Legal
This policy explains what information AtRisk collects across URL scanning, monitors, Findings, GitHub connections, agents, MCP, teams, billing, analytics, free tools, and (where offered) public or unlisted reports - and the choices you have.
Last updated: September 9, 2026 · Effective: September 9, 2026
AtRisk ("AtRisk," "we," "us," or "our") operates the websites atrisk.dev and app.atrisk.dev, along with related free tools, APIs, emails, and the AtRisk product (the "Services").
AtRisk is a maintenance and security-assurance layer for AI-built apps: URL scanning, monitors, repository audits, Findings, fix prompts for AI coding agents, optional MCP and CI deploy-gate features, and related workflows.
For privacy requests, contact contact@atrisk.dev.
Our Terms of Service, Cookie Policy, DPA, and Subprocessors list should be read with this Policy. For security controls and disclosure, see our Trust Center.
For personal data about website visitors and account holders that we decide how to process, we act as a controller (or analogous "business" under US state privacy laws). For Customer Content you submit about third parties (for example content retrieved from a site you authorize us to scan), you are typically the controller / business and we process that data to provide the Services on your instructions under the Terms and our Data Processing Addendum. Business customers may also request a negotiated DPA by emailing contact@atrisk.dev.
This Privacy Policy applies to information we collect when you:
It does not apply to third-party websites, products, or services we link to or that you connect (except as described for our processors).
When you contact us, we collect your email, message content, attachments, and metadata needed to respond.
On atrisk.dev free tools, we may store your email in browser local storage for a limited period so you do not have to re-enter it. The app may use sessionStorage for pending scan URLs across authentication. Auth/session cookies or tokens keep you signed in. You can clear site data in your browser; blocking essential storage may break login.
We do not seek to collect sensitive personal information (as defined under GDPR Art. 9, CPRA, or similar laws) to infer characteristics about you. Do not submit government IDs, health data, precise geolocation, full card numbers, or unnecessary production secrets into free tools or prompts. If such data appears incidentally in scan evidence or support mail, we will handle deletion requests under Section 11.
Where the GDPR, UK GDPR, or analogous laws apply, we rely on:
We use personal information to:
To generate fix prompts, optional finding judgments, free-tool results, and similar Outputs, we may send relevant inputs and necessary context to third-party AI providers:
Those providers process content to return model Outputs under their terms. We do not use Customer Content to train third-party foundation models except as necessary to generate the specific Output you requested, as required by law, or as otherwise disclosed here and in provider terms.
Do not submit secrets, passwords, payment card numbers, government ID numbers, health data, or other highly sensitive personal data into prompts or free tools. You are responsible for the content you submit and the targets you authorize. AI Outputs and automated Findings may be inaccurate or incomplete - review before relying on them.
We use essential and functional technologies to operate the Services, including:
We also use product analytics and diagnostics that may set cookies or similar identifiers:
More detail is in our Cookie Policy. We do not use Microsoft Clarity or other marketing-site session-replay / heatmap tools. You can control cookies and site data through your browser settings. Blocking essential cookies or storage may prevent login or other core features. Where consent is required by law for non-essential analytics or advertising measurement, we will seek consent through a banner or similar mechanism when implemented; until then, you may use browser controls or contact us to object. If your browser sends Global Privacy Control (GPC), we do not load the Reddit Pixel and we do not send Reddit Conversions API events for that request.
We do not sell personal information for money. The Reddit Pixel shares technical identifiers (and, for email leads, a hashed email) with Reddit so we can measure and optimize Reddit Ads. Under some US state laws that may be "sharing" for cross-context behavioral advertising. GPC is treated as an opt-out of that sharing. Do Not Track is not a reliable signal and does not change processing by itself; email contact@atrisk.dev to object where applicable law allows.
We do not sell or rent your personal information. We share information with service providers to run AtRisk, and with Reddit for advertising measurement, including:
These providers are authorized to process data only to perform services for us and are subject to contractual or comparable confidentiality and security obligations. A current list is also published on our Subprocessors page. We may also share limited information with professional advisors under confidentiality, with authorities when required by law, and with successors in a merger or asset sale.
If you invite teammates or create shareable report links, the people who receive access can see the Customer Content and Findings you share. You are responsible for choosing recipients and for any personal data in those materials.
We may disclose information if we believe in good faith that disclosure is required by law, necessary to protect rights, safety, or security, or needed to investigate fraud or Terms violations.
When you visit atrisk.dev after seeing or clicking a Reddit ad (or otherwise while the pixel is active), we share event data with Reddit, Inc. for conversion measurement and campaign optimization: page URL, event type, technical identifiers (IP, user agent, pixel cookies / click IDs), and hashed email when you submit a free-tool lead. Reddit acts as an independent controller for that advertising measurement. See Reddit's privacy policy. GPC opts you out of this sharing as described in Section 7.
We retain personal information for as long as needed for the purposes above. Indicative periods:
Disconnecting GitHub stops new repository access; residual copies may remain in backups for a limited period. When retention is no longer required, we delete or anonymize information where reasonably practicable.
We use administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, access controls, least-privilege practices, monitoring, and vendor controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. A plain-language overview of current controls is on our Trust Center.
Please use a strong unique password, protect credentials and MCP tokens, enable available security features, and notify us promptly of any suspected unauthorized access. To report a vulnerability, see our vulnerability disclosure policy.
If a personal-data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the competent supervisory authority without undue delay and, where required, affected individuals, in line with applicable law (including GDPR Arts. 33 and 34 where they apply). Where we process Customer Personal Data as a processor, we will notify the customer controller as described in our DPA.
We do not make decisions that produce legal effects or similarly significant effects on you based solely on automated processing within the meaning of Art. 22 GDPR. Scanning, Findings, severity labels, and fix prompts are informational tools; you decide how to act on them.
AtRisk is operated with infrastructure and vendors that may process data in the United States, the European Economic Area, and other countries. Where personal information is transferred across borders, we take steps intended to provide an appropriate level of protection consistent with applicable law, which may include Standard Contractual Clauses (SCCs), adequacy decisions, or provider certifications (such as Data Privacy Framework participation where applicable). Contact contact@atrisk.dev for more detail on transfer mechanisms for a specific processor.
Depending on your location, you may have rights to access, correct, delete, or export personal information; object to or restrict certain processing; withdraw consent where processing is consent-based; and lodge a complaint with a supervisory authority (for example the UK Information Commissioner's Office, or your local EEA supervisory authority).
Email contact@atrisk.dev with the subject "Privacy Request." We may need to verify your identity before fulfilling a request. We aim to respond within thirty (30) days (or sooner where law requires), extendable where permitted. Some requests may be limited where we must retain data for legal or legitimate operational reasons (for example fraud prevention or tax records).
If you are a resident of California or another US state with similar laws, you may have rights to know/access, delete, correct, and obtain a portable copy of personal information, and to opt out of "sale" or "sharing" for cross-context behavioral advertising. Categories of personal information we collect are described in Section 3. We do not sell personal information for money. We share limited visitor and lead identifiers with Reddit for advertising measurement as described in Sections 7 and 8.4; GPC is treated as an opt-out of that sharing. We do not use or disclose sensitive personal information to infer characteristics about you. You may designate an authorized agent to submit requests subject to verification. We will not discriminate against you for exercising privacy rights.
AtRisk is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
Our sites and app may link to third-party websites or services (including AI coding agents, GitHub, Polar checkout, model providers, and social profiles). Their privacy practices are governed by their own policies. We are not responsible for third-party practices.
We do not sell personal information for money or other valuable consideration. We share limited identifiers with Reddit for advertising measurement and optimization as described in Sections 7 and 8.4; that sharing is not a sale for money, but it may be "sharing" under some US state privacy laws. GPC opts you out. We do not use Customer Content to train third-party foundation models except as necessary to generate the specific Output you requested, as required by law, or as otherwise disclosed in this Policy and provider terms.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date on this page and, where appropriate, provide additional notice (for example by email or in-product notice). Continued use of the Services after the effective date means you acknowledge the updated policy.
Questions or privacy requests:
Contact: contact@atrisk.dev
We aim to respond within a reasonable timeframe and within statutory deadlines where they apply.