What we keep, why, and how to have it removed. Short on purpose.
This page says what Left Unlocked keeps about you, why, and how to have it removed. Last updated 6 September 2026. Questions go to [email protected].
The free scan
We keep the address you scanned, the findings, the score, and the time, so that the report link keeps working and so that we can count scans in aggregate (the homepage shows numbers like how many scans ran last month; never which sites).
The scan itself sends read-only requests to the app you named. It never stores any of that app's data: the Supabase check asks for a row count only, the Firebase check asks for section names and one document with every field masked.
Your IP address is used in memory to rate-limit scans and is not stored with the scan.
Leaving your email
If you type your email into a form (after a scan, or on the pricing page), we keep the email, the app it was about, and which form it came from, so that we can tell you about monitoring. It goes into our own lead sheet and into a daily summary sent to the person who runs Left Unlocked.
We do not sell it, share it, or add it to anyone else's list. Ask and it is deleted.
Signing in with GitHub
When you sign in we store your GitHub id, username, display name, avatar address, and the email GitHub marks as primary. We use the email for alerts and nothing else.
We keep the token GitHub issues for your sign-in encrypted at rest. It is used to complete the sign-in and to read your account details; it is never used to read or write repositories.
A signed session cookie keeps you signed in. It is HttpOnly, sent only to our own site, and cleared when you sign out. During sign-in a short-lived state cookie guards against forged requests. There are no advertising or tracking cookies.
Monitoring
For each app you add we keep the address, every scan's findings and score, the results of a reachability check every five minutes, and a record of each alert we sent you and why.
Alerts and the owner's daily summary are sent through Resend, an email delivery service, to the email on your account.
Remove an app from your dashboard and its history goes with it.
Connecting a GitHub repository
Repositories are read through the Left Unlocked GitHub App, on the repositories you chose when you installed it. We read file contents to check them and keep only the findings: file paths, variable names, table names, and the first few characters of a secret. Never a whole file, never a secret's value.
If you ask for a fix pull request, the app writes a new branch named leftunlocked/… and opens a pull request from it. It never changes your default branch and never merges. Everything in that branch is generated from templates; a committed .env is deleted by path without its contents being read.
Uninstall the app on GitHub and we lose access at once; unlink the repository on your dashboard and its findings are deleted.
Hosting and analytics
Left Unlocked runs on Railway and sits behind Cloudflare. Both keep short-lived request logs (including IP addresses) for operating the service, as any host does.
We may use Cloudflare Web Analytics for visit counts. It sets no cookies, fingerprints no one, and stores no personal data.
Your choices
You can scan without an account and without leaving an email.
You can remove any app, unlink any repository, and sign out at any time from the dashboard.
To see, correct, or delete anything we hold about you, including your whole account, email [email protected] from the address on the account. It is done within a few days.
Left Unlocked is not directed at children.
Changes
When this page changes, the date at the top changes with it. Material changes are also mentioned in the next alert or summary email to affected accounts.