Privacy policy
Last updated: 5 October 2026
Draft, not yet reviewed by a lawyer
This text was written by an AI assistant from public guidance. It is not legal advice and must be reviewed by a qualified lawyer before launch.
1. Who we are
Signoffly is a service that reads a public GitHub repository, or looks at a public website the way a browser does, and writes a report on security, testing, code quality and privacy risk. It is run by Arif Noviarrizal ("we", "us"). We decide why and how the personal data described here is used, which makes us the controller of that data.
You can reach us at arifnoviarrizal@gmail.com for anything in this policy.
2. The data we handle
| Kind of data | What it includes | Where it comes from |
|---|---|---|
| Account | Your email address, your name and the identifier of your GitHub or Google account. We only accept an email that GitHub or Google has verified. | GitHub or Google, when you sign in |
| Scan requests and results | The repository you asked us to scan (owner, name, branch, commit) or the host name of the website you asked us to check (never the rest of the address), the legal regions you chose, the status, score and verdict, and the findings: rule, severity, file paths, line numbers and a short excerpt with secrets masked. | You, and our analysis of the repository |
| Orders and passes | The repository, the currency and amount, a payment reference, the status and the dates. | You, when you order a project pass |
| Technical data | Our server logs record the method, address path, result code and duration of each request. Our hosting providers may also log your IP address and browser details. | Your browser |
| Messages | What you write to us by email, and your email address. | You |
We do not use advertising or analytics trackers, and we do not use cookies to follow you around the web.
When you paste a link that we cannot scan, for example a live website, we add one to an anonymous daily count for that type of link, so we know what to build next. The link itself is not stored.
3. What happens to the code you scan
To scan a public repository we download a temporary copy, read it as text, and delete the copy when the scan ends. We never run your code.
We keep only the findings and the short excerpts needed to show you where a problem is. Before an excerpt is stored, we shorten it and mask anything that looks like a secret. Our logs do not contain your code or secrets.
We only scan public repositories for now. Public code is already visible to anyone, and we still treat what we read from it with care.
To check a website, our server opens its home page and the script files that page loads from the same address, once over https and once over http, the way a browser does. We do not sign in, fill in forms or try to get into anything, and we refuse addresses that are not public websites. We keep the host name, the findings and short excerpts with secrets masked, and not the pages themselves.
4. Why we use your data
| What we do | Why we are allowed to |
|---|---|
| Create your account, run your scans and show you the results | It is needed to provide the service you asked for |
| Sell and activate project passes, and keep payment records | It is needed to provide what you bought, and to meet accounting and tax rules |
| Keep the service secure, apply usage limits, prevent abuse and fix problems | It is in our legitimate interest to run a safe service, and security duties may also require it |
| Answer your messages and requests about your data | It is in our legitimate interest, and the law may require us to answer |
| Count the kinds of links people try that we cannot scan yet | It is in our legitimate interest to improve the product, and the counts are anonymous |
Where the law of your country says we need your consent for something, we will ask for it first.
6. Where your data is processed
Our database is in Singapore. Our servers and providers may be in other countries, so your data may cross borders, including when you use Signoffly from outside the country where it is processed. Where the law requires safeguards for such transfers, we use them.
7. How long we keep it
- Your account, scans, reports, orders and passes: until you delete your account. You can do that yourself on your account page, and everything tied to the account is deleted with it.
- Records of payments that are kept outside the app, such as bank records and our own accounting: as long as accounting and tax rules require.
- Messages you send us: as long as we need them to deal with your request.
- Backups: copies disappear when the backups expire.
8. Your rights
Depending on where you live, you can ask us to:
- tell you what data we hold about you and give you a copy
- correct data that is wrong
- delete your data
- limit or stop how we use it
- send it to you in a form you can reuse
- stop relying on your consent, if that is what we rely on
To use any of these rights, email arifnoviarrizal@gmail.com from the address on your account. We may ask you to prove who you are. We answer as quickly as we can, and within the time the law requires.
Downloading your data and deleting your account: you can do both yourself on your account page. You can also email us.
You can also complain to the data protection authority in the place where you live.
10. How we protect your data
We use encrypted connections, we limit who and what can reach our systems, we mask secrets before we store anything, and we keep a copy of your repository only while the scan runs. No system is perfectly secure. If a breach affects your data, we will tell you and the authorities as the law requires.
11. Children
Signoffly is not meant for children, and you must be at least 18 to use it. We do not knowingly collect children's data. If you think a child has given us data, contact us and we will delete it.
12. Changes to this policy
We will update this policy when the product or the law changes, and we will change the date at the top. If a change matters to you, we will tell you in the service or by email before it takes effect. This version was last updated on 5 October 2026.
13. Contact
Arif Noviarrizal, arifnoviarrizal@gmail.com.