libyears

Privacy

Draft, not yet reviewed by a lawyer. This document describes what the product actually does and is accurate on the facts, but it has not been checked for enforceability or for whether it covers what it needs to. Do not rely on it, and do not treat it as a contract offer.

Libyears is a business tool that reads dependency manifests. It holds very little personal data, and this page says exactly what and why rather than reserving rights we do not exercise.

The personal data we hold

There are three pieces, and this is all of them.

  • Your email address, because an account needs one and because the weekly digest goes somewhere.
  • Your GitHub user id and login, recorded when you install the app, so we know who authorised the installation.
  • Email addresses you add for client notifications, which receive the digest and nothing else. They grant no access to the product.

We do not ask for your name, your address, your phone number, or your job title. We do not collect commit authorship, so we never learn who wrote what.

What we do not do

No analytics, no session recording, no advertising or tracking pixels, no cookie banner because there is nothing to consent to beyond the session cookie that keeps you signed in. The dashboard loads no third-party script.

Nothing is sent to any AI model. No customer data is used to train anything, ours or anyone else’s, and we do not sell or share data with anyone outside the subprocessors who operate the service.

Repository data, which is not personal data but is yours

We read manifests and lockfiles, and store the dependency inventory they describe. We do not read, store or transmit your source code. The complete list of paths we will ever fetch is on the security page, generated from the allowlist the scanner actually uses.

Private package names never leave the system. Anything published to a private registry, resolved from a scope with its own registry, or defined inside your own workspace is counted and never named to any third party — not to the npm registry, not to an advisory database, and not in a client report or an export.

Credentials found in .npmrc, .yarnrc.yml or bunfig.toml are discarded before parsing. They are never stored or logged. If we find one we say so, because a token committed to a repository should be rotated whatever we do with it.

How long we keep it

Scan history is retained for the period your plan includes: 30 days on Free, up to two years on Agency. Older snapshots are deleted; the current inventory is not.

When you uninstall the GitHub App, that installation’s data is marked for deletion immediately and permanently erased within seven days. Removing a single repository from the installation does the same for that repository. An owner can delete an entire organisation from the settings screen without contacting us, on the same seven-day schedule.

The delay exists so an accidental uninstall does not destroy history that cannot be rebuilt. It is well inside the thirty days the GitHub Marketplace agreement allows. Every deletion is recorded, and we can produce that record if your client asks for evidence.

Where it lives

The United States: Supabase in AWS us-west-2 and Vercel in iad1. If you are in the EU or UK, transfers are covered by the standard contractual clauses in our providers’ data processing agreements.

We chose the United States because every upstream the scanner reads is hosted there, so colocating removes a transatlantic round trip from each request. If a client contract requires EU residency, that is available on the Enterprise plan.

Your rights

If the GDPR or UK GDPR applies to you, you have rights of access, rectification, erasure, restriction, portability and objection. Most of them are self-serve rather than a request form: your data is exportable as CSV or CycloneDX from any repository page, and deletion is a button in settings.

For anything that is not, or if you want the record of what we deleted, email privacy@libyears.com. We answer within 30 days and usually much sooner.

Where we act as a processor rather than a controller — which is the case for the repository data an agency holds about its clients — we act on your instructions, and a data processing agreement is available.

Security incidents

If customer data is exposed, we will tell affected customers what happened, what was exposed and what we did, without waiting to have a complete story first. A partial notification on the day beats a polished one a fortnight later.

Changes

Material changes are announced before they take effect. A new subprocessor is announced before it starts handling data, which is a commitment the subprocessor list exists to make checkable.