Data practices
What data does AppTruth retain?
AppTruth retains account, integration, repository, billing, and scan-result data needed to provide the service, with a 30-day source-artifact lifecycle.
Reviewed by Uriel from AppTruth · Updated · 4 min read
Direct answer to “What data does AppTruth retain?”
AppTruth retains the account, integration, repository, billing, support, and scan-result records needed to provide the service. Prepared source artifacts and internal analysis artifacts are stored in encrypted private storage with a 30-day lifecycle; normalized scan results remain available in scan history until removed under applicable account and data processes.
Key points: What data does AppTruth retain?
- Source and internal analysis artifacts have a 30-day storage lifecycle.
- Completed scan findings and repository metadata support scan history.
- Users can request account deletion from Settings; the product states deletion occurs within 72 hours.
Data used to provide AppTruth
The service stores identity and profile information, GitHub installation and approved repository metadata, subscription state, scan status, normalized behavior findings, user review selections, and support records when a user contacts support. Operational records are also kept to run queues, enforce quota, recover scans, deliver notifications, and investigate failures.
Payment details are handled by Stripe rather than accepted directly by AppTruth’s billing API. Repository credentials and internal identifiers are not included in public scan-detail responses.
How long is repository source retained?
Prepared repository source, manifests, dependency-graph material, map inputs and outputs, and reducer artifacts are stored in encrypted, versioned, private object storage. The configured lifecycle for these artifacts is 30 days.
AI analysis uses background processing, which requires temporary provider-side response retention for polling. This should be considered separately from AppTruth’s own 30-day object-storage lifecycle when assessing data requirements.
Account deletion and authoritative policies
A signed-in user can submit an account deletion request from Settings using the required confirmation. The product states that the account and associated data will be deleted within 72 hours. Retention obligations may differ for billing, fraud prevention, legal compliance, or aggregated operational records, so users with contractual requirements should request the current privacy and security documentation before uploading sensitive repositories.
AppTruth data categories and stated retention behavior
| Data category | Why it is used | Stated handling |
|---|---|---|
| Prepared source artifacts | Repository analysis | Encrypted private storage with a 30-day lifecycle |
| Normalized scan results | Scan history and review | Available until applicable account or data removal |
| Account and billing records | Service operation | Subject to operational, legal, and contractual needs |
The SOURCE Data Review
A repository-risk checklist to complete before sending source to any analysis provider.
- Scope: Approve only the repository and branch material needed for the task.
- Observe: Identify what account, source, result, and support data the service uses.
- Understand: Review storage locations, subprocessors, encryption, and provider processing.
- Retain: Confirm source-artifact and result-retention periods.
- Control: Document deletion, revocation, and contractual escalation paths.
- Escalate: Obtain formal documentation before sharing regulated or highly sensitive source.
Trusted sources that inform this guide
These independent sources support the surrounding verification practices. AppTruth-specific product statements are product guidance and should be confirmed against current account or contractual documentation when formal assurance is required.
- NIST Privacy Framework — NIST. Provides a risk-based structure for identifying and managing privacy risk.
- Choosing permissions for a GitHub App — GitHub Docs. Explains how GitHub App permissions should be selected and limited to the access an integration needs.
Related questions about “What data does AppTruth retain?”
Are source artifacts and scan results retained for the same period?
No. The product states a 30-day lifecycle for prepared source and internal analysis artifacts, while normalized scan results support scan history until removed under applicable processes.
Is this article the authoritative AppTruth privacy policy?
No. Organizations should request the current privacy, security, subprocessor, and contractual documentation for formal review.