Privacy Policy

Your code stays yours.

1. Scope

This policy applies to CodeValuation.com, the Code Valuation web portal, mobile applications, public RepoWorth and Contributor Value pages, assessment and monitoring products, research tools, and related communications. It does not govern GitHub, Stripe, Apple, Google, or other services under their own privacy policies.

2. Data we collect

Depending on how you use the service, we collect the following categories of data:

3. Where data comes from

We receive data from you, your authorized workspace administrators, GitHub and GitHub Apps, public GitHub sources, repository scans, payment and app-store providers, and activity generated when you use CodeValuation.com. Public GitHub data may be used to create or update public repository and contributor records. We do not infer a person's identity or social profile from name similarity alone.

4. How repository processing works

Public repositories are evaluated from public GitHub data. Private repositories require an authorized GitHub connection. Managed Scan streams the selected repository through an isolated, ephemeral processing environment for the requested calculation. We persist derived measurements, permitted metadata, identifiers, hashes, valuation snapshots, and evidence references. We do not save or log the raw archive or source, send source to AI, or retain credentials, raw source snippets, or raw private diffs as part of the valuation record.

Valuation results and permitted derived metrics are stored so we can show changes over time, support current and requested reporting, detect refactors and removed value, provide analytics, and preserve the evidence context used for each result.

5. How we use data

6. Analytics and social outreach

Google Analytics is optional and does not load until you choose “Accept analytics.” We honor Global Privacy Control and browser Do Not Track signals by keeping analytics disabled. You can change your choice at any time through “Privacy choices” in the site footer. Essential local storage and cookies used for authentication, security, requested preferences, and core service operation do not depend on analytics consent.

Our private outreach workflow may use X's API to search recent public posts containing a public GitHub repository URL or operator-supplied keyword. Operators review search results and generated drafts before posting. The workflow does not automatically publish to X. We retain the selected public post, the saved draft, the public response link, and a contacted status to prevent duplicate outreach and maintain an operational record.

7. Public pages, research, and sharing

Public RepoWorth pages use public repository evidence. A contributor profile is not made searchable solely because a commit exists. Identity, evidence, quality, freshness, duplication, and privacy requirements apply. Claimed users can choose whether a profile is public, unlisted, or private and can control eligible repository attribution, badges, milestones, and private-value aggregates.

Public research and indexes use eligible public data and disclose the metric definition, date range, sample size, coverage, and known limitations. Private repositories, private portfolios, private assessment details, raw emails, and precise personal locations are excluded from public research views. Connected-account measurements may contribute to anonymous aggregate benchmarks. We do not share the underlying source, account, company, repository, contributor, or report data used to calculate those benchmarks, and benchmark outputs do not identify a participating account or repository.

8. Evaluator access and private reports

Investors, lenders, acquirers, and enterprise evaluators receive private-derived information only after an authorized repository or organization administrator accepts the complete request. Reports are read-only and never expose source code or repository credentials. The evaluated organization can see who has access, what report is shared, who is paying, when the last scan ran, and how to revoke access.

Private PDF download links expire seven days after they are issued. An authorized user can request a new link while the report remains available.

Revoking an evaluator ends future platform access for that evaluator and invalidates that evaluator's private report access. Disconnecting GitHub stops new private scans but does not by itself delete completed reports or permitted derived records. Copies lawfully downloaded before revocation cannot be remotely deleted from a recipient's device.

9. Service providers and disclosures

We disclose only the data needed for service providers to perform contracted functions, including:

We do not sell personal data. We do not use personal data for third-party targeted advertising, and the app does not use cross-app tracking or an advertising identifier.

Our current service-provider list and change process are published on the Subprocessors page.

10. Retention and deletion

We retain account data and permitted derived repository records while your account or connection remains active and as needed for reporting, analytics, security, billing, dispute resolution, and legal obligations. Disconnecting a repository does not start a 30-day deletion clock. Completed reports remain available until you delete them, access is revoked, or the subscription-lapse rule below applies. Public-source facts and published research may remain under our public-data policy.

If paid access ends and the account does not renew or resubscribe, stored report files and report snapshots are scheduled for deletion 30 days after the paid-access period ends. Renewing or resubscribing during that period cancels the scheduled report deletion. This report cleanup does not delete permitted connected-account measurements or derived metrics, which may continue to support private reporting, analytics, and anonymous aggregate benchmarking while the account connection remains authorized. Underlying connected-account data is not shared with benchmark participants or the public. Billing records, consent records, audit events, and non-sensitive identifiers may be retained as required for compliance. We do not retain private source code as part of these records.

Managed-scan processing receipts and operational security evidence are retained for up to 400 days and then purged under an automated retention control. Encrypted backups may retain deleted records until their documented backup expiry; restored records remain subject to the same deletion requirements. Temporary migration and restore artifacts are restricted to authorized operators and removed after the approved rollback window.

Resolved, closed, and junk support conversations, including private support attachments, are retained for up to 400 days and then deleted together under an automated control. Completed, failed, dead-letter, and canceled processing-job records are also retained for up to 400 days for reliability and security evidence. A documented legal hold may suspend ordinary deletion when preservation is required.

Unselected X search candidates are retained for up to 30 days. Selected social outreach workflows, saved drafts, public post references, contacted status, and audit events are retained for up to 400 days unless a shorter legal or operational requirement applies. Optional analytics retention is configured in Google Analytics and is subject to your consent choice; withdrawing consent stops future analytics collection from this browser and removes available CodeValuation analytics cookies.

11. Your privacy choices

Use the privacy controls in the app or email justin@codevaluation.com. We may need to verify your identity before completing a request. Some information cannot be deleted immediately when retention is required for fraud prevention, security, billing, legal compliance, or an active authorized report.

12. Security and international processing

We use access controls, signed provider events, row-level authorization, encryption in transit, encrypted infrastructure, audit records, and scoped repository permissions designed to protect data. Primary managed-scan processing and derived-data storage are operated in U.S. West regions. Data may also be processed in the United States and other countries where our providers or their subprocessors operate, subject to applicable transfer protections. No security measure is perfect.

13. Children

CodeValuation.com is a professional software service and is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided data, contact us so we can review and delete it where required.

14. Changes and contact

We may update this policy as the service, providers, or law changes. We will post the effective date and provide additional notice when a material change requires it. Questions and privacy requests can be sent to justin@codevaluation.com.