home

Privacy

fasany is run by Hayo Bouma in the Netherlands. This page describes what the site stores. It is short because there is not much.

Scans

When you start a scan, the repository name, the ref, the scan results (file paths, line numbers, code snippets around each finding) and timestamps are stored and shown publicly on this site. Only public GitHub repositories can be scanned, so nothing that was not already public is published. Scans and their findings are deleted automatically after 30 days. Repository archives are downloaded to a temporary folder on the server and removed as soon as the scan finishes.

Rate limiting

To limit abuse, the number of scans started per IP address is counted in the server's memory for 15 minutes. IP addresses are not written to the database or to logs.

Accounts

Signing in is optional and only needed to mark findings as resolved. Sign-in goes through the central account service at auth.bouma.cloud. This site then stores your account id, display name, e-mail address and avatar URL so it can show who resolved what. Only the display name is shown publicly (on findings and the leaderboard); the e-mail address is never displayed. The session is an encrypted cookie that is only used to keep you signed in.

Cookies and tracking

There are no analytics, no advertising and no third-party scripts. The only cookies are the session cookies set when you sign in. Fonts are bundled with the site, not loaded from a third party.

Third parties

Repository data is fetched from GitHub (GitHub, Inc.) using its public API. The server does not pass your IP address or any information about you to GitHub; the request comes from this site's own server.

Your rights and contact

Under the GDPR you can ask what is stored about you and have it corrected or deleted. To have a scan removed earlier than the 30 days, or an account record deleted, write to hbouma01@gmail.com.