

CategoryWhatSource
GitHub identityUsername, display name, avatar URL, email address (if your GitHub account exposes one), GitHub account IDGitHub, at sign-in
GitHub authorizationAn OAuth access token and refresh token scoped to repo access (see Section 2)GitHub, at sign-in
Repository dataRepository ID, name, default branch, and public/private status for repositories you choose to connectGitHub, when you connect a repo
API keysA one-way cryptographic hash of each API key you generate (the plaintext key is shown to you once and never stored by us)Generated by you in the dashboard
Scan resultsPull request number, commit SHA, health scores, and a capped set of findings (file paths, function names, dependency names and versions, vulnerability advisory IDs)The GitHub Action, when it runs against your pull requests
Session cookiesEncrypted, httpOnly session cookies that keep you signed inSet by our authentication provider (Supabase)
Billing and subscription statusYour subscription plan, status (e.g. active, cancelled), renewal date, and an identifier linking your account to our payment processor's records. We do not receive or store your card number or other payment card data; our payment processor handles that directly (see Section 4)Our payment processor (Polar), when you subscribe or your subscription changes

We do not collect or store your payment card details. If you subscribe to a paid plan, your payment is handled entirely by our payment processor, Polar; see Sections 4 and 8 for what we receive from them instead. We do not run any analytics, advertising, or behavioral-tracking scripts (no Google Analytics, no Meta Pixel, no session-replay tools). We checked our own codebase to confirm this before writing this sentence, and it stays true only for as long as we don't add one later without updating this policy first.

We do not collect your repositories' source code contents as personal data. Scan findings store file paths and computed metrics, not code.

2. About the repo Permission Scope

When you sign in, GitHub asks you to authorize DebtDraft with the repo scope. This is a broad scope: it lets DebtDraft's servers read (not write) both public and private repositories you own, using your GitHub access token, for the sole purpose of listing your repositories so you can choose which ones to connect for scanning. We do not use this access for anything else, and we do not access repository contents through this token. Only the GitHub Action you install yourself, running in your own GitHub Actions environment, reads your code to perform the scan.

3. How We Use Your Data

  • To authenticate you and maintain your session (necessary to perform our contract with you)
  • To let you connect repositories and generate API keys (necessary to perform our contract with you)
  • To receive, store, and display scan results and their trend over time (necessary to perform our contract with you)
  • To operate, secure, and improve the Service, including detecting abuse and debugging errors (our legitimate interest in running a secure, working service)

We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.

4. Who We Share Data With

We share data only with the service providers that run our infrastructure, each acting under their own security and privacy commitments:

  • Supabase: database, authentication, and storage of the data described in Section 1
  • Vercel: hosting for the dashboard and API
  • GitHub: the identity provider and the platform your Action runs on
  • Polar (Polar Software Inc.): our payment processor and merchant of record for paid plans. If you subscribe, Polar and its payment partner Stripe collect and process your payment card details, billing address, and email directly; we never receive or store your card number. As merchant of record, Polar acts as the seller for tax and payment-compliance purposes and handles the transaction under its own privacy policy
  • Cloudflare and Google (Gmail): if you email us, Cloudflare forwards the message sent to our support address and Google hosts the mailbox that receives it

When a scan checks your dependencies against public vulnerability databases or checks for outdated packages, only public package names and version numbers are sent, never your repository name, code, or any personal data.

5. International Data Transfers

Our infrastructure is hosted in India (Supabase and Vercel, ap-south-1/bom1 regions) and we operate from Pakistan; GitHub's servers are in the United States. Using DebtDraft means your data is processed in these countries, which may have different data protection laws than your own. We rely on our service providers' own security, contractual, and compliance measures to protect your data during this processing. Email you send us is forwarded by Cloudflare and stored by Google, whose servers may be located in other countries.

6. Data Retention

We keep your account data and scan history for as long as your account remains active, since past scans are what let you see your project's trend over time. If you request deletion (Section 8), we delete your account data within a reasonable period, except where we're required to keep limited records for security, fraud-prevention, or legal-compliance purposes.

7. Cookies

We use only the session cookies our authentication provider sets to keep you signed in. They are strictly necessary for the Service to function, are not used for tracking or advertising, and are exempt from cookie-consent requirements under GDPR/ePrivacy for that reason. We do not use a cookie-consent banner because we do not use any non-essential cookies.

8. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data (“right to erasure”)
  • Restrict or object to certain processing
  • Port your data to another service
  • Withdraw consent at any time, where processing is based on consent (you can also do this directly by revoking DebtDraft's GitHub OAuth authorization in your GitHub settings)
  • Lodge a complaint with your local data protection authority

California residents: we do not sell or share your personal information, and we have not done so in the preceding 12 months. You may still submit a request under Section 8 above.

9. Automated Scoring

Health scores and letter grades shown in the dashboard are computed automatically from your repository's code (complexity, coverage, duplication, dependency freshness, and known vulnerabilities). This is informational scoring about your codebase, not an automated decision that produces a legal or similarly significant effect about you as an individual.

10. Security

We use encrypted connections (HTTPS/TLS) throughout, store session tokens in httpOnly, Secure cookies inaccessible to page scripts, store API keys only as one-way hashes, and enforce strict data isolation between accounts at the database level so one team's data is never visible to another's.

11. Children's Privacy

DebtDraft is a developer tool not directed at, or intended for use by, individuals under 16. We do not knowingly collect data from children.

12. Changes to This Policy

We may update this policy as the Service changes. We'll update the “Last updated” date above, and for material changes, we'll provide a more prominent notice.

13. Governing Law

This policy is governed by the laws of Pakistan, without regard to conflict-of-law principles.

14. Contact