Privacy Policy

What we keep.

This page says what ShuriCode stores so it can check your code and show you the results.

Your account

We store the email you sign in with and the name you give us. Sign-in uses a code we send to that email. There is no password.

The app keeps you signed in with a session cookie on app.suricode.ai.

Your projects

We store the repositories you connect: name, clone address, and the branch we check. For GitHub and Bitbucket we keep the read-only connection that lets us list and clone. For a git address we keep the token or SSH key you gave us so we can clone again.

Each check fetches a private working copy onto our scanner. Tools and an AI reviewer read that copy to judge which findings are real. Nobody else has access to it.

Findings and keys

We store the findings, the plain explanations, scores, and the history of scans. If you create an agent key, we store a hash of it so the MCP server can recognise it. We show the secret once.

Mail

We email sign-in codes and, if you leave weekly mail on, a summary of what changed. We send mail through our mail provider.

Why we keep it

We use this data to run ShuriCode: to sign you in, to check the projects you added, and to show you the results. We do not sell it.

Contact

Questions about this policy: hello@suricode.ai.