Last Updated: Oct 2026
At Octoshield, we take your privacy and the security of your data seriously. This Privacy Policy outlines how we collect, use, and protect your information when you use our secret scanning service and mobile applications.
When you connect your GitHub or GitLab accounts to Octoshield, we request minimum-viable read permissions to access repository webhooks and scan incoming commits. We do not clone your entire repository or store your source code.
Our scanning engine analyzes commit diffs in memory. When a potential secret (like an API key or token) is detected, we log an obfuscated hash and immediately trigger an alert. We offer optional encrypted storage for known API credentials to provide billing velocity signals. If you opt out, no credentials are saved in our databases.
Octoshield does not sell, rent, or trade your personal information or repository metadata to third parties. We may share limited anonymized data with service providers (like analytics and hosting platforms) strictly to operate our service.
We retain your account information and scanning logs for as long as your account is active. If you delete your account, we securely wipe all associated tokens, webhooks, and historical scanning data within 30 days.
If you have questions about this policy or your data, you can reach our security team at privacy@octoshield.app.