Legal
Data Retention Policy
Last updated: 3 October 2026
A security tool should keep as little of your data as possible. Here is exactly what we keep, and for how long.
Retention periods
| Data | How long we keep it |
|---|---|
| Your source code (cloned repository or zip) | Deleted as soon as the analysis is complete. Never executed, never copied to personal devices. |
| Scan and audit results, reports | Kept for 24 months so you can download them again and compare with a re-scan. Deleted earlier on request. |
| Free scan requests (URL, email, IP hash) | 12 months, then deleted. |
| Audit requests that didn’t lead to an order | 12 months, then deleted. |
| Marketing consent and email address | Until you unsubscribe, then removed from our mailing list. |
| Invoices and accounting records | 6 years, as required by UK law. |
| Emails you send us | As long as needed to answer you, and at most 24 months after our last exchange. |
How your code is handled
- Access is read-only, and you can revoke it at any time.
- Each analysis runs in an isolated, disposable environment that is destroyed afterwards.
- Your code is analysed statically: it is never run.
- Engineers reviewing an audit see only the code needed, only for the time of the review.
Deleting your data earlier
Email scan@scanmyapp.dev from the address you used and we’ll delete your data, except what we must keep by law (such as invoices).
