Privacy Policy
Your account data and private work deserve clear boundaries.
Effective September 5, 2026 · CodeMerchant by Divide-By-0
CodeMerchant analyzes projects you deliberately submit. It keeps source handling narrow, records source-free findings, and gives you controls over scanning and retained account data.
1. Scope
This Privacy Policy covers CodeMerchant websites, accounts, GitHub connections, ZIP uploads, quality scans, valuation reports, remediation tools, and agent interfaces. It describes personal information practices and the separate handling of private source material.
2. Information you provide
Account data includes your email address, password verifier, optional Google identity, optional GitHub profile, and the Data License version and acceptance time. Organization context can include software you can license, company size, years in operation, and another software description. Submitted content includes ZIP filenames, private-repository identifiers, code, configuration, task-tracker exports, and Git history you choose to scan. Privacy requests and support details are also retained.
3. Information collected through use
CodeMerchant records installation and repository metadata, scan timing and status, API-token metadata, security events, derived quality metrics, valuations, finding categories and counts, relevant file paths, and exact commit hashes matched by the public-history check. Hosting infrastructure may create short-lived request, security, and performance logs.
4. How submitted source is processed
Private source and ZIP bytes are read in bounded Worker memory to produce a report. Raw file bodies, patches, matched personal values, credentials, and ZIP bytes are discarded after the request. Reports retain categories, counts, scopes, paths, and derived metrics. Repository code, CI workflows, and tests stay unexecuted.
5. Purposes
Information is used to authenticate accounts, connect requested sources, run selected quality and privacy checks, generate indicative valuations, create user-requested remediation pull requests, support coding-agent access, prevent abuse, troubleshoot failures, answer privacy requests, and improve reliability.
6. Service providers and external destinations
Codex Sites and its Cloudflare infrastructure host the application and D1 database. Google handles Google sign-in when chosen. GitHub handles repository authorization and remediation pull requests. Software Heritage receives exact Git commit hashes for archive-presence checks; repository names and source stay inside CodeMerchant. A configured agent reviewer receives metadata and aggregate signals only. Customer source is kept away from external PII and secret-scanning APIs.
7. Personal information sales and advertising
CodeMerchant sells no personal information and serves no behaviorally targeted advertising. A future transaction involving a project concerns the submitted asset under separately presented commercial terms; account personal information stays outside that asset unless you expressly approve its inclusion.
8. Legal bases and disclosures
Processing supports the service you request, account and system security, legal compliance, and legitimate product operations. Information may be disclosed when you direct a connection or remediation action, to infrastructure providers acting for CodeMerchant, during a corporate transaction with appropriate safeguards, or when law requires disclosure.
9. Retention
Account identifiers, Data License acceptance records, source metadata, and reports remain while the account is active or while needed for security, disputes, and legal obligations. Raw submitted source currently follows the ephemeral rule above. If CodeMerchant retains raw Submission Files for transaction evaluation and then declines them, operational copies are deleted within 30 days and protected backup or quarantine copies within 90 days. Source-free reports and agreement, audit, security, fraud-prevention, tax, and dispute records may remain as reasonably needed for those purposes. API tokens expire after 90 days. OAuth states expire after 10 minutes. Privacy requests remain as an accountability record.
10. Security
CodeMerchant uses encrypted GitHub tokens, hashed API tokens, salted password derivation, short-lived installation tokens, bounded scans, source-free reports, secure session cookies, and least-purpose data flows. Every system carries residual risk, so credentials found by a scan should be revoked and rotated before sharing a project.
11. Your choices and rights
You can select individual GitHub repositories, choose Scan all, use ZIP without GitHub, change GitHub App access, uninstall the App, sign out, and let tokens expire. Depending on location, you may request access, correction, export, deletion, restriction, or objection and may appeal a response through the same request channel. Identity verification protects account data before fulfillment.
12. International use and children
CodeMerchant infrastructure may process information in the United States and other locations used by its hosting providers. CodeMerchant is intended for adults and business users and is unavailable to children under 13.
13. Changes
Material updates will appear here with a revised effective date and, when appropriate, an in-product notice. Continued use after the effective date means the updated policy applies to later activity.
14. Data License, contact, and requests
The Data License governs submission, evaluation, ownership promises, acceptance, payment, and any later commercial transaction. Submit a secure account-linked request for access, correction, export, deletion, or another privacy question.