GuardAPI

Effective 10 September 2026 · replaces January 2026 scanner policy

Privacy Policy

GuardAPI is a BOLA merge gate. The check runs in your GitHub Actions runner. We do not operate a public URL scanner and we do not send your API traffic to a language model.

What we store

  • Account email and auth identifiers (Supabase).
  • Stripe customer and subscription IDs. We do not store card numbers.
  • A CI API key associated with your account.
  • Repository names you register by running the Action, plan limits, trial end date.
  • Check results: verdict (passed / failed / error / inconclusive), leak count, duration, and a redacted evidence summary the Action POSTs to /ci/runs.

What we do not store

  • Tenant tokens (TOKEN_A, TOKEN_B). They remain GitHub Secrets and are used only on your runner.
  • Full API response bodies, except whatever redacted snippet the Action includes in the evidence payload.
  • Your source code.
  • End-customer PII except insofar as a redacted finding accidentally contains it — use staging fixtures.

Processors

  • Supabase — account and check records.
  • Stripe — billing.
  • Cloudflare — API worker and this website.
  • GitHub — if you use GitHub OAuth to sign in; also your own Actions logs, which we do not control.
  • Resend — transactional email if we send login or support mail.

Google Gemini is not used in v6. Older policies that said otherwise are void.

Deletion

Email support@guard-api.com from the account address to request deletion of customer and check records. Stripe records follow Stripe’s retention. GitHub logs stay in your org until you delete them.