Privacy Policy

Last updated: March 2025

Overview

Aegis ("we", "our") provides security scanning for AI-generated code. We are committed to protecting your privacy. This policy describes what information we collect, how we use it, and your choices.

Information we collect

  • Account and sign-in: When you register or sign in (e.g. email/password or GitHub), we store your email, name if provided, and account identifiers.
  • GitHub: If you connect GitHub, we store which repositories you connect and branch names. We do not store your source code except as needed temporarily to run scans (e.g. sending file content to our scanning service for analysis).
  • Scan metadata: We store repo and branch references, scan status, and findings (file path, line, severity, description). This lets you view results in the dashboard.
  • Support and contact: If you use our contact form or support channels, we collect the email and message content you submit.

How we use information

We use the information above to provide the service (scanning, dashboard, authentication), respond to support requests, improve the product, and comply with legal obligations. We do not sell your personal data.

Data storage and security

Data is stored using industry-standard hosting (e.g. Supabase, Vercel). We retain account and scan data for as long as your account is active or as needed to provide the service. We apply reasonable security measures to protect data in transit and at rest.

Cookies and similar technology

We use session and authentication cookies to keep you signed in and to operate the site. We do not use third-party advertising cookies.

Third parties

We use third-party services that may process data on our behalf: GitHub (for OAuth and repository access), Stripe (for payments, if you subscribe), and email providers (e.g. for contact form or transactional email). Each has its own privacy policy: GitHub, Stripe.

Your rights

You may request access to, correction of, or deletion of your personal data. You can disconnect GitHub and remove connected repos from the dashboard. To exercise your rights or ask questions, contact us via our contact page.

Changes

We may update this policy from time to time. We will post the updated policy here and update the "Last updated" date. Continued use of the service after changes constitutes acceptance of the revised policy.