Legal
Privacy policy
What the hosted service stores, why it stores it, and how long it keeps it.
1. The scanners send nothing
Ebb, Telltale, Charter and Lading run entirely on your machine or in your
own CI. They read the repository you point them at and print a result. They contact no
Foretop server, require no account, and transmit nothing — unless you explicitly pass
--report with a token for a hub you configured. Using them anonymously is
not a concession; it is the only mode there is.
2. Who the controller is
For Foretop Hub, the data controller is Nicolas Mitchell, sole trader (entreprise individuelle), registered at 35 rue de l’Aigle, 92250 La Garenne-Colombes, France, under SIREN 817 535 081, reachable at support@foretop.dev. Paddle.com Market Ltd is a separate controller for payment data — see Paddle's privacy notice. Foretop never receives or stores card details.
3. What the hub stores
Account data
Your GitHub-authenticated identity through Supabase: a user identifier, and the email address and display name returned at first sign-in. Organisation name, member roles, and API token hashes — never the token itself, which is shown once and stored only as a hash.
Scan results you send
Findings, their evidence (a file path, a line, a content hash, and the matched text), issue groups, baselines and suppressions, plus the repository and commit each run came from. Foretop does not receive your source code — a finding carries a path and a line reference, not the file. The matched text is the specific thing the check recognised, such as a model identifier, a route template or a package name, never the surrounding line.
Operational data
Request metrics and error logs. Tokens, signed URLs, document bodies and prompts containing customer text are never logged; that is an invariant of the codebase, not a policy preference.
4. How long it is kept
Run history is kept for the life of your organisation. Finding-level detail expires on a plan-dependent window — 30 days on the free tier — after which the detail is deleted while the history and trends remain. Deleting a subscription does not delete data; deletion is a separate, explicit request that removes the organisation and everything under it.
5. Who else sees it
Only the infrastructure needed to run the service: Google Cloud (hosting, in the EU), Supabase (database and authentication), Resend (email digests you opt into), and Paddle (payments). Your data is not sold, not shared with advertisers, and not used to train models.
One feature sends data to a further processor, and only when you ask it to. Charter semantic review, available to Team organisations, sends the tool declarations you submit to OpenAI for analysis. It never runs on its own: you paste the declarations, the minimised text that would be sent is shown to you first, and nothing leaves until you confirm it. Server names, commands, URLs, environment-variable names and schema defaults are removed before sending. Requests are made with retention disabled, so OpenAI does not use them to train models, though it may retain them briefly for its own abuse monitoring. This processing may take place outside the EU. No scan result, finding or repository content is ever sent this way — only declarations you paste yourself.
6. Your rights
You may request access to, correction of, export of, or deletion of your data. Export is self-service from the product; the rest is handled by a request. Do not include secrets or customer data in a public channel.
7. Cookies
The hub sets one cookie: a signed session cookie after you sign in. There is no analytics, advertising or third-party tracking on this site or in the product.