tugtug reads repository files to compute code health metrics, then discards the source. Only derived numbers and file paths are persisted.
We store
src/auth.ts)We do NOT store
View your analysis data via the dashboard. Contact us if you need an export.
Purge all team analysis data at any time from Team Settings. Irreversible.
Full audit logs showing who accessed what data and when. 90 days retention.
Ask us to delete your stored GitHub token so tugtug can no longer access the GitHub API on your behalf. To fully revoke OAuth access, also visit github.com/settings/applications.
We comply with GDPR Article 17 (right to erasure). EU customers can request data deletion at any time via the purge endpoint. Contact privacy@tugtug.com for GDPR requests.
tugtug is not currently SOC 2 certified. Contact us for security details or to discuss compliance requirements.
Data is currently stored in the US via Supabase. EU data residency is not currently available.
| Data Type | Retention | Deletable |
|---|---|---|
| Analysis metrics & hotspot data | Until purged | Yes — via purge |
| Health score history | Until purged | Yes — via purge |
| Audit logs | 90 days | Yes — via purge |
| Email digest logs | Until purged | Yes — via purge |
| Team record (name, slug) | 7 years | Kept for billing |
| Billing history | 7 years (legal) | Legal requirement |
Security questions: security@tugtug.com
GDPR / privacy requests: privacy@tugtug.com
Enterprise security reviews:Contact us and we'll provide a completed security questionnaire, architecture diagram, and compliance documentation.
Looking for how we handle personal data, cookies, and third-party processors? See our Privacy Policy.