Last updated: 4 October 2026
GitHub Repo QA is a read-only repository quality and release-readiness service. It processes GitHub account and repository identifiers, repository metadata, selected repository text files used by the checks, workflow run statuses, branch and issue/PR timestamps, Marketplace plan state, and generated audit findings.
We do not request repository write access, collect or store secret values, read secret scanning alert values, or sell data. Selected dependency names and pinned versions may be sent to public npm and PyPI metadata endpoints solely to compare current versions. GitHub OAuth access tokens are used during sign-in and are not stored. GitHub App installation tokens are short lived and held in process memory only.
Audit results and installation metadata are stored in a local SQLite database on the service host. Uninstalling the GitHub App deletes the installation's stored repository and finding data. Marketplace cancellation returns the account to the Free plan unless the app is uninstalled. Contact the support address in the GitHub Marketplace listing for data or privacy requests.
Repository file contents are read into memory only while checks run and are not persisted; reports store findings, metadata, and timestamps. The service uses secure, HTTP-only session cookies and signed GitHub webhooks. The operator should publish this policy at the service's HTTPS /privacy URL before listing.