Legal

Privacy Policy

This policy explains what information AtRisk collects across URL scanning, monitors, Findings, GitHub connections, agents, MCP, teams, billing, analytics, free tools, and (where offered) public or unlisted reports - and the choices you have.

Last updated: September 9, 2026 · Effective: September 9, 2026

1. Who we are

AtRisk ("AtRisk," "we," "us," or "our") operates the websites atrisk.dev and app.atrisk.dev, along with related free tools, APIs, emails, and the AtRisk product (the "Services").

AtRisk is a maintenance and security-assurance layer for AI-built apps: URL scanning, monitors, repository audits, Findings, fix prompts for AI coding agents, optional MCP and CI deploy-gate features, and related workflows.

For privacy requests, contact contact@atrisk.dev.

Our Terms of Service, Cookie Policy, DPA, and Subprocessors list should be read with this Policy. For security controls and disclosure, see our Trust Center.

1.1 Roles

For personal data about website visitors and account holders that we decide how to process, we act as a controller (or analogous "business" under US state privacy laws). For Customer Content you submit about third parties (for example content retrieved from a site you authorize us to scan), you are typically the controller / business and we process that data to provide the Services on your instructions under the Terms and our Data Processing Addendum. Business customers may also request a negotiated DPA by emailing contact@atrisk.dev.

2. Scope

This Privacy Policy applies to information we collect when you:

  • Visit or browse atrisk.dev or app.atrisk.dev
  • Create an account or sign in (email/password or OAuth such as Google)
  • Submit a URL for scanning, enable monitors, or review Findings / fix prompts
  • Connect a GitHub (or other) repository via our App or OAuth flow
  • Use repo agents, inbox workflows, correlation, apps, or team invites
  • Create, use, or revoke MCP tokens or CI deploy-gate integrations
  • View, claim, or share public / unlisted report artifacts where offered
  • Subscribe, start a trial, or manage billing
  • Use free tools that ask for an email address
  • Contact support or otherwise communicate with us

It does not apply to third-party websites, products, or services we link to or that you connect (except as described for our processors).

3. Information we collect

3.1 Account and identity

  • Name, email address, and profile fields you provide (for example avatar URL)
  • Authentication data handled by our auth provider (password hashes; OAuth identifiers such as Google)
  • Account identifiers, session metadata, and security events (sign-in, revoke sessions)
  • Team invite emails and seat membership
  • Email preference flags (for example regression alerts, weekly digests)

3.2 Scan, monitor, and Finding data

  • Target URLs, domains, and app / project labels you create
  • HTTP responses, headers, HTML/JS snippets, DNS/TLS and related publicly reachable signals retrieved during scans
  • Finding records, severity, evidence, status (fixed/dismiss/reopen/false positive), correlation links, and generated fix prompts
  • Monitor schedules, re-scan results, and regression / digest email content
  • Public or unlisted report artifact metadata and access tokens where offered

3.3 Repository and integration data

  • GitHub App installation metadata and repository identifiers you connect
  • Repository file contents, paths, diffs, and lockfile package names/versions you authorize us to read for agents
  • Agent run logs needed to deliver and debug scheduled audits
  • MCP token labels, hashes, and usage signals (token secrets are not shared with marketing analytics)
  • CI / deploy-gate configuration and SARIF-related results where used

3.4 Billing

  • Plan, subscription status, credit ledger entries, and entitlement usage
  • Polar customer / subscription identifiers and billing email or country metadata Polar shares with us
  • We do not store full payment card numbers on our servers (Polar processes payments and may act as merchant of record)

3.5 Free tools and marketing leads

  • Email addresses submitted to unlock free tools, associated tool slug, IP, and timestamps
  • Prompt text and other inputs you submit to free tools (sent to AI providers to return results)

3.6 Automatically collected technical data

  • IP address, user agent, device/browser/OS signals, approximate location derived from IP
  • Pages viewed, referral source, feature usage events, performance metrics, and timestamps
  • Advertising measurement identifiers when the Reddit Pixel is active (for example click IDs and pixel cookies)
  • Diagnostic and error data (including stack traces) needed for reliability
  • Rate-limit and abuse-prevention signals

3.7 Support and communications

When you contact us, we collect your email, message content, attachments, and metadata needed to respond.

3.8 Local storage and similar technologies

On atrisk.dev free tools, we may store your email in browser local storage for a limited period so you do not have to re-enter it. The app may use sessionStorage for pending scan URLs across authentication. Auth/session cookies or tokens keep you signed in. You can clear site data in your browser; blocking essential storage may break login.

3.9 Sensitive personal information

We do not seek to collect sensitive personal information (as defined under GDPR Art. 9, CPRA, or similar laws) to infer characteristics about you. Do not submit government IDs, health data, precise geolocation, full card numbers, or unnecessary production secrets into free tools or prompts. If such data appears incidentally in scan evidence or support mail, we will handle deletion requests under Section 11.

4. Legal bases (EEA / UK / similar)

Where the GDPR, UK GDPR, or analogous laws apply, we rely on:

  • Contract - to create accounts, run scans you request, deliver Findings, process subscriptions, and provide support
  • Legitimate interests - to secure and improve the Services, prevent fraud/abuse, understand product usage, and (where lawful) send limited product notices; we balance these interests against your rights
  • Consent - where required for non-essential cookies, analytics, or advertising measurement; you may withdraw consent without affecting prior lawful processing
  • Legal obligation - tax, accounting, and responding to lawful requests

5. How we use information

We use personal information to:

  • Provide, operate, secure, and improve the Services (scans, monitors, agents, inbox, MCP, deploy gate, reports, free tools)
  • Create and manage accounts, sessions, teams, apps, entitlements, and access controls
  • Store and display Findings, generate fix prompts, support verify-after-fix and re-checks
  • Run connected-repo agents within the permissions you grant and look up dependency data (for example via OSV)
  • Process subscriptions, trials, credits, invoices, and customer portal access via Polar
  • Send transactional messages (account, billing, security, regression alerts, digests you enable)
  • Send optional product or marketing emails where permitted; you can unsubscribe
  • Measure usage, diagnose issues, prevent fraud and abuse, and enforce our Terms
  • Measure Reddit advertising campaigns and optimize conversion ads (Reddit Pixel and, when configured, Conversions API)
  • Operate claim / report / domain-proof flows where offered
  • Comply with legal obligations and respond to lawful requests
  • Create aggregated or de-identified statistics that do not reasonably identify you

6. AI processing

To generate fix prompts, optional finding judgments, free-tool results, and similar Outputs, we may send relevant inputs and necessary context to third-party AI providers:

  • In-app AI Features generally use Anthropic APIs (for example model calls to polish fix prompts; optional agent LLM judges when enabled by configuration)
  • Marketing free tools generally use OpenRouter, which routes to underlying model providers

Those providers process content to return model Outputs under their terms. We do not use Customer Content to train third-party foundation models except as necessary to generate the specific Output you requested, as required by law, or as otherwise disclosed here and in provider terms.

Do not submit secrets, passwords, payment card numbers, government ID numbers, health data, or other highly sensitive personal data into prompts or free tools. You are responsible for the content you submit and the targets you authorize. AI Outputs and automated Findings may be inaccurate or incomplete - review before relying on them.

7. Cookies and analytics

We use essential and functional technologies to operate the Services, including:

  • Session and authentication storage needed to keep you signed in
  • Pending scan URL storage across authentication
  • Local storage for free-tool email convenience
  • Security, rate-limiting, and abuse-prevention mechanisms

We also use product analytics and diagnostics that may set cookies or similar identifiers:

  • PostHog - product analytics and usage events (no session recording in current configuration)
  • Sentry - error monitoring and performance traces (session replay sample rates are set to zero; we do not enable session replay by default)
  • Reddit Pixel - conversion measurement for Reddit Ads (page visits, content views, leads, and signup intent)

More detail is in our Cookie Policy. We do not use Microsoft Clarity or other marketing-site session-replay / heatmap tools. You can control cookies and site data through your browser settings. Blocking essential cookies or storage may prevent login or other core features. Where consent is required by law for non-essential analytics or advertising measurement, we will seek consent through a banner or similar mechanism when implemented; until then, you may use browser controls or contact us to object. If your browser sends Global Privacy Control (GPC), we do not load the Reddit Pixel and we do not send Reddit Conversions API events for that request.

We do not sell personal information for money. The Reddit Pixel shares technical identifiers (and, for email leads, a hashed email) with Reddit so we can measure and optimize Reddit Ads. Under some US state laws that may be "sharing" for cross-context behavioral advertising. GPC is treated as an opt-out of that sharing. Do Not Track is not a reliable signal and does not change processing by itself; email contact@atrisk.dev to object where applicable law allows.

8. How we share information

We do not sell or rent your personal information. We share information with service providers to run AtRisk, and with Reddit for advertising measurement, including:

8.1 Service providers / processors

  • Neon - authentication and database hosting
  • Polar - payment processing, subscriptions, and customer billing portal (Polar may act as merchant of record)
  • GitHub - when you connect a repository via the GitHub App or OAuth
  • Anthropic - in-app AI generation
  • OpenRouter and underlying model providers - free-tool AI on the marketing site
  • Cloudflare - hosting, CDN, Workers, Browser Rendering, Containers, KV (including free-tool leads and rate limits), and related infrastructure
  • OSV (api.osv.dev) and similar public vulnerability sources - dependency lookups using package metadata
  • Resend - transactional and tool-related email delivery
  • Sentry - error monitoring and performance traces
  • PostHog - product analytics and usage insights

These providers are authorized to process data only to perform services for us and are subject to contractual or comparable confidentiality and security obligations. A current list is also published on our Subprocessors page. We may also share limited information with professional advisors under confidentiality, with authorities when required by law, and with successors in a merger or asset sale.

8.2 Team and report sharing

If you invite teammates or create shareable report links, the people who receive access can see the Customer Content and Findings you share. You are responsible for choosing recipients and for any personal data in those materials.

8.3 Legal and safety

We may disclose information if we believe in good faith that disclosure is required by law, necessary to protect rights, safety, or security, or needed to investigate fraud or Terms violations.

8.4 Advertising measurement

When you visit atrisk.dev after seeing or clicking a Reddit ad (or otherwise while the pixel is active), we share event data with Reddit, Inc. for conversion measurement and campaign optimization: page URL, event type, technical identifiers (IP, user agent, pixel cookies / click IDs), and hashed email when you submit a free-tool lead. Reddit acts as an independent controller for that advertising measurement. See Reddit's privacy policy. GPC opts you out of this sharing as described in Section 7.

9. Data retention

We retain personal information for as long as needed for the purposes above. Indicative periods:

  • Account / profile / subscription metadata - for the life of the account; deleted or anonymized within a reasonable period after account deletion except where law requires longer retention
  • URL scans, agent runs, audit logs, and related billing event records - typically about 90 days under our automated retention job, unless we must keep records longer for disputes, security, or legal compliance
  • Findings and operational copies tied to those runs - follow the same operational retention windows unless associated with an active account feature that requires longer display (subject to product limits)
  • Free-tool lead records in Cloudflare KV - about 90 days, refreshed on each reuse (TTL resets when the same email is submitted again)
  • Payment and tax records held by us or Polar - as required by applicable commercial/tax law
  • Support correspondence - generally account life plus a short period after closure
  • Backups - short rolling windows; deletion from production propagates as backups rotate

Disconnecting GitHub stops new repository access; residual copies may remain in backups for a limited period. When retention is no longer required, we delete or anonymize information where reasonably practicable.

10. Security

We use administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, access controls, least-privilege practices, monitoring, and vendor controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. A plain-language overview of current controls is on our Trust Center.

Please use a strong unique password, protect credentials and MCP tokens, enable available security features, and notify us promptly of any suspected unauthorized access. To report a vulnerability, see our vulnerability disclosure policy.

11. Personal-data breach notification

If a personal-data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the competent supervisory authority without undue delay and, where required, affected individuals, in line with applicable law (including GDPR Arts. 33 and 34 where they apply). Where we process Customer Personal Data as a processor, we will notify the customer controller as described in our DPA.

12. Automated decision-making

We do not make decisions that produce legal effects or similarly significant effects on you based solely on automated processing within the meaning of Art. 22 GDPR. Scanning, Findings, severity labels, and fix prompts are informational tools; you decide how to act on them.

13. International transfers

AtRisk is operated with infrastructure and vendors that may process data in the United States, the European Economic Area, and other countries. Where personal information is transferred across borders, we take steps intended to provide an appropriate level of protection consistent with applicable law, which may include Standard Contractual Clauses (SCCs), adequacy decisions, or provider certifications (such as Data Privacy Framework participation where applicable). Contact contact@atrisk.dev for more detail on transfer mechanisms for a specific processor.

14. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, or export personal information; object to or restrict certain processing; withdraw consent where processing is consent-based; and lodge a complaint with a supervisory authority (for example the UK Information Commissioner's Office, or your local EEA supervisory authority).

14.1 Account and marketing controls

  • Update account profile details in the app where available
  • Delete your account via in-app account deletion where offered (removes app profile data; complete auth-provider erasure may require additional steps we will assist with)
  • Disconnect GitHub or revoke App permissions in GitHub settings
  • Revoke MCP tokens and team seats in-product
  • Manage or cancel subscriptions through the billing portal / account settings
  • Unsubscribe from marketing emails using the link in those emails
  • Clear free-tool local storage via your browser

14.2 Privacy requests

Email contact@atrisk.dev with the subject "Privacy Request." We may need to verify your identity before fulfilling a request. We aim to respond within thirty (30) days (or sooner where law requires), extendable where permitted. Some requests may be limited where we must retain data for legal or legitimate operational reasons (for example fraud prevention or tax records).

14.3 US state privacy (including CCPA/CPRA)

If you are a resident of California or another US state with similar laws, you may have rights to know/access, delete, correct, and obtain a portable copy of personal information, and to opt out of "sale" or "sharing" for cross-context behavioral advertising. Categories of personal information we collect are described in Section 3. We do not sell personal information for money. We share limited visitor and lead identifiers with Reddit for advertising measurement as described in Sections 7 and 8.4; GPC is treated as an opt-out of that sharing. We do not use or disclose sensitive personal information to infer characteristics about you. You may designate an authorized agent to submit requests subject to verification. We will not discriminate against you for exercising privacy rights.

15. Children's privacy

AtRisk is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

16. Third-party links and services

Our sites and app may link to third-party websites or services (including AI coding agents, GitHub, Polar checkout, model providers, and social profiles). Their privacy practices are governed by their own policies. We are not responsible for third-party practices.

17. No sale; advertising measurement; no foundation-model training

We do not sell personal information for money or other valuable consideration. We share limited identifiers with Reddit for advertising measurement and optimization as described in Sections 7 and 8.4; that sharing is not a sale for money, but it may be "sharing" under some US state privacy laws. GPC opts you out. We do not use Customer Content to train third-party foundation models except as necessary to generate the specific Output you requested, as required by law, or as otherwise disclosed in this Policy and provider terms.

18. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date on this page and, where appropriate, provide additional notice (for example by email or in-product notice). Continued use of the Services after the effective date means you acknowledge the updated policy.

19. Contact

Questions or privacy requests:

We aim to respond within a reasonable timeframe and within statutory deadlines where they apply.

This Privacy Policy is effective as of September 9, 2026 and applies to atrisk.dev, app.atrisk.dev, and related AtRisk services. This is product-aligned privacy copy - have counsel review before relying on it for regulated or enterprise deals.