Privacy Policy

Last updated August 2026

This policy explains what Proof of Concept ("we") collects when you use the service, why, the legal basis for it, who we share it with, and the control you have over it. It applies to proofofconcept.fun.

What we collect

Your account. Your email address and a securely hashed password (we never store your password in plain text). If you sign in with Google or GitHub, we store the identifier, display name and avatar that provider gives us, using only a verified email address.

The code you submit. When you scan an app we make a temporary copy of its source to analyse it, and we store that copy so you and any reviewer can browse the findings. We do not ask for or store your production database credentials.

Billing. If you subscribe, our payment processor handles your card details — we never see or store them. We keep a record of your plan, subscription status and payment history.

Usage. Basic technical logs (such as IP address and request times) needed to operate and secure the service.

Legal basis (EU/UK)

We process your data to perform our contract with you (providing the service), on the basis of our legitimate interests in operating and securing it, to comply with legal obligations, and — where required — with your consent.

How we use it

To run the security scan, show you the results, let a reviewer help you on the paid tiers, process payments, send you account and security emails, and keep the service secure. We do not sell your data, we do not use it for advertising, and we do not use your source code to train machine-learning models.

Who we share it with

We share the minimum necessary with service providers who process data on our behalf under contract:

  • Hosting and infrastructure (to run the application and database)
  • Payment processing (Stripe) — for subscriptions and billing
  • Email delivery (Resend) — for verification and account emails
  • Sign-in providers (Google, GitHub) — only if you choose to use them

We may also disclose data where required by law. We do not sell personal data.

Cookies

We use a single essential, httpOnly session cookie to keep you signed in. We do not use advertising or third-party tracking cookies.

Security

Passwords are hashed with bcrypt, traffic is encrypted in transit (HTTPS), sessions are stored as hashes, and access to stored code is limited to you and assigned reviewers. No method is perfectly secure, but we take reasonable measures to protect your data.

How long we keep it

Account data is kept while your account is open. Stored source code is retained so you can revisit a scan; deleting a project removes its stored code, and deleting your account removes your personal data. We may retain limited billing records where required by law.

International transfers

Some providers may process data outside your country. Where that happens we rely on appropriate safeguards (such as standard contractual clauses).

GitHub access

For private-repo import we use a GitHub App with read-onlyaccess to the repositories you explicitly grant. We never write to your repositories, and we never store a long-lived GitHub token — access tokens are short-lived and requested only when a scan runs.

Children

The service is not intended for anyone under 16, and we do not knowingly collect their data.

Your rights

You can access, correct, export or delete your personal data. If you are in the EU/UK you have rights under the GDPR, including the right to object and to lodge a complaint with your supervisory authority. Contact us at privacy@proofofconcept.fun to exercise them.

Changes to this policy

We may update this policy; material changes will be reflected by the "last updated" date above.

Contact

Questions about this policy: privacy@proofofconcept.fun.