Privacy
What Remedisees — and what we don't.
Remedi is a read-only GitHub App. We process repository metadata to detect published security advisories and open automated fix pull requests. This page describes exactly what that means for your data.
What we collect
- GitHub account basics. GitHub user ID, login, and avatar URL — used to attribute PR authors and render your dashboard.
- Repository metadata. The list of repositories you install the App on, default branch, and dependency manifests (package.json, requirements.txt, go.mod, Cargo.toml, and similar lockfiles). Read on demand — never cloned.
- Advisory matches.The affected package, installed version, and fixed version surfaced by GitHub's published advisory feed. No application source is persisted beyond the patch we propose.
- Operational logs.Timestamped request logs from GitHub's webhook delivery (delivery ID, repository, event type) retained for 30 days to debug delivery failures.
What we never collect
- Full Git history, source trees, or any file outside a supported manifest.
- Secrets, environment variables, or CI configuration.
- Issues, pull-request contents, comments, or reviewer messages.
- Cross-site browsing history, third-party cookies, or advertising identifiers.
How long we keep data
Dependency snapshots are recomputed on every scan and the previous snapshot is discarded. GitHub account basics persist for the lifetime of the installation and are deleted within 24 hours of the App being uninstalled. Operational logs auto-expire after 30 days.
Where we run
All processing runs on infrastructure hosted in the United States. We do not transfer your data to any third party other than GitHub itself, which is the source of the repository metadata we use.
Contact
Questions about this notice or requests for a copy of the data we hold can be sent to remedi-safe@polsia.app. We respond within five business days.