Privacy policy
What we keep, and what we deliberately don’t.
Secondread reads source code for a living, so the most important part of this policy is the part about what never gets stored.
The short version
Your source code is read to write your report and is then discarded. It is never written to our database, our report storage, our workflow state, our logs, or our analytics. What we keep is the report itself and the file locations it points at.
Everything below explains that in more detail, along with the account and billing data we do keep in order to run the service.
Who this policy is from
Secondread is operated by Qudelta Solutions LLP, registered at Millat Colony, Delina, Baramulla, Jammu and Kashmir 193103, India. For anything in this policy, including a request to access or delete your data, write to hello@secondread.dev.
We are committed to handling personal data in line with the UK GDPR, the California Consumer Privacy Act (CCPA), and India’s Digital Personal Data Protection Act, 2023 (DPDP Act). We offer the core access, correction, deletion, objection, and portability rights described below to every user, regardless of where they live. We are auditing our operational compliance against each regime before public launch and will update this policy if that review requires a more specific process.
What we collect
When you create an account
You sign in through GitHub or Google. We receive your name, email address, and profile image from whichever provider you use. We never receive your password for either service. We store encrypted OAuth tokens needed to keep your chosen sign-in and repository connection working, along with security information associated with a session, such as its IP address and user agent.
When you connect a repository
Connecting happens through a GitHub App with read access to Contents and Metadata, limited to the repositories you select. We store the connection and installation details, and the metadata of the repositories you have chosen, such as their names and the commit a report was run against.
When a report runs
We store the finished report: its findings, their plain-English explanations, the severity and effort assessments, and the file paths and line numbers each finding points at. Line numbers and file paths are references, not copies of your code.
Selected source files are sent to Cloudflare Workers AI for the sole purpose of writing that report. They are not retained by us afterwards.
When you pay
Payment is handled by our merchant of record. Your card details go directly to the payment provider and never reach Secondread. We store the order record, the plan purchased, the amounts, the currency, and the resulting credit balance and expiry.
Product analytics
If you opt in from Settings, we record a small set of named product events — for example that an audit started, completed, or failed — together with your account ID and a timestamp. These events are deleted after 180 days. We do not attach IP addresses, device fingerprints, user agents, or advertising identifiers to analytics events, and we do not use third-party advertising or cross-site tracking anywhere in the product.
This marketing site fires the same kind of named events for page interactions. It sets no tracking cookies of its own and loads no fonts or scripts from third-party hosts.
What we never store
- Your raw source code. Read to produce the report, then dropped. It is excluded from our database, stored reports, workflow state, logs, and analytics.
- Your card details. These are handled entirely by our merchant of record.
- Your GitHub or Google password. Authentication happens on the provider’s side; the OAuth tokens we need are encrypted at rest.
- Anything written back to your repository. There is no code path in the product that writes to GitHub.
Service providers
These providers help us run Secondread. Some process data on our instructions, while payment, identity, and repository providers may also act under their own terms and privacy policies.
| Provider | What they do |
|---|---|
| Cloudflare | Hosting, database, file storage, queues, and the AI models that write your report |
| Dodo Payments | Merchant of record for international checkout, payment processing, taxation, billing, refunds, and invoices |
| GitHub | Sign-in, and read-only access to the repositories you select |
| Sign-in, if you choose it | |
| Resend | Transactional email, such as when a report is ready |
We do not sell personal data, and we do not share it for advertising.
How long we keep things
Reports, findings, and the evidence references attached to them are kept until you delete them or delete your account. Optional analytics events are kept for 180 days. Limited transaction records that must remain available for accounting, fraud prevention, disputes, or legal obligations may be kept for up to one year after account closure. Our merchant of record may retain billing and tax records for the period required under its own legal obligations.
Deleting your data
You can delete your account yourself, from Settings inside the app. Doing so disconnects GitHub and removes your sign-in data, saved app details, private reports, generated downloads, plan access, and payment history from your active account. The limited transaction records described above may remain for up to one year. Account deletion cannot be undone.
You can also disconnect Secondread from GitHub at any time, from GitHub itself. Reports you have already generated stay readable; new reads on private repositories stop.
If you would rather we did it, or you want a copy of your data first, email hello@secondread.dev.
Your rights
You may ask to access your data, correct it, delete it, object to or restrict certain processing, or receive it in a portable format. You may also withdraw consent for optional analytics at any time in Settings. We do not sell personal data or share it for cross-context behavioural advertising. We will respond within the period required by the UK GDPR, the California Consumer Privacy Act (CCPA), and India’s Digital Personal Data Protection Act, 2023 (DPDP Act). Ask at hello@secondread.dev. You may also complain to the privacy or data-protection authority that applies where you live.
Why we process personal data
We process account, repository, report, and order information to perform our contract with you. We process security, abuse-prevention, and reliability information for our legitimate interests in protecting and operating the service. We process records where necessary to meet legal obligations, and optional product analytics only with your consent.
International data transfers
Secondread is operated from India and uses providers that operate internationally. Your data may therefore be processed outside your country. Where a privacy regime requires a transfer mechanism or contractual safeguard, we commit to using one that is valid under that regime.
Cookies
The application uses strictly necessary cookies to keep you signed in and protect your session. They are not used for advertising. The marketing site sets no tracking cookies of its own.
Changes to this policy
If we change how we handle your data in a way that materially affects you, we will update the effective date at the top of this page and tell account holders by email before the change takes effect.