LEGAL
Privacy Policy
Last updated: 7 September 2026
Mapnostics analyses source code repositories to provide codebase intelligence. This policy explains what data we collect, how we use it, and the choices you have. The short version: we access your repositories read-only, indexed code is stored encrypted at rest and purged when you delete a repository or your account, and we never sell your data.
01Data we collect
When you sign in with GitHub and connect a repository, we collect:
- Account information from GitHub: your username, email address, and avatar.
- Repository metadata: file paths, function and symbol names, import relationships, and git history (commit metadata, authorship, and file-level activity).
- Code embeddings: vector representations of code used for semantic search. Indexed code itself is also stored, encrypted at rest, so we can keep analyses up to date without re-reading your repository on every request.
- Analysis results: dead code flags, health scores, impact simulations, and reports you generate.
- Usage data: pages visited and features used, collected via privacy-respecting analytics.
02How we use your data
We use collected data solely to provide and improve the Mapnostics service: generating analyses, keeping them up to date, and producing the reports you request. Code-derived data is processed by our AI providers to generate analyses; these providers are contractually prohibited from training models on your data.
We never sell your data or share it with third parties for advertising.
03Repository access
Mapnostics requests read-only access to the repositories you explicitly connect. We never write to your repositories, and you can revoke access at any time from your GitHub settings or by disconnecting the repository in Mapnostics.
04Data storage and security
Data is stored in managed Postgres infrastructure hosted in the Asia-Pacific region, protected by row-level security so each account can only access its own data. Access tokens and indexed code content are both stored encrypted (AES-256-GCM) and are never exposed to the browser. Deleting a repository or your account permanently purges every stored chunk of its code.
05Cookies and consent
When you first visit the marketing site, a banner asks you to accept or reject cookies. We store your choice in your browser’s local storage, not in a cookie, so we can honour it on later visits.
If you accept, we load privacy-respecting product analytics (Vercel Analytics and Speed Insights) and set one first-party cookie that records which channel brought you to the site, so a later signup can be attributed to it. If you reject, none of these load and no analytics cookie is set. Cookies that are strictly required to keep you signed in are always set, because the app cannot work without them.
You can change your choice at any time using the “Cookie settings” link in the site footer, or by clearing site data in your browser.
06Sharing and public reports
Analysis data is private to you and the team members you invite. If you create a shareable report, anyone with the link can view that report without logging in — only share report links with people you trust.
07Data retention and deletion
You can delete an individual repository’s data or your entire account from Settings. Deletion is immediate and permanent. If you revoke GitHub access without deleting your account, previously computed analyses remain until you delete them.
08Changes to this policy
We may update this policy as the product evolves. Material changes will be announced in the app before they take effect. Continued use of Mapnostics after changes take effect constitutes acceptance.
Questions about this policy? Contact us at support@mapnostics.com.