← Back to CheckMyLaunch
Privacy Policy
Last updated: 14 July 2026
CheckMyLaunch scans code repositories and live websites for launch-readiness issues.
This page explains what we collect while doing that, in plain English.
What we collect
- Account info: when you sign in with GitHub we store your
GitHub username, display name, and avatar. We never see your GitHub password.
- Repository access: scanning a repo uses a temporary,
scoped access token for only the repositories you chose when installing our
GitHub App. Cloned code is deleted immediately after each scan — we keep the
scan results (findings, scores), not your code.
- URL scans: when you scan a live website we fetch a small
number of its public pages, the same way a browser would, and store the results.
- Billing: payments are processed by Stripe. We never see or
store card numbers — only your plan and a Stripe customer reference.
What we don't do
- We don't sell your data or share it with advertisers.
- We don't keep copies of your source code after a scan finishes.
- We don't display the actual secret values our scanner finds — findings name
the type of secret and the file it's in, not the secret itself.
Where data lives
Scan results and account records are stored in our database (Supabase/Postgres).
Sign-in sessions are held server-side and expire after 30 days.
Deleting your data
You can request deletion of your account, scan history, and sessions at any
time, and we'll action it within 7 days. Uninstalling the GitHub App revokes our
repository access instantly at GitHub's end.
Contact
CheckMyLaunch is operated by MATD NZ, New Zealand. For any privacy questions
or requests about your data, email privacy@checkmylaunch.com.