Legal
Privacy Policy
Last updated: July 12, 2026
1. What this policy covers
2. Information we process
We process account information supplied by your sign-in provider, including your name, email address, account identifier, and GitHub username when available.
When you connect a repository, we process repository metadata such as its name, URL, selected branch, and review status. We also keep scan records, finding details, proposed patches, and pull request links associated with your account.
To run a scan, Faultmark retrieves relevant repository content through the GitHub API. File content may be held in application caches keyed to repository and file-version information so the service can avoid repeating work. We also retain code excerpts that are part of saved findings and proposed fixes.
We process payment and subscription identifiers supplied by Stripe. Faultmark does not receive or store full payment-card details.
3. How we use information
- To authenticate users and maintain sessions
- To retrieve repository content and run reviews you request
- To show scan history, findings, patches, and pull request status
- To create a branch and pull request after you approve a proposed fix
- To operate billing, enforce service limits, prevent abuse, and diagnose service problems
4. Service providers
Faultmark uses GitHub to access repositories that you authorize. It may send relevant code and review context to Anthropic, OpenAI, and Google AI services to produce analysis and fix proposals. Stripe processes payments.
These providers process information under their own terms and privacy policies. We do not sell source code, finding data, or personal information. We do not use customer source code or findings to train Faultmark models.
5. GitHub access
GitHub access is granted through OAuth. Faultmark requests access needed to identify your GitHub account, read repositories you choose to connect, and create branches and pull requests after you approve a fix.
Your GitHub access token is kept in the application session and is not stored as a separate database record. You can revoke Faultmark's GitHub access through GitHub at any time.
6. Cookies and local storage
Faultmark uses authentication cookies that are necessary to keep you signed in. The dashboard can also use browser storage for temporary interface state, such as scan progress and your selected color theme. Faultmark does not use advertising cookies or cross-site tracking pixels.
7. Retention and deletion
Account records, repository metadata, scan records, findings, and cached content are retained while they are needed to provide the service and operate the account. The product does not currently provide self-service account deletion. To request deletion or ask about data held for your account, contact us at hello@faultmark.com.
8. Security
We use authenticated application sessions and access controls to limit access to account data. No system is completely secure, so please contact us promptly at hello@faultmark.com if you believe your account has been accessed without authorization.
9. Changes and contact
We may update this policy as the service changes. The date above identifies the current version. For privacy questions or requests, contact hello@faultmark.com.
