PRIVACY
What we hold about you.
What we never hold.
How long we keep it.
Written the same way as the security page: every claim specific enough that you can hold it against what the product does. Where our implementation is behind our policy, this page says so rather than leaving you to find out. Last reviewed 7 August 2026.
THE SHORT VERSION
Your source is not something we hold.
It is cloned into a machine created for your audit, read there, and destroyed with the machine — on every exit path, including the runs that crash halfway. There is no copy of it to ask us about and nothing to delete.
Read-only, one repository, attached to the clone request from outside the sandbox. Nothing running in there could exfiltrate it, because it was never in there.
No deploy, no server, nothing reaching your infrastructure or your production data. Your own test suite runs inside the sandbox so we can report whether it passes. Your application does not.
Outbound network is denied while the audit runs, our own telemetry included. The report is the only thing that comes out.
Destruction is a property of the machine being per-run and disposable, not a cleanup step that can be skipped when something goes wrong.
WHAT WE DO HOLD
Four things, and you can ask about any of them.
Everything below sits in one Postgres database and one private storage bucket, both hosted in the United States.
Your email address and name, the organization name you chose, and the billing address you give Stripe. Sign in with Google or GitHub and we get the address that provider reports — nothing else from your profile.
File, line, commit, and the sentences the audit wrote about them. This is the thing you bought, and it is the one part of your project we keep.
A design audit photographs the pages it grades. They sit in private storage, reachable only through a link that expires. If a page is showing real customer data at the moment we photograph it, that data is in the screenshot — you choose the URL and the test login, so you choose what is on screen.
The read-only repository token, and — only if you ask us to audit a flow behind a login — a test account's password. Both go into a secrets manager and neither is ever sent back to your browser: the settings screen tells you one is held, never what it is.
HOW LONG
Reports outlive everything else, on purpose.
A grade history with holes in it is not a history. That decision is the reason two of the four answers below are "indefinitely" rather than a number that sounds more careful.
Never written to our database, never backed up, never retained after the run. Revoking the token breaks nothing on our side, because there is no copy depending on it.
A project's trend line, the comparison against your previous run and every automated re-audit read from that history — delete a report at ninety days and you delete the comparison with it. Ask and we remove them sooner. Close the account and they go with it, along with the repository credentials you gave us.
Twelve months is our policy and no scheduled job deletes them yet. That is a gap in what we built rather than a different policy, and it is written here rather than left for you to discover. Ask and we delete a run's captures now.
There is no button for it. Email us from the address you sign in with, say what you want gone — the account, the reports, or both — and we do it and write back to confirm.
Your projects, runs, reports, screenshots and stored repository credentials are deleted. What we keep is the record of what you paid — the date, the amount, the pack and the Stripe reference — because it is our accounting and we cannot drop it. The organization row stays too, emptied of its name, its billing address and its owner, because that identifier is what the payment record points at. Unspent credits are not refunded; nothing can reach them afterwards.
WHO ELSE HANDLES IT
Six companies, and what each one gets.
Named rather than described as "trusted partners", because the point of the list is that you can go and read their terms.
Anthropic
The model that reads your code. Your source and the audit's own working go to the Claude API during a run. It is one of only two hosts the reviewing machine can reach; the other is the endpoint findings come back through.
Vercel
Hosts this site and the app, and provides the disposable machine your audit runs in.
Supabase
The Postgres database, sign-in, and the private bucket screenshots sit in. United States, region us-east-2.
Stripe
Payments. Card details go to Stripe and never reach us — we hold the receipt, not the number.
Resend
Transactional email: sign-in links, team invitations, and the message telling you a report is ready. Sent from no-reply@alongside.dev.
Google, unpkg and jsDelivr
Typefaces and icons, loaded on every page of this site and the app. Read the next section before you decide how you feel about that.
Two things on this page we are not happy with
- Loading any page here sends your IP address to three other companies before you click anything. The typefaces come from Google Fonts and jsDelivr, the icons from unpkg, and all three are fetched on first paint — this page included. Nothing asks you first. We think the fix is to serve those files ourselves rather than to put a consent dialog in front of a font, and that work is not done.
- The twelve-month screenshot window has nothing enforcing it. Said once already; repeated here because a retention period no job carries out is a claim rather than a control, and this page exists to stop us making claims of that shape.
WHAT YOU CAN ASK FOR
One address, and a reply from a person.
There is no self-service export screen and no ticketing system. Email us and you get an answer written by someone who can read the database.
Your account row, your reports, and the list of runs against them. Ask and we send it.
Your name and email are editable in Settings. Anything else, tell us what is wrong and we fix the record.
Of a project, of a run's screenshots, of your reports, or of the account. Say which, and we confirm when it is done.
The audit grades your code. Nothing here profiles you, scores you, or decides anything about you as a person.
Anything this page does not answer, ask.
hello@alongside.devSecurity questions go to security@alongside.dev, and the security page answers most of them already. Alongside is operated by Alongside Software, LLC.