Privacy. There is not much of your personal data here to have a policy about.
Last updated 24 August 2026. This page is about personal data. What happens to your plan and your infrastructure is a longer and more interesting document: data handling.
What we hold about a person
Three things, and one of them only if you write to us.
- Your GitHub account login and numeric id. Recorded when the App is installed, because an installation belongs to an account. The numeric id is the identity; the login is a column, so that a page can say whose installation it is.
- Repository names, pull request numbers and commit shas. The address of the thing being reviewed. A pull request number is personal data in the sense that it is attached to your work, so it is listed here rather than argued about.
- Whatever is in an email you send us. Support, a security report, a question about pricing. Held in a mailbox, not in the product.
There are no accounts to create, no passwords, no profile, no marketing list and no analytics of any kind. This website makes no external request and runs no script, so reading it tells us nothing.
Cookies
This website sets none. The only cookie in the product is on the
sign-in page where you issue an upload token: one encrypted cookie
holding your GitHub access token, valid for two hours, marked
httpOnly and SameSite=Lax. It is strictly
necessary for signing in and there is nothing to consent to, because
there is nothing else.
There is no sessions table, so a stolen database backup contains no sessions. The cost of that, stated plainly on the data handling page, is that a session cannot be revoked before it expires — which is why it is two hours.
Why we hold it, and for how long
To operate the product you asked for: to know which account an installation belongs to, to post a comment on the right pull request, and to answer you when you write to us. Not for advertising, profiling or resale, none of which this product has any mechanism for.
Runs and findings are deleted after 30 days. Account rows last as long as the installation does. Uninstalling deletes all of it immediately.
Who else sees it
The list of subprocessors, what each receives and which are in use today is a table on the data handling page rather than a second copy here. Nobody outside that table receives anything, and none of them receives your data for their own purposes.
What you can ask for
- A copy of what we hold. Email, and you get it. The honest answer is usually one row about your installation and a list of recent runs.
- Deletion. Uninstall the App and it happens without asking anyone. If you would rather we did it, ask.
- Correction. Almost everything we hold is copied from GitHub, so the fix is usually there. Ask if it is not.
No form and no verification hoop: security@blastradiusapp.com, from the address on the account, is enough.
The unsettled part
The same two things the terms name, because they decide which data-protection law applies and who the controller is.
- Which legal entity you are contracting with. Today BlastRadius is one person, not a company.
- Which country’s law governs these terms, and where a dispute would be heard.
Until they are settled, the operator of BlastRadius is the controller of the data above, and the address on this page reaches them directly.