Skip to content
ScanMyApp

Legal

Data Retention Policy

Last updated: 3 October 2026

A security tool should keep as little of your data as possible. Here is exactly what we keep, and for how long.

Retention periods

DataHow long we keep it
Your source code (cloned repository or zip)Deleted as soon as the analysis is complete. Never executed, never copied to personal devices.
Scan and audit results, reportsKept for 24 months so you can download them again and compare with a re-scan. Deleted earlier on request.
Free scan requests (URL, email, IP hash)12 months, then deleted.
Audit requests that didn’t lead to an order12 months, then deleted.
Marketing consent and email addressUntil you unsubscribe, then removed from our mailing list.
Invoices and accounting records6 years, as required by UK law.
Emails you send usAs long as needed to answer you, and at most 24 months after our last exchange.

How your code is handled

  • Access is read-only, and you can revoke it at any time.
  • Each analysis runs in an isolated, disposable environment that is destroyed afterwards.
  • Your code is analysed statically: it is never run.
  • Engineers reviewing an audit see only the code needed, only for the time of the review.

Deleting your data earlier

Email scan@scanmyapp.dev from the address you used and we’ll delete your data, except what we must keep by law (such as invoices).