Privacy policy

Last updated 2 October 2026.

Who is responsible

QualityGate is operated by Dragutin Marjanović as a sole proprietor, who is the controller of the personal data described here. For anything about your data, write to privacy@qualitygate.dev.

What we collect

  • Account: your email address, display name, and a salted hash of your password if you set one.
  • Sign-in providers: when you use GitHub, GitLab, or Bitbucket, the provider's account identifier and the email address it reports.
  • Sessions: when each session started, when it was last used, and when it expires.
  • Organizations and teams: organizations you belong to, your role, and invitations you send, including the invited email address.
  • Projects and scans: connected repositories, allowed domains, the URLs scanned, and scan results such as findings, scores, and the page text and images needed to explain them.
  • Billing: the billing email and the Stripe customer and subscription identifiers. Card details go directly to Stripe and never reach our servers.
  • Server logs: IP address, request method, and URL for each API request, used for security and troubleshooting.

Why we use it

  • To provide the service you signed up for (contract): accounts, sign-in, organizations, scans, reports, and billing.
  • To keep the service secure and working (legitimate interests): rate limiting, abuse prevention, and diagnosing failures from logs.
  • To meet legal obligations: keeping billing and tax records.

We send only service emails, such as verification, password reset, invitations, and account notices. We do not sell personal data or use it for advertising.

Who processes it for us

  • Render hosts the application, database, and logs.
  • Stripe processes payments and subscriptions.
  • Resend delivers our emails.
  • GitHub, GitLab, and Bitbucket authenticate you when you choose them, and provide repository access you grant through the QualityGate GitHub App.
  • An AI model provider receives the scanned page's URL, text, images, and findings when AI analysis runs. It does not receive your account details.

Some of these providers process data outside the European Economic Area. Those transfers rely on the European Commission's Standard Contractual Clauses or the EU-US Data Privacy Framework, as each provider offers.

How long we keep it

  • Account, organization, and project data are kept while your account exists.
  • Sessions expire after 7 days without use and after 30 days at most.
  • When you delete your account, you are signed out at once and everything is permanently erased after 30 days. Signing in during those 30 days cancels the deletion. Organizations where you are the only member are erased with your account, and their Stripe customer is deleted, which ends any subscription.
  • Database backups kept by our hosting provider can contain erased data until they expire on its rotation schedule.
  • Stripe keeps billing records for the period the law requires.

Cookies

The QualityGate app sets one cookie, qg_session, to keep you signed in. It is strictly necessary, HTTP only, and secure, so it does not need consent. This marketing site sets no cookies, and we use no analytics, advertising, or tracking cookies anywhere.

Your rights

Under the GDPR you can:

  • Access and port your data: use Download my data in the app's account settings for a JSON copy.
  • Correct it: edit your profile in account settings, or write to us.
  • Erase it: use Delete account in account settings.
  • Restrict or object to processing, by writing to privacy@qualitygate.dev.
  • Complain to the data protection authority where you live or work.

We answer requests within one month.

Changes

When this policy changes, we update the date at the top. Material changes are also announced by email to account holders.