Privacy
Last updated 11 October 2026
PreClone reads code so you don't have to run it. We keep as little about you as that takes, and nothing is sold or used for advertising. There are no analytics scripts or tracking cookies on this site.
When you check a repository by link
- Our server downloads the repository archive from GitHub, GitLab or Bitbucket, reads it in memory and throws the archive away. The code itself is never written to disk or kept.
- We store the report: the repo address, branch and commit, the findings, and the short excerpts of files that back each finding. Anyone with the report link can open it. Reports are marked noindex so search engines leave them out.
- If you're signed in, the report is tied to your account so it appears in your history. If not, it isn't tied to anyone. Reports are kept so their links keep working; they don't expire on their own yet.
- Package names and versions from the repo's manifests and lockfiles are looked up on the public npm registry and osv.dev to check for known malware and recently published versions.
Private repositories (Pro)
The access token you paste is sent once to the code host to download that archive. It is not stored, logged or sent anywhere else. Reports from private repositories are visible only to you, even if someone else has the link.
Zip files you upload
A zip or tarball you drop on the page is unpacked and analysed inside your browser tab. The files never reach our server. Only package names and version numbers go to our server, so it can check them against npm and osv.dev. Git, URL and file dependencies stay in your browser. Uploaded checks aren't saved; close the tab and the report is gone.
Your account
- Your email address, name, and a hash of your password (we never see or store the password itself).
- Each signed-in session records the IP address and browser it came from, so you can spot sign-ins that weren't you. A session ends when you sign out or after 30 days without use.
- API tokens are stored as a one-way hash. We show you a token once, when you create it.
- If you sign in with GitHub, we receive your GitHub name, email and avatar. We don't ask for access to your repositories.
Payments
Payments aren't switched on yet. Pro is a free preview: no card is asked for and no payment details are stored, only whether your preview is active. When payments start, Stripe will handle checkout, and this page will say so first.
Limits and abuse prevention
To enforce the free limit of 12 checks an hour without an account, we count requests per network. The counter is keyed by a salted hash of your IP address, never the address itself, and resets every hour. Old counters are deleted after two days.
Reports you flag
When you use “Report a problem”, we store your message, the report and rule it concerns, the email address if you chose to give one, and your account if you were signed in. We use it to fix rules and to reply to you.
Who else is involved
- Vercel hosts the site and runs the server code.
- Neon hosts the database.
- GitHub, GitLab and Bitbucket serve the repositories you ask us to check.
- The npm registry and osv.dev receive package names and versions, never your code or identity.
Deleting your data
Delete your account from Settings. That cancels any Pro subscription and removes your profile, sessions, tokens and private reports straight away. Reports of public repositories stay up without your name on them, because other people may already hold the link. If you want one of those taken down, ask and we'll remove it.
Questions or requests: use “Report a problem” under any report and leave an email address if you'd like a reply.