Privacy Policy
Version 1.0 · 23 September 2026
Who is responsible
AELaboratories is the data controller. support@borehole.dev.
The short version
- Reports contain no personal data. Authorship is stored as counts and ratios — "top author 160 of 257 commits", "40 of 56 authors have exactly one commit" — never as names or email addresses.
- We do not store your IP address for quota. It is hashed with a secret salt, because the only question we ask of it is whether it is the same subject as before.
- All of our own infrastructure is in the EU.
- We do not sell anything to anyone, and there is no advertising.
What we store, and why
| What | Why | Lawful basis | Kept |
|---|---|---|---|
| Your GitHub id, login, display name, email and avatar, if you sign in | To know who you are, to apply your allowance, and to show you what you bought | Contract | While the account exists |
| Session id, user agent and address | To keep you signed in and to spot session abuse | Legitimate interest | 30 days, then deleted |
| A salted hash of your address | Free-tier quota. Never the address itself | Legitimate interest | 30 days |
| Reports: findings, evidence pointers, bands, rejection log | The product. A report is about a repository, not a person | Legitimate interest (public) · Contract (private) | Indefinitely — a verification mark has to keep resolving |
| Order reference, amount, tier, email, Stripe identifiers | To take payment and prove what you bought | Contract, then legal obligation for tax records | As tax law requires |
| Anything you type into a form — assessment requests, rebuttals, ratings | To reply to you, and to publish a rebuttal beside the finding it answers | Consent | Until you ask us to remove it |
| A pseudonymous analytics id — a salted hash, never the raw address | To count how many people reach each step | Legitimate interest | As PostHog retains it |
What we deliberately do not store
- Your source code. The working copy is deleted when the scan ends, including when it fails. What survives is the report.
- Contributor identities. Authorship is counted, not named. A report contains no email addresses.
- Card details. Payment happens on Stripe's pages. We never see a card number.
- Access tokens. A private-repository token is minted for one scan and discarded after it.
- Commit author names and email addresses. Authorship reaches a report only as counts and ratios.
One exception, stated rather than hidden. Three checks quote a small amount of text as evidence: the text of up to five TODO-style comments, up to four commit subjects, and an unpinned dependency line. In each case the quoted text is the evidence, which is why it is kept by default — paraphrasing a TODO would be worthless. Whoever controls the repository can remove it from a report at any time, which rewrites what we store, so afterwards we do not hold it at all. The pointers stay, so the line can still be found.
Who else processes it
All of our own infrastructure runs in the EU.
| Processor | For | Where |
|---|---|---|
| Google Cloud | Hosting, database, scanning | europe-west1 (Belgium) |
| Stripe | Payments | United States and globally |
| GitHub | Sign-in and repository access | United States |
| Resend | Transactional email | eu-west-1 (Ireland) |
| Sentry | Error reports | Germany |
| PostHog | Product analytics | EU cloud |
What each one receives, and which are optional.
Stripe and GitHub are US companies, so using them involves a transfer outside the EU under their standard contractual clauses. You cannot use the paid product without Stripe, or sign in without GitHub.
Error reports and analytics
Error reports are scrubbed before they leave the process, by key name and by value shape: access tokens, Stripe keys and clone tokens are removed rather than redacted after the fact. Analytics are server-side and identified by a salted hash, not by a cookie. Do Not Track is honoured. Session replay is off, and must never be enabled on a report page — a report can quote a private repository, and recording the screen would store that content a second time outside the boundary the architecture is built around.
Your rights
Under the GDPR you may ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing based on legitimate interest, and complain to a supervisory authority.
Export and deletion are self-service, on your account page. The export is assembled by querying the database rather than from a list of what we believe we store, because such a list goes stale the first time a table is added and you would have no way to tell. For anything these do not cover, write to support@borehole.dev.
When an account is deleted: the account record is anonymised, sessions are deleted, form submissions are removed, and a published rebuttal is anonymised rather than deleted — removing it would alter what a report said. Orders are kept where tax law requires, with the email address redacted once that period has passed. Reports are unaffected, because they contain no personal data.
Children
This is a tool for professionals. It is not directed at anyone under 16 and we do not knowingly collect their data.
Changes
A material change will appear here with a new version and date.
See also the Terms of Service.