Public repositories are evaluated from public GitHub data. Private repositories require an authorized GitHub App installation.
Private source is processed in an ephemeral environment. CodeValuation.com persists permitted identifiers, hashes, derived measurements, valuation snapshots, and evidence references, but not a copy of the source code.
Disconnecting GitHub stops private scans, cancels queued private work, invalidates private report access, and begins the configured deletion window for inaccessible private-derived data.