Signoffly

Privacy policy

Last updated: 5 October 2026

Draft, not yet reviewed by a lawyer

This text was written by an AI assistant from public guidance. It is not legal advice and must be reviewed by a qualified lawyer before launch.

1. Who we are

Signoffly is a service that reads a public GitHub repository, or looks at a public website the way a browser does, and writes a report on security, testing, code quality and privacy risk. It is run by Arif Noviarrizal ("we", "us"). We decide why and how the personal data described here is used, which makes us the controller of that data.

You can reach us at arifnoviarrizal@gmail.com for anything in this policy.

2. The data we handle

Kind of dataWhat it includesWhere it comes from
AccountYour email address, your name and the identifier of your GitHub or Google account. We only accept an email that GitHub or Google has verified.GitHub or Google, when you sign in
Scan requests and resultsThe repository you asked us to scan (owner, name, branch, commit) or the host name of the website you asked us to check (never the rest of the address), the legal regions you chose, the status, score and verdict, and the findings: rule, severity, file paths, line numbers and a short excerpt with secrets masked.You, and our analysis of the repository
Orders and passesThe repository, the currency and amount, a payment reference, the status and the dates.You, when you order a project pass
Technical dataOur server logs record the method, address path, result code and duration of each request. Our hosting providers may also log your IP address and browser details.Your browser
MessagesWhat you write to us by email, and your email address.You

We do not use advertising or analytics trackers, and we do not use cookies to follow you around the web.

When you paste a link that we cannot scan, for example a live website, we add one to an anonymous daily count for that type of link, so we know what to build next. The link itself is not stored.

3. What happens to the code you scan

To scan a public repository we download a temporary copy, read it as text, and delete the copy when the scan ends. We never run your code.

We keep only the findings and the short excerpts needed to show you where a problem is. Before an excerpt is stored, we shorten it and mask anything that looks like a secret. Our logs do not contain your code or secrets.

We only scan public repositories for now. Public code is already visible to anyone, and we still treat what we read from it with care.

To check a website, our server opens its home page and the script files that page loads from the same address, once over https and once over http, the way a browser does. We do not sign in, fill in forms or try to get into anything, and we refuse addresses that are not public websites. We keep the host name, the findings and short excerpts with secrets masked, and not the pages themselves.

4. Why we use your data

What we doWhy we are allowed to
Create your account, run your scans and show you the resultsIt is needed to provide the service you asked for
Sell and activate project passes, and keep payment recordsIt is needed to provide what you bought, and to meet accounting and tax rules
Keep the service secure, apply usage limits, prevent abuse and fix problemsIt is in our legitimate interest to run a safe service, and security duties may also require it
Answer your messages and requests about your dataIt is in our legitimate interest, and the law may require us to answer
Count the kinds of links people try that we cannot scan yetIt is in our legitimate interest to improve the product, and the counts are anonymous

Where the law of your country says we need your consent for something, we will ask for it first.

5. Who we share data with

We do not sell your personal data. We share it only with the providers that help us run the service, and where the law requires us to.

ProviderWhat it does for usWhere
GitHubSign-in, and reading the public repositories you ask us to scanUnited States and other countries
NeonThe database that stores accounts, scans and ordersSingapore

We also use providers that host our website and our servers. If you pay by bank transfer or QRIS, your bank handles the payment and we only see the details you send us.

Artificial intelligence: we do not currently send your code or your data to an AI model provider. Our reports are written from templates. If that changes, we will name the provider, say what is sent and where it is processed, and update this policy before we start.

We may disclose data to the authorities when the law requires it.

6. Where your data is processed

Our database is in Singapore. Our servers and providers may be in other countries, so your data may cross borders, including when you use Signoffly from outside the country where it is processed. Where the law requires safeguards for such transfers, we use them.

7. How long we keep it

  • Your account, scans, reports, orders and passes: until you delete your account. You can do that yourself on your account page, and everything tied to the account is deleted with it.
  • Records of payments that are kept outside the app, such as bank records and our own accounting: as long as accounting and tax rules require.
  • Messages you send us: as long as we need them to deal with your request.
  • Backups: copies disappear when the backups expire.

8. Your rights

Depending on where you live, you can ask us to:

  • tell you what data we hold about you and give you a copy
  • correct data that is wrong
  • delete your data
  • limit or stop how we use it
  • send it to you in a form you can reuse
  • stop relying on your consent, if that is what we rely on

To use any of these rights, email arifnoviarrizal@gmail.com from the address on your account. We may ask you to prove who you are. We answer as quickly as we can, and within the time the law requires.

Downloading your data and deleting your account: you can do both yourself on your account page. You can also email us.

You can also complain to the data protection authority in the place where you live.

9. Cookies and similar storage

We use only what the site needs to work:

  • a session cookie that keeps you signed in
  • a security cookie that protects the sign-in form against forged requests
  • a short-lived cookie that remembers where to send you after you sign in
  • your choice of light or dark theme, saved in your browser

None of these is used for advertising or tracking.

10. How we protect your data

We use encrypted connections, we limit who and what can reach our systems, we mask secrets before we store anything, and we keep a copy of your repository only while the scan runs. No system is perfectly secure. If a breach affects your data, we will tell you and the authorities as the law requires.

11. Children

Signoffly is not meant for children, and you must be at least 18 to use it. We do not knowingly collect children's data. If you think a child has given us data, contact us and we will delete it.

12. Changes to this policy

We will update this policy when the product or the law changes, and we will change the date at the top. If a change matters to you, we will tell you in the service or by email before it takes effect. This version was last updated on 5 October 2026.

13. Contact

Arif Noviarrizal, arifnoviarrizal@gmail.com.