Privacy

Privacy policy

Last updated August 26, 2026. Written in plain English on purpose, see our security page for more detail on exactly how your uploaded code is handled.

1. Introduction & who we are

Welcome to Riskline ("we," "our," or "us"). We provide an AI-assisted security scanner for codebases. Because you are trusting us with your code, our system is built on data minimization and zero code retention by design.

Under the General Data Protection Regulation (GDPR), Riskline is the Data Controller for the personal data described in this policy. The Service is operated by Leontios Konstantinidis, based in Greece, an EU member state, so the Article 27 GDPR requirement to appoint an EU representative does not apply to us. We have not been required to appoint a Data Protection Officer under Article 37 GDPR, as we do not carry out large-scale systematic monitoring or large-scale processing of special-category data. For UK users, we have not separately appointed a UK GDPR Article 27 representative as of this writing; UK privacy requests are handled through the same contact below, and we will appoint one if our processing of UK data subjects' data reaches a scale where that becomes required.

Our services are not intended for, and we do not knowingly collect personal data from, children under 16. If we learn we have collected personal data from a child under 16 without appropriate parental consent, we will delete it promptly. If you believe a child has provided us data, contact us at support@riskline.co.

2. Zero-code-retention & the scanning process

Our core promise to you is that we do not keep your source code. Here is exactly what happens when you upload a codebase or connect a repository:

  • Upload & extraction: Your code is securely transferred to an isolated, sandboxed temporary environment on our compute infrastructure.
  • Deterministic scanning: We run established security tools over the code to identify vulnerabilities.
  • Secret redaction: If our tools discover credentials or API keys, the raw value is redacted in memory before it is stored or sent anywhere else, including to our AI sub-processor. The raw secret never reaches our database, is never sent to our AI models, and never appears in your report.
  • Immediate deletion: The moment your scan completes, whether it succeeds, fails, or errors partway through, the uploaded code and the extracted files are deleted from our storage and memory.

3. AI processing, automated analysis & how data is shared

We separate detection (done deterministically by established security tools) from explanation (done by AI). For transparency, and consistent with the EU AI Act's transparency principles for AI-generated content, the plain-English explanations, risk narratives, and suggested fixes in your report are AI-generated based on the deterministic tool output described above; they are not independently verified findings unless our documentation states otherwise, and they do not constitute an automated decision about you personally within the meaning of Article 22 GDPR (they describe your code, not you).

The data we share with our AI sub-processor (Anthropic) depends on your subscription tier:

  • Free & Guardian tiers: finding metadata (engine name, severity, file path, line number), the redacted engine output, and, for specific findings, a small surrounding code snippet for context.
  • Guardian Pro (deep review): to identify complex logic flaws such as race conditions and prompt-injection risks, we send up to 60 KB of raw source files from your repository.

Under our commercial agreement with Anthropic, your code and snippets are contractually excluded from being used to train or fine-tune their models.

4. Data we collect & retain

Aside from transient code uploads, we collect and retain the categories below, processed on the legal bases of contractual necessity (to provide the account and features you sign up for), your consent (for optional analytics), and our legitimate interest in operating a secure, reliable service (for security telemetry):

  • Account data: Email address, full name, and hashed password. Retained for the life of your account.
  • Scan reports: File paths, line numbers, AI explanations, and letter grades. This reveals your project structure, but not the file contents. Retained for as long as your account is active, because scan history and grade-over-time tracking are part of the Service you've asked us to provide (a paid feature on the Guardian tier); deleted when you delete the scan or your account.
  • Billing data: Processed directly by Lemon Squeezy, our merchant of record. We only store your subscription tier and Lemon Squeezy customer ID.
  • Telemetry & analytics: Usage data, error logs, and IP addresses to secure and improve the platform, and (only with your opt-in consent) first-party product analytics.

5. Sub-processors we use

To provide Riskline, we rely on trusted third-party service providers (sub-processors). Where data is transferred outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) and other adequate safeguards recognized under GDPR Chapter V.

  • Supabase (EU/US): Postgres database, user authentication, and ephemeral zip storage.
  • Anthropic (US): AI interpretation of findings.
  • Fly.io (EU, Frankfurt): Containerized, ephemeral compute infrastructure where scans execute.
  • Vercel (global edge): Hosting for our web application and edge routing.
  • Lemon Squeezy (US): Subscription and payment processing, as our merchant of record.
  • Trigger.dev (US/EU): Background job orchestration (receives scan IDs only).
  • Semgrep & OSV.dev (US): Scan-time outbound queries for rule registries and vulnerability data (dependency names and versions).
  • Upstash (global): Redis-based API rate limiting and abuse prevention.
  • PostHog (US/EU): First-party product analytics, opt-in only, to understand platform usage.
  • Sentry (US): Error tracking and system diagnostics.
  • Zoho (EU): Transactional SMTP emails for account notifications.

We will keep this list current. If we add a sub-processor that materially changes how your data is handled, we will update this page and, for significant changes, notify active users by email or in-app notice.

If you use the Service on behalf of an organization and need a signed Data Processing Addendum for your own compliance program, one is available on request; see Section 19 of our Terms of Service.

6. Cookies & trackers

We use essential cookies (via Supabase) that are strictly necessary to keep you logged into the application. We also use analytics cookies (via PostHog) to understand how users interact with our site. Analytics cookies are only set if you provide your prior opt-in consent via our cookie banner, and you can withdraw that consent at any time from your account settings. For full detail, including cookie duration and categories, see our Cookie Policy.

7. Data security & breach notification

We apply technical and organizational measures designed to protect your data, described in full on our Security Details page, including sandboxed processing, secret redaction, database-level access control (Row Level Security), least-privilege service credentials, and encryption of data in transit. Access to production data by personnel is restricted to what is needed to operate and support the Service and is not granted by default.

No system is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that poses a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required by Article 33 GDPR, and will notify affected users without undue delay where the breach is likely to result in a high risk to you, as required by Article 34 GDPR.

8. Your GDPR rights

If you are located in the European Economic Area (EEA) or the UK, you have the following rights regarding your personal data:

  • Right to access: You can view all your scans, reports, and account data directly in our dashboard.
  • Right to rectification: You can update your name and email address in your account settings.
  • Right to erasure (right to be forgotten): You can permanently delete your account and associated scan data via the self-service delete option.
  • Right to data portability: You may request an export of your account data and scan history by emailing us.
  • Right to restrict or object: You can turn analytics tracking off at any time in your account settings, or object to specific processing by contacting us.

To exercise any of these rights, please email support@riskline.co. We may ask you to verify your identity (for example, by emailing from your account's registered address) before acting on a request, to make sure we don't hand your data to someone else. We will respond to all requests within 30 days. You also have the right to lodge a complaint with your local Data Protection Authority (in Greece, the Hellenic Data Protection Authority).

9. Your California & US state privacy rights

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you the right to know what personal information we collect, request its deletion or correction, and opt out of any "sale" or "sharing" of personal information, without discrimination for exercising these rights.

We do not sell your personal information for money, and we do not use it for cross-context behavioral advertising. Our only analytics processing (PostHog) is first-party, opt-in, and used solely to understand product usage, which we do not believe constitutes a "sale" or "sharing" under the CCPA; if our practices change, we will update this section and provide an opt-out.

To exercise a California (or other US state) privacy right, email support@riskline.co. We may need to verify your identity before acting on the request. Residents of other US states with comparable privacy laws (for example Virginia, Colorado, Connecticut) may exercise the equivalent rights under those laws through the same contact.

10. Account deletion & data retention exceptions

You can delete your account at any time via your account settings. This action initiates a cascading deletion of your profile, all scan history, findings, and reports.

Exceptions (legitimate interests): When you delete your account or submit an in-app feedback widget, we retain the feedback message, the stated reason for deletion, and your associated email address for up to 36 months from the date of deletion, processed under our legitimate interest in understanding churn and improving our product, after which it is deleted or anonymized. You may object to this processing at any time by contacting us; we will honor objections unless we have a compelling legitimate ground that overrides your interests, or need to retain limited data for a shorter or longer period to comply with a legal obligation (for example, financial records required by tax law, which we retain only as long as that law requires).

11. International users

The Service is operated from Greece and the European Union. If you access the Service from outside the EEA, you understand your data will be transferred to and processed in the EEA and in the countries of our sub-processors listed above, under the safeguards described there.

12. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by an updated "Last updated" date, and where changes significantly affect your rights, we will provide additional notice (email or in-app).

Contact

Questions about this policy or your data: support@riskline.co.