Privacy Policy

Last updated June 2026

GhostCred ("we") provides automated credential and secret exposure scanning. This policy explains what we collect and how we handle it.

What we collect

Your email address, the repository URL or file you submit for scanning, and the resulting findings. We also store payment metadata returned by Stripe (customer and subscription identifiers), never card numbers.

How we handle secrets

Secret values detected during a scan are redacted to the first four characters before anything is written to our database or included in a report. Uploaded files are processed to produce your report and are not retained as raw content afterward.

Private repositories

On Pro and MSP plans you can scan a private GitHub repository with a read-only token you provide. The token is used for that one scan and is never stored or logged. The contents of the files we read are sent to Anthropic for analysis, the same as for public repositories, and results from a private-repository scan are visible only to the account that ran it.

Sub-processors

We use Supabase (database, storage, authentication), Stripe (payments), Anthropic (AI analysis), Resend (email delivery), and Vercel (hosting).

Your choices

Request deletion of your scans and account data any time through our contact form.