Skip to content

Privacy Policy

Last updated 22 July 2026.

This page describes what the MCP Upgrade hosted service does with data. It describes the behaviour the software actually implements, not an aspiration.

Source code you submit

By uploading a ZIP file or submitting a public repository address, the following happens:

We do not retain your source code after a scan completes. We do retain the resulting report, which contains file paths, line numbers and short excerpts of the matched source.

Excerpts in reports

A report includes a short excerpt of each matched line so the finding is intelligible. Those excerpts pass through credential redaction before they are stored: recognised token shapes, private keys and credential-shaped assignments are replaced. Redaction is pattern-based and is not a guarantee. Treat a report as containing fragments of your source, and do not upload code whose fragments you would not be willing to store.

Public repositories

When you submit a public GitHub repository we resolve it to a specific commit and download that commit’s archive over HTTPS. We store the normalised repository address, the owner and repository name, and the commit identifier. We do not run git clone, do not fetch submodules, do not download large-file-storage objects and do not execute repository hooks.

Account data

We store your email address, an optional display name, and timestamps. Authentication is handled by Supabase. Your password, if you use one, is never visible to this application.

Billing data

Payments are processed by Stripe. Card details never reach our servers. We store the Stripe customer and subscription identifiers, the price identifier, the subscription status and the current billing period, so we know which plan you are on.

Logs

We keep structured operational logs containing job identifiers, timing, error categories and counts. Logs are filtered to exclude source code, report excerpts, credentials, storage keys and absolute file paths.

Security limitations

This is a young service operated by an individual. It has been built with the specific threats of handling untrusted archives in mind and is tested against them, but it has not undergone an independent security audit, and we do not claim compliance with SOC 2, ISO 27001, HIPAA, or any other certification scheme.

Deleting your data

Deleting your account removes your profile, your scan history and your stored reports. Records Stripe keeps for its own financial and legal obligations are outside our control. Contact us through the repository issue tracker to request deletion.