Data practices

What data does AppTruth retain?

AppTruth retains account, integration, repository, billing, and scan-result data needed to provide the service, with a 30-day source-artifact lifecycle.

Reviewed by Uriel from AppTruth · Updated · 4 min read

Direct answer to “What data does AppTruth retain?”

AppTruth retains the account, integration, repository, billing, support, and scan-result records needed to provide the service. Prepared source artifacts and internal analysis artifacts are stored in encrypted private storage with a 30-day lifecycle; normalized scan results remain available in scan history until removed under applicable account and data processes.

Key points: What data does AppTruth retain?

  • Source and internal analysis artifacts have a 30-day storage lifecycle.
  • Completed scan findings and repository metadata support scan history.
  • Users can request account deletion from Settings; the product states deletion occurs within 72 hours.

Data used to provide AppTruth

The service stores identity and profile information, GitHub installation and approved repository metadata, subscription state, scan status, normalized behavior findings, user review selections, and support records when a user contacts support. Operational records are also kept to run queues, enforce quota, recover scans, deliver notifications, and investigate failures.

Payment details are handled by Stripe rather than accepted directly by AppTruth’s billing API. Repository credentials and internal identifiers are not included in public scan-detail responses.

How long is repository source retained?

Prepared repository source, manifests, dependency-graph material, map inputs and outputs, and reducer artifacts are stored in encrypted, versioned, private object storage. The configured lifecycle for these artifacts is 30 days.

AI analysis uses background processing, which requires temporary provider-side response retention for polling. This should be considered separately from AppTruth’s own 30-day object-storage lifecycle when assessing data requirements.

Account deletion and authoritative policies

A signed-in user can submit an account deletion request from Settings using the required confirmation. The product states that the account and associated data will be deleted within 72 hours. Retention obligations may differ for billing, fraud prevention, legal compliance, or aggregated operational records, so users with contractual requirements should request the current privacy and security documentation before uploading sensitive repositories.

AppTruth data categories and stated retention behavior

This summary is product guidance, not a substitute for current contractual or privacy documentation.
Data categoryWhy it is usedStated handling
Prepared source artifactsRepository analysisEncrypted private storage with a 30-day lifecycle
Normalized scan resultsScan history and reviewAvailable until applicable account or data removal
Account and billing recordsService operationSubject to operational, legal, and contractual needs

The SOURCE Data Review

A repository-risk checklist to complete before sending source to any analysis provider.

  1. Scope: Approve only the repository and branch material needed for the task.
  2. Observe: Identify what account, source, result, and support data the service uses.
  3. Understand: Review storage locations, subprocessors, encryption, and provider processing.
  4. Retain: Confirm source-artifact and result-retention periods.
  5. Control: Document deletion, revocation, and contractual escalation paths.
  6. Escalate: Obtain formal documentation before sharing regulated or highly sensitive source.

Trusted sources that inform this guide

These independent sources support the surrounding verification practices. AppTruth-specific product statements are product guidance and should be confirmed against current account or contractual documentation when formal assurance is required.

Related questions about “What data does AppTruth retain?”

Are source artifacts and scan results retained for the same period?

No. The product states a 30-day lifecycle for prepared source and internal analysis artifacts, while normalized scan results support scan history until removed under applicable processes.

Is this article the authoritative AppTruth privacy policy?

No. Organizations should request the current privacy, security, subprocessor, and contractual documentation for formal review.