Privacy Policy
Last updated: August 3, 2026
The short version: we use your code only to run the audit you asked for, then delete it. We don't sell your data.
What we receive
- The code you submit — uploaded files, pasted code, or a repository you connect with a read-only token.
- Payment details — handled entirely by our payment processor (Stripe). We never see or store your full card number.
- Account details — if you create an account, sign-in is handled by our accounts provider (Clerk). We see your email address and an account id; your password or social-login credentials stay with Clerk.
- Basic technical data — your IP address, used only to prevent abuse (rate limiting).
Who your data is shared with
- Anthropic (Claude), OpenAI (GPT), and Google (Gemini) — your code is sent to these AI providers to be read and analyzed.
- The public OSV vulnerability database — your dependency names and versions (not your code) are checked against it.
- Stripe — to process payment.
- Clerk — our accounts provider: handles sign-in and stores your account email and credentials. It never receives your code.
- GitHub — only if you connect a repository: we use your read-only token once to fetch that repository. The token is never stored, and it is not passed on to the AI providers.
We coordinate these services on your behalf — we're the middleman, not an air-gap.
How long we keep it
- Your code is deleted from our servers immediately after the scan finishes (success or failure), or when your session expires.
- Your report is held briefly so you can download it, then removed when you click "delete everything" or automatically within about an hour.
- We do not keep your code, your findings, or your report content long-term.
What we do keep
Business records: a timestamp, a random scan id, which AI models ran, line and token counts, amounts charged, our own cost and margin figures, and whether each model returned results. We also keep a short payment-reconciliation log of charge reference IDs (a Stripe charge id and the random scan id). If you have an account, we additionally keep your credit balance and purchase history, linked to your account id; your email and sign-in credentials are held by Clerk. None of this contains your code, your findings, or your card number.
Cookies
We use only strictly necessary cookies: a session cookie from Clerk that keeps you signed in, and fraud-prevention cookies set by Stripe during checkout. We do not use advertising or analytics cookies — which is why you don't see a cookie consent banner here: there is nothing optional to consent to.
Your choices
You can delete your report at any time with the "delete everything" button. To close your account or ask us to delete the records linked to it, email support@zapittech.com.
Contact
Questions about your data: support@zapittech.com
Terms of Use
Last updated: August 3, 2026
What AuditMyCode is
An automated, AI-assisted first-pass security review. It combines open-source scanners with three AI models to flag possible issues in code you submit.
What it is not
It is not a certified security assessment, a penetration test, or a guarantee that your code is secure. Findings are AI-generated suggestions that may miss real issues or flag false positives. Always review the results — and any suggested fixes — before acting on them.
Your responsibilities
- You must have the right to submit the code you scan. Don't submit code you don't own or have permission to audit.
- Don't misuse the service — no attempts to disrupt, overload, or reverse-engineer it.
Payment
Scans are paid for with credits. You buy a credit pack (checkout is handled by Stripe), the credits appear on your account, and each scan spends credits at the price shown before you run it. If a scan fails to produce a report (for example, if the AI providers are unavailable), the credits held for it are returned to your balance automatically. Because the audit is delivered immediately as a digital service, payments are final once a scan has run. If you believe you were charged in error, email us at support@zapittech.com and we'll put it right.
No warranty; limitation of liability
The service is provided "as is," without warranties of any kind. To the maximum extent permitted by law, AuditMyCode is not liable for any damages arising from your use of the service or your reliance on its results.
Changes
We may update these terms; the current version is always shown here.
Contact
support@zapittech.com