Privacy

Privacy policy

Last updated August 2026. Written in plain English on purpose — see our security page for more detail on exactly how your uploaded code is handled.

1. Who this policy covers

This policy applies to anyone who visits riskline.co or creates a Riskline account. It explains what we collect, why, who we share it with, how long we keep it, and the choices you have. If you have questions this page doesn't answer, email support@riskline.co.

2. What we collect

  • Account info: your email address, a display name you choose, and your password (stored hashed by our authentication provider — we never see or store it in plain text).
  • Your uploaded code, temporarily: when you start a scan, your zip file is extracted into an isolated sandbox to run the scan, then both the sandbox and the uploaded file are deleted immediately after — win, lose, or scan failure. We do not keep a copy of your source code.
  • Scan results: findings, severities, file paths (not file contents), grades, and the AI-generated explanations in your report — tied to your account so you can come back and view your history.
  • Billing information: if you subscribe to a paid plan, Stripe processes your payment directly. We receive a customer ID and your subscription status — never your card number.
  • Basic technical data: the kind any web app generates as a byproduct of running (session cookies to keep you signed in, standard request logs from our hosting infrastructure). We don't run advertising trackers or analytics that profile you across other sites.

3. Why we collect it

Strictly to run the product: authenticate you, run your scans, generate and store your reports, enforce plan quotas, process payments, and email you things like magic links or billing receipts. We don't use your data for advertising, and we don't build profiles of you to sell to anyone.

4. Who we share it with

Only the infrastructure that runs the product itself, each scoped to only what it needs to do its job: Supabase (database, authentication, and temporary file storage), Anthropic (generating the plain-English explanations in your report — see below), Stripe (billing), Trigger.dev (scheduling scan jobs), and our hosting provider. We don't sell your data, and we don't share it with anyone for advertising or marketing purposes. We may disclose information if legally required to (for example, a valid court order), but we're not in the business of handing out user data and will push back on anything that looks overbroad.

5. How AI is used, specifically

The plain-English explanations in your report are generated by sending the specific finding — and a small surrounding code snippet, where relevant — to Claude (Anthropic). That's the only use. Your code is never used to train or fine-tune any model, ours or anyone else's. When our secret scanner finds something like an exposed API key, the actual secret value is redacted before it's stored or sent anywhere in our pipeline, including to the AI model — we tell you where the problem is, not what the secret was.

6. How long we keep it

Uploaded code: deleted immediately after each scan, every time. Scan results and account data: kept for as long as your account is active, so your history stays available to you. If you delete your account, we delete the associated data within a reasonable period, except where we're required to retain records (for example, billing records, for tax and accounting purposes).

7. Your rights

You can access, export, or delete your account data at any time. Most of it — your name and scan history — you can already see and manage directly in your account settings and dashboard. For anything else, including full account deletion, email us at support@riskline.co and we'll take care of it directly. If you're in the EU/UK, this includes the rights available to you under GDPR (access, rectification, erasure, portability, and objection); if you're a California resident, this includes the rights available to you under the CCPA/CPRA.

8. Cookies

We use a small number of strictly-necessary cookies to keep you signed in between visits, plus one first-party analytics cookie (PostHog) that helps us understand how the product gets used. We don't use third-party advertising or cross-site tracking cookies, and this data is never sold or shared with ad networks.

9. International data transfers

Our infrastructure providers (Supabase, Anthropic, Stripe, and our hosting provider) operate in the United States. If you're accessing Riskline from outside the US, your data will be processed there.

10. Children's privacy

Riskline isn't directed at children, and we don't knowingly collect information from anyone under 16. If you believe a child has created an account, email us and we'll remove it.

11. Changes to this policy

If we make material changes to this policy, we'll update the date below and, for significant changes, notify you by email.

Contact

Questions about this policy or your data: support@riskline.co.