Privacy Policy
Last updated October 1, 2026DebtDraft (“DebtDraft,” “we,” “us,” or “our”) provides a GitHub Action and hosted dashboard that scans pull requests for code health signals (complexity, test coverage, duplication, outdated dependencies, and known vulnerabilities) and displays the results over time. This Privacy Policy explains what personal data we collect, why, and what rights you have over it.
If you have questions about this policy or want to exercise any of the rights described below, contact us at support@debtdraft.dev.
1. What We Collect
We collect the following, all through GitHub's OAuth sign-in and your own use of the Service. We never ask you to fill out a separate registration form:
| Category | What | Source |
|---|---|---|
| GitHub identity | Username, display name, avatar URL, email address (if your GitHub account exposes one), GitHub account ID | GitHub, at sign-in |
| GitHub authorization | An OAuth access token and refresh token scoped to repo access (see Section 2) | GitHub, at sign-in |
| Repository data | Repository ID, name, default branch, and public/private status for repositories you choose to connect | GitHub, when you connect a repo |
| API keys | A one-way cryptographic hash of each API key you generate (the plaintext key is shown to you once and never stored by us) | Generated by you in the dashboard |
| Scan results | Pull request number, commit SHA, health scores, and a capped set of findings (file paths, function names, dependency names and versions, vulnerability advisory IDs) | The GitHub Action, when it runs against your pull requests |
| Session cookies | Encrypted, httpOnly session cookies that keep you signed in | Set by our authentication provider (Supabase) |
| Billing and subscription status | Your subscription plan, status (e.g. active, cancelled), renewal date, and an identifier linking your account to our payment processor's records. We do not receive or store your card number or other payment card data; our payment processor handles that directly (see Section 4) | Our payment processor (Polar), when you subscribe or your subscription changes |
We do not collect or store your payment card details. If you subscribe to a paid plan, your payment is handled entirely by our payment processor, Polar; see Sections 4 and 8 for what we receive from them instead. We do not run any analytics, advertising, or behavioral-tracking scripts (no Google Analytics, no Meta Pixel, no session-replay tools). We checked our own codebase to confirm this before writing this sentence, and it stays true only for as long as we don't add one later without updating this policy first.
We do not collect your repositories' source code contents as personal data. Scan findings store file paths and computed metrics, not code.
2. About the repo Permission Scope
When you sign in, GitHub asks you to authorize DebtDraft with the repo scope. This is a broad scope: it lets DebtDraft's servers read (not write) both public and private repositories you own, using your GitHub access token, for the sole purpose of listing your repositories so you can choose which ones to connect for scanning. We do not use this access for anything else, and we do not access repository contents through this token. Only the GitHub Action you install yourself, running in your own GitHub Actions environment, reads your code to perform the scan.
3. How We Use Your Data
- To authenticate you and maintain your session (necessary to perform our contract with you)
- To let you connect repositories and generate API keys (necessary to perform our contract with you)
- To receive, store, and display scan results and their trend over time (necessary to perform our contract with you)
- To operate, secure, and improve the Service, including detecting abuse and debugging errors (our legitimate interest in running a secure, working service)
We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.
5. International Data Transfers
Our infrastructure is hosted in India (Supabase and Vercel, ap-south-1/bom1 regions) and we operate from Pakistan; GitHub's servers are in the United States. Using DebtDraft means your data is processed in these countries, which may have different data protection laws than your own. We rely on our service providers' own security, contractual, and compliance measures to protect your data during this processing. Email you send us is forwarded by Cloudflare and stored by Google, whose servers may be located in other countries.
6. Data Retention
We keep your account data and scan history for as long as your account remains active, since past scans are what let you see your project's trend over time. If you request deletion (Section 8), we delete your account data within a reasonable period, except where we're required to keep limited records for security, fraud-prevention, or legal-compliance purposes.
8. Your Rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data (“right to erasure”)
- Restrict or object to certain processing
- Port your data to another service
- Withdraw consent at any time, where processing is based on consent (you can also do this directly by revoking DebtDraft's GitHub OAuth authorization in your GitHub settings)
- Lodge a complaint with your local data protection authority
California residents: we do not sell or share your personal information, and we have not done so in the preceding 12 months. You may still submit a request under Section 8 above.
9. Automated Scoring
Health scores and letter grades shown in the dashboard are computed automatically from your repository's code (complexity, coverage, duplication, dependency freshness, and known vulnerabilities). This is informational scoring about your codebase, not an automated decision that produces a legal or similarly significant effect about you as an individual.
10. Security
We use encrypted connections (HTTPS/TLS) throughout, store session tokens in httpOnly, Secure cookies inaccessible to page scripts, store API keys only as one-way hashes, and enforce strict data isolation between accounts at the database level so one team's data is never visible to another's.
11. Children's Privacy
DebtDraft is a developer tool not directed at, or intended for use by, individuals under 16. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this policy as the Service changes. We'll update the “Last updated” date above, and for material changes, we'll provide a more prominent notice.
13. Governing Law
This policy is governed by the laws of Pakistan, without regard to conflict-of-law principles.