Privacy Policy
Who We Are
cupel is operated by Viktor Mares, a sole trader based in Burgas, Bulgaria, trading as cupel. For the personal data described here, Viktor Mares is the data controller.
Questions about this policy or your data: support@cupel.sh.
This policy covers the website at cupel.sh, the dashboard at app.cupel.sh, and the service at api.cupel.sh that the cupel command-line tool sends results to.
The Short Version
- Your source code is never collected. The scan runs on your own machine or in your own CI. What reaches us is the result: which advisories apply, which packages and versions, the verdict, and where in your code the relevant call sits — never the code itself.
- We don't use advertising or analytics trackers, and we don't sell your data.
- We don't count the people in your organisation, and never price on it.
- Card details go to Stripe and never reach us.
- You can delete your account, remove an organisation, and export your findings yourself, from the dashboard.
What We Collect and Why
Visiting cupel.sh
The website sets no cookies and runs no analytics. If you switch between light and dark themes, your choice is kept in your own browser's local storage and is never sent to us. Our hosting provider processes your IP address to deliver pages and protect the site from attacks.
Your Account
To give you an account: your email address, an optional display name you choose, and — if you sign in with GitHub — your GitHub account's numeric id, username and avatar address. If you register with an email address instead, we keep a salted, slow hash of your password; the password itself is never stored. Legal basis: performance of our contract with you.
Signing In and Keeping It Secure
A session cookie keeps you signed in; we store only a hash of its token, which expires after 14 days. Sign-in, registration and password-reset links are stored only as a hash, with the address they were sent to, and are deleted once they expire. Your IP address is used briefly to limit repeated requests and is not stored in our database.Legal basis: our legitimate interest in keeping accounts and the service secure.
Organisations and Workspaces
Their names, who belongs to them and in which role, and invitations. An invitation holds the invited person's email address or GitHub username until it is accepted, revoked, or expires after seven days — then that address is removed.Legal basis: performance of our contract.
Scan Results
When you or your CI send results: project names, advisory identifiers, package names and versions, verdicts, and file paths and call-site locations in your code. Alongside them, what you do in the dashboard — labels, triage decisions and notes, and policy rules — and a history of scans with counts per verdict. Legal basis: performance of our contract.
The GitHub Integration
If you install the cupel GitHub App, it can read the list of repositories you choose and their metadata, read your GitHub email address, and start the cupel workflow you added to a repository when you press Scan Now. It cannot read your repository's contents.
Billing
Payments are handled by Stripe. We keep your Stripe customer and subscription identifiers, your plan, and what the current billing period is for. Card details are entered with Stripe and never reach us. Legal basis: performance of our contract, and our legal obligation to keep accounting records.
Notifications
If you add a Slack or webhook destination, its address and signing secret are stored encrypted. Notifications send a short message — a repository name, what happened and a link — to the destination you chose.
The Activity Trail
A record of who did what, and when, inside an organisation — for example who removed a repository or changed a member's role — so an organisation can answer that question later.Legal basis: our and your legitimate interest in accountability.
Emailing Us
If you write to us, we keep the conversation to answer it and to follow up.Legal basis: our legitimate interest in responding.
What We Never Collect
- Your source code, syntax trees, or archives of it — on any plan.
- A count of the developers or committers in your organisation.
- Payment card data.
- Data from advertising or analytics trackers — there are none.
Cookies
The website sets none. The dashboard at app.cupel.sh sets the following, each needed to sign you in or to remember a choice you made there, so none requires consent. None is used for tracking.
cupel_session- Keeps you signed in. Expires after 14 days, or when you sign out.
cupel_oauth_state,cupel_install_state- Protect GitHub sign-in and App installation against forgery. Last only minutes.
cupel_theme- Remembers light or dark theme.
cupel_rail- Remembers whether you collapsed the side navigation.
cupel_org- Remembers the organisation you last opened.
Who Processes It
These companies process data on our behalf, only to run the service:
- Cloudflare
- Hosting for the website and the service, databases, file storage, domain names, and sending account emails.
- Stripe
- Payments and subscriptions.
- GitHub
- Sign-in with GitHub, and the GitHub App integration described above.
- Email hosting for messages you send to cupel.sh addresses.
We may also disclose data where the law requires it. We don't sell personal data or share it for advertising.
International Transfers
Some of these processors are based outside the European Economic Area, or process data there. Where that happens, the transfer relies on a recognised safeguard such as the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
How Long We Keep It
- Account data
- For the life of your account, then deleted within 30 days.
- Stored scan results
- 90 days on the Free plan, 12 months on paid plans — then deleted automatically. This applies even after you remove the project or organisation they belong to: removal deletes the findings, history and decisions in your dashboard straight away, but the stored results themselves are deleted when their retention period ends.
- Projects, findings and triage decisions
- Until you remove the project or organisation, when they are deleted.
- Sign-in and reset links
- Deleted shortly after they expire.
- Invitations
- Up to seven days, or until accepted or revoked.
- The activity trail
- Two years, or until the organisation is removed, whichever comes first.
- Billing records
- For as long as tax and accounting law requires.
- A record that something was deleted
- When you delete an account or remove an organisation, we keep a note that it happened, when, and who asked — with no name, address, repository or finding in it — so the deletion itself can be verified.
Your Rights
Under the GDPR you can ask us to:
- give you a copy of your personal data, and in a portable form;
- correct data that is wrong;
- delete your data;
- restrict how we process it, or object to processing based on legitimate interest.
Much of this you can do yourself: change your display name on your profile, delete your account, remove an organisation, and export findings as CSV or JSON. For anything else, emailsupport@cupel.sh — we answer within one month.
You can also complain to a data-protection authority. In Bulgaria that is the Commission for Personal Data Protection (Комисия за защита на личните данни) (cpdp.bg); you may instead contact the authority where you live or work.
Security
Passwords and access tokens are stored only as hashes, notification secrets are encrypted, all traffic is encrypted in transit, and each organisation's data is kept separate from every other's. To report a vulnerability, email security@cupel.sh.
Automated Decisions
cupel's verdicts are about your code, not about you. We make no automated decisions that have legal or similarly significant effects on a person.
Children
cupel is not intended for anyone under 18, and we don't knowingly collect their data.
Changes
If we change this policy in a way that matters, we'll tell account holders by email or in the dashboard before it takes effect. The date at the top shows the current version.