Privacy Policy
What we collect, why we collect it, and what we do not do with it.
Last updated: 10 August 2026
Controller
Freesc, Door 1b, First Floor, Nags Corner, Wiston Road, Colchester, CO6 4LT, United Kingdom, is the controller for the data described here. Contact: contact@freesc.uk.
What we process
- Account data — email address, authentication identifiers, organisation name.
- Repository access credential — the read-only access token you enter, stored encrypted and only decrypted server-side for the duration of a run.
- Application metadata — repository name, branch, commit, and the answers you give in the criticality questionnaire.
- Analysis results — findings, file paths, line numbers and short evidence extracts. Values that look like secrets are redacted before anything is stored or logged.
- Service records — assessment requests, invoices and product usage events used to run and improve the service.
Your source code itself is not stored. It is downloaded for a single run, analysed in memory and discarded when the run ends.
Why we process it
To provide the service you asked for (performance of a contract), to invoice and support you, to keep the service secure and functioning, and to comply with our legal obligations.
Who else is involved
- Managed cloud hosting and database providers, for the application, authentication and storage.
- An email delivery provider, for account and service notifications sent from notify.freesc.uk.
- The public OSV.dev vulnerability database, queried with dependency names and versions only — never with your code or your identity.
- Your Git provider, when we read the repository you connected using your own token.
We do not sell your data and we do not use it to train machine learning models.
How long we keep it
Assessments and reports stay available on your account until you delete the application or the account. Access tokens are deleted as soon as you disconnect the repository. Invoicing records are kept for the period required by UK accounting law.
Security
Credentials are encrypted at rest with AES-256-GCM. Data is isolated per organisation with row-level access rules. Report files live in private storage and are served only through short-lived signed links.
Your rights
Under UK GDPR you can ask for access, correction, deletion, restriction, portability, or object to certain processing. Write to contact@freesc.uk and we will respond within one month. You may also complain to the UK Information Commissioner's Office.