foretop

Legal

Privacy policy

What the hosted service stores, why it stores it, and how long it keeps it.

1. The scanners send nothing

Ebb, Telltale, Charter and Lading run entirely on your machine or in your own CI. They read the repository you point them at and print a result. They contact no Foretop server, require no account, and transmit nothing — unless you explicitly pass --report with a token for a hub you configured. Using them anonymously is not a concession; it is the only mode there is.

2. Who the controller is

For Foretop Hub, the data controller is Nicolas Mitchell, sole trader (entreprise individuelle), registered at 35 rue de l’Aigle, 92250 La Garenne-Colombes, France, under SIREN 817 535 081, reachable at support@foretop.dev. Paddle.com Market Ltd is a separate controller for payment data — see Paddle's privacy notice. Foretop never receives or stores card details.

3. What the hub stores

Account data

Your GitHub-authenticated identity through Supabase: a user identifier, and the email address and display name returned at first sign-in. Organisation name, member roles, and API token hashes — never the token itself, which is shown once and stored only as a hash.

Scan results you send

Findings, their evidence (a file path, a line, a content hash, and the matched text), issue groups, baselines and suppressions, plus the repository and commit each run came from. Foretop does not receive your source code — a finding carries a path and a line reference, not the file. The matched text is the specific thing the check recognised, such as a model identifier, a route template or a package name, never the surrounding line.

Operational data

Request metrics and error logs. Tokens, signed URLs, document bodies and prompts containing customer text are never logged; that is an invariant of the codebase, not a policy preference.

4. How long it is kept

Run history is kept for the life of your organisation. Finding-level detail expires on a plan-dependent window — 30 days on the free tier — after which the detail is deleted while the history and trends remain. Deleting a subscription does not delete data; deletion is a separate, explicit request that removes the organisation and everything under it.

5. Who else sees it

Only the infrastructure needed to run the service: Google Cloud (hosting, in the EU), Supabase (database and authentication), Resend (email digests you opt into), and Paddle (payments). Your data is not sold, not shared with advertisers, and not used to train models.

One feature sends data to a further processor, and only when you ask it to. Charter semantic review, available to Team organisations, sends the tool declarations you submit to OpenAI for analysis. It never runs on its own: you paste the declarations, the minimised text that would be sent is shown to you first, and nothing leaves until you confirm it. Server names, commands, URLs, environment-variable names and schema defaults are removed before sending. Requests are made with retention disabled, so OpenAI does not use them to train models, though it may retain them briefly for its own abuse monitoring. This processing may take place outside the EU. No scan result, finding or repository content is ever sent this way — only declarations you paste yourself.

6. Your rights

You may request access to, correction of, export of, or deletion of your data. Export is self-service from the product; the rest is handled by a request. Do not include secrets or customer data in a public channel.

7. Cookies

The hub sets one cookie: a signed session cookie after you sign in. There is no analytics, advertising or third-party tracking on this site or in the product.