Privacy Policy
1. What we collect
| Category | What | Why |
|---|---|---|
| Account | Email address; display name and avatar (optional); the sign-in providers you connect (GitHub, Google) and the identifiers they return | To create and secure your account and sign you in |
| Code you submit | Source code you upload as a .zip, a public Git URL you paste, or the contents of a GitHub repository you connect read-only | To run the security scan you requested |
| Payment | Handled by Stripe. We receive confirmation of payment and limited billing metadata; we never see or store your full card number | To process paid scans, credits, and subscriptions |
| Usage & technical | IP address, request logs, and a strictly-necessary session cookie; the scan reports and credit history tied to your account | To operate the service, prevent abuse, and let you return to your reports |
2. How your code is handled
- Uploaded code is processed in an isolated, sandboxed environment whose network access is locked down to what the analysis requires.
- During AI review, relevant portions of your code are processed by our AI provider (Anthropic) to generate findings. Your code and findings are never used to train any AI model, ours or a third party's.
- Your submitted code is kept for as long as the scan itself lives — 7 days on the Free tier, 30 days on paid tiers — and is deleted together with the report when the scan expires. We keep it that long because features you may run later, including the auto-fix, need the code on hand to rewrite it and re-scan the result. Deleting a scan deletes its code immediately.
3. How long we keep things
- Submitted code and reports: kept 7 days on the Free tier and 30 days on paid tiers, then deleted together when the scan expires — or deleted immediately when you choose to delete a scan.
- Account & billing records: kept while your account is open; billing/credit records may be retained as required for tax and accounting.
- You can delete your account at any time, which removes your data as described in Section 6.
4. Who we share with (subprocessors)
We do not sell your data. We share it only with the service providers we need to operate Scout:
- Stripe — payment processing
- Anthropic — the AI models that perform the code review
- Resend — transactional email (sign-in links, scan-complete notices)
- Hosting & infrastructure — Netlify (website), Hetzner (application & analysis servers), Cloudflare (DNS)
- Cloudflare Web Analytics — cookieless traffic measurement, loaded only if you opt in to analytics (see Section 5)
- GitHub, Google — only if you use them to sign in
We may also disclose information if required by law or to protect the rights, safety, or property of Scout, our users, or others.
5. Cookies
The only cookies Scout sets are strictly necessary — a session cookie to keep you signed in and a CSRF-protection token. We do not use advertising or cross-site tracking cookies.
We also offer optional analytics: Cloudflare Web Analytics, which measures page traffic without cookies and without fingerprinting you or following you across other sites. It is off until you turn it on — it loads only after you choose "Accept" on our cookie banner. Choosing "Reject non-essential" means the analytics script is never loaded at all, and you can change your mind at any time from Cookie settings in the footer of any page.
6. Your rights & choices
- Access & export: download your account data (scans, credit history, identities) from your account.
- Delete: delete individual reports, or delete your entire account, which removes your scans, reports, and associated data.
- Depending on where you live (e.g. the EU/UK under GDPR, or California under the CCPA), you may have additional rights to access, correct, or erase your data, or to object to certain processing. Email questions@dimsylaisolutions.com and we will honor valid requests.
7. Security
We protect your data with encryption of sensitive tokens at rest, tenant isolation (row-level security so one account cannot access another's data), sandboxed analysis, and least-privilege access. No system is perfectly secure, but security is the core of what we do and we treat it accordingly. To report a vulnerability, see our responsible disclosure policy.
8. Children
Scout is not directed to, and not intended for, anyone under 18. We do not knowingly collect data from children.
9. International users
Scout is operated from the United States and your data is processed there and in the regions our providers operate. By using Scout you understand your data may be transferred to and processed in the United States.
10. Changes
We may update this policy as Scout evolves. Material changes will be reflected here with a new effective date; significant changes may also be emailed to you.
11. Contact
DIMSYL AI SOLUTIONS LLC — general privacy questions: questions@dimsylaisolutions.com. Security reports: security@dimsylaisolutions.com.