Privacy policy
Last updated Jun 11, 2026
This policy describes how Logorythm processes personal data in compliance with Brazil's Lei Geral de Proteção de Dados (LGPD) and the EU General Data Protection Regulation (GDPR). The structure follows sections commonly required for transparency to data subjects.
1. Data controller.
The controller of personal data described in this policy is Logorythm, operator of Logorythm Cloud at logorythm.io and dashboard.logorythm.io.
For privacy questions, exercising your rights, or contacting our data protection contact, use [email protected].
2. Categories of personal data.
We process only the data needed to operate the service, in the categories below.
2.1. Account and identity data.
Your GitHub identity (username, email, and avatar) used to authenticate you and link your workspace.
2.2. Derived architecture data.
Service graph, communication between components, metrics, and metadata extracted from authorized repositories. Does not include storage of source code.
2.3. Billing data.
When you subscribe to a paid plan, Stripe processes payment on our behalf. We do not store card numbers or full payment details in our systems.
3. Data we do not process.
We do not store source code: it is analyzed ephemerally and discarded after each scan.
We do not use third-party trackers, ad pixels, or behavioral profiles on the landing site or in the authenticated app.
4. Purposes and legal bases.
We process personal data for the purposes and on the legal bases listed below, under LGPD Art. 7 and GDPR Art. 6.
4.1. Performance of contract.
Authenticate your account, run scans, maintain the architecture graph, process billing, and provide support related to the subscribed service.
4.2. Legitimate interests.
Operate, protect, and improve service security, prevent abuse, and maintain audit records necessary for operations.
4.3. Consent.
When the basis is consent (for example, marketing communications in a separate flow), you may withdraw it at any time without affecting prior processing based on valid consent.
5. Sharing and subprocessors.
We share personal data only with subprocessors that provide essential services to us, under contracts that impose confidentiality and protection obligations consistent with this policy.
Main subprocessors include edge and compute hosting providers, object storage, Stripe (payments), and GitHub (authentication and repository reads). We keep the list current and provide it on request through our contact channel.
6. International transfers.
Some subprocessors may process data outside Brazil or the European Union. In those cases, we use adequate contractual safeguards, such as standard data protection clauses, to maintain a level of protection consistent with LGPD and GDPR.
7. Retention and deletion.
Graph and account data are retained while your account is active. When you request account deletion, we remove your data within our operational window, except where law requires retention for a set period.
Because source code is never stored, there is no retention of repository files after a scan completes.
8. Your rights.
Under LGPD Art. 18 and GDPR Arts. 15–22, you may request confirmation of processing, access, correction, anonymization, portability, erasure, information about sharing, withdrawal of consent, and review of automated decisions where applicable.
To exercise any right, write to [email protected]. We respond within applicable legal deadlines and may request information to verify your identity.
10. Changes to this policy.
We may update this policy to reflect changes to the service or applicable law. We publish the new version on this page with the update date and, when the change is material, notify account holders by email.
11. Contact.
Privacy questions or rights requests: [email protected].