Privacy Policy
This policy explains what personal data ScanDrix AI Inc. collects, why we collect it, who we share it with, how long we keep it, and what you can require us to do about it.
1.Who we are and what this covers
ScanDrix AI Inc. (“ScanDrix”, “we”) provides a code review and security analysis service. This policy covers our marketing website, the hosted review service, and our self-hosted deployments.
For personal data in your source code, commits, and account, you are the controller and we are the processor acting on your instructions. For our own business data — billing, marketing, and support administration — we are the controller. Where we act as a processor, the terms in our Data Processing Addendum apply and take precedence over this policy for that data.
2.What we collect
Account and organisation data
Your name, work email, organisation, workspace members, role, and authentication records. If you sign in with a Git provider, we receive the identity and email address that provider returns and store the provider token to read repository and pull request content on your behalf.
Customer content
Pull request diffs, file contents, commit metadata, and repository structure are transmitted to us when you connect a Git provider or run the CLI. Review output — findings, rules, suggested patches — is generated from that content and stored so you can act on it later.
Billing data
Plan, billing name and email, transaction identifiers, and invoice records. Full payment card details are handled by our payment processor and never reach our servers.
Website data
If you submit the contact form we receive the name, email, company, team size, and message you provide. If you use the website chat assistant, we transmit your message text — with anything matching a credential pattern redacted — to a third-party model provider to generate a reply. We do not store that exchange ourselves. Chat assistant text is not used to train any model.
Analytics
Product analytics run only if you consent. Until you consent we do not initialise the analytics client, and we honour the browser’s Do Not Track signal. Consent can be withdrawn at any time from the cookie banner.
Server logs
Our infrastructure records IP address, timestamp, request path, and response status for security, abuse prevention, and debugging.
3.What we do not do
- We do not use your source code, diffs, or review output to train, fine-tune, or evaluate any model, ours or a third party’s.
- We do not sell personal data, and we do not share it for anyone else’s advertising.
- We do not require a card to use the free plan or the public review demo.
4.Why we use it, and our legal bases
- Contract — to provide the service, run reviews, and bill you.
- Legitimate interests — security monitoring, fraud and abuse prevention, service reliability, and responding to enquiries. We balance these against your interests and stop where the impact becomes significant.
- Consent — optional product analytics. You can withdraw it without affecting the rest of the service.
- Legal obligation — retaining invoices and tax records.
5.Who we share it with
We share personal data only with vendors that need it to deliver the service, and only for the purpose listed. The current list — with the exact data each receives and the region it operates in — is published on our subprocessors page. In summary: payment processing, optional product analytics, model inference for the website chat assistant, and Git hosting providers for repository access.
None of these vendors receive your source code as part of the review pipeline. Customers on self-hosted deployments run the full stack inside their own network, so no ScanDrix subprocessor handles their code at all.
We also disclose data if required by law or valid legal process, and will tell you unless legally prohibited from doing so.
6.How long we keep it
We keep data only as long as we need it for the purpose it was collected. Our default periods are:
Source code and pull request diffs submitted for review
Processed in memory for the review; not written to disk or database.
Review findings (title, file, line, rule, suggested patch)
Retained for the life of the workspace so you can act on and filter past findings. Deleted on workspace or account deletion.
Finding feedback you submit (helpful / not helpful, suppression memory)
Retained to suppress repeat false positives. Deletable on request.
Account and organisation records
Life of the account, then deleted within 30 days of closure.
Billing records and invoices
Retained as required by tax and accounting law in the billing region.
Audit logs (review execution, rule and admin changes)
Configurable per plan; default 12 months on paid plans.
Support correspondence
Retained 24 months after the last exchange.
Website analytics events (opt-in only)
PostHog default retention of 24 months, or shorter at your election.
Contact form submissions
Retained 12 months, then deleted.
7.Cookies and session storage
We set a session cookie to keep you signed in and a small non-sensitive cookie so the interface can render your name and plan before a server round trip. We do not set advertising cookies. The optional analytics cookie is only set after you consent.
8.International transfers
We are based in the United States and may process data in the United States and India. Where personal data leaves the EEA, UK, or Switzerland, we rely on an appropriate transfer mechanism, such as the Standard Contractual Clauses together with a transfer impact assessment.
If your compliance requirements mandate that processing stay within a specific jurisdiction, our self-hosted VPC and on-premise options keep data inside your own infrastructure.
9.Your rights
If you are in the EEA, UK, or Switzerland you have the right to access, correct, delete, restrict, or port your personal data, and to object to processing based on legitimate interests. You can also withdraw consent and lodge a complaint with your supervisory authority.
California residents have the right to know what personal data is collected, to request deletion, to correct inaccurate data, and to opt out of “sale” or “sharing” as those terms are defined by the CCPA/CPRA. We do not sell or share personal data as defined by those laws.
To exercise any of these rights, email privacy@scandrix.dev from the address on your account. We verify identity before acting on a request, aim to respond within 30 days, and will tell you if we need more information. If you are unhappy with the outcome you can escalate to our privacy contact or your regulator.
10.How we protect it
Encryption in transit, encryption at rest for persistent data, role-based access control on a least-privilege basis, audit logging of administrative actions, and segregated production environments. Access to customer data requires an authenticated account and is logged.
No system is perfectly secure. If a breach affects your personal data we will investigate, notify you and the relevant authority within the legally required timeframe, and describe what was affected and what we did about it.
11.Children
The service is intended for organisations and adults. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
12.Changes to this policy
We update this policy when our practices change. Material changes are announced by email to workspace administrators and in-product before they take effect, and the updated date at the top of this page always reflects the current version.
13.Contact
Questions, requests, or complaints about this policy can go to privacy@scandrix.dev.