Privacy
DebtDetect, at debtdetect.org, explains here what personal data the service uses. Questions go to hello@debtdetect.org. You can complain to the data-protection authority in the EU country where you live, or where the Frankfurt service is supervised.
Why
DebtDetect processes account, repository, scan, billing, and integration data to provide the workspace you signed up for. That is the contract. Tax invoices are kept because the law requires them. Security logs are kept to protect the service. DebtDetect does not sell personal data and does not use repository contents to train a model.
What
Name, email, GitHub identifier, role, session, an encrypted repository credential, repository names, findings, scan times, billing name, and a VAT ID if you save one. Full card numbers stay at Stripe. Sign-up uses GitHub. DebtDetect does not create a separate password.
Who receives it
Fly.io hosts the application and database in Frankfurt. GitHub provides sign-in and repository access you authorize. Stripe handles payment and VAT. Resend, in Ireland, sends a report overview only when a person asks. Slack receives a message only after that workspace installs the app. Spaceship hosts hello@debtdetect.org. The data-processing agreement is the processor contract for data the workspace submits.
How long
Shown scan history is 90 days on Starter, 365 days on Pro, 1,095 days on Business, and 1,825 days on Enterprise. A source clone is deleted when the scan ends. Removing a person revokes their sessions. A tax invoice and the record that you accepted these terms can remain where the law requires that copy.
Your choices
After you are in the workspace, Settings can export or delete your account. You can ask for access, correction, deletion, restriction, or a copy, and you can object to a use that is not required for the contract, by writing to hello@debtdetect.org. A paid account stays one workspace for that GitHub identity.