← Back to Backpatch

Privacy Policy

Last updated August 29, 2026

The short version

We collect the minimum needed to run the service and understand how the site is used. No advertising, no cross-site tracking, and we never sell your data.

Website analytics

When you browse this site, we record anonymous usage events: the page viewed, clicks on a few key buttons, an approximate timestamp, the referring URL, and your IP address (used for coarse geography and abuse prevention). To count returning visits we store a random identifier in your browser's local storage — it isn't a cookie and isn't shared with anyone.

These analytics only run after you accept them in the consent banner. If you decline, no events are sent. You can change your mind by clearing this site's local storage. Traffic events are automatically deleted after 90 days.

API usage

When you call the Backpatch API, we record per-day counts of requests by API key and which endpoint was called, plus one row per analysis describing what happened: when it ran, how long it took, whether it succeeded, which client made the call (MCP server, GitHub Action, direct API), whether a lockfile was included, which package manager the project uses, and how many of the overrides came back safe to remove, still needed, needing a major upgrade, or unknown. This powers your dashboard, our capacity planning, and our understanding of whether Backpatch is actually finding things worth removing.

That record describes what happened, not what you analyzed. We do not store your package.json or lockfile contents, the names or versions of your dependencies, your repository name or URL, or your source code — none of it is retained beyond the time needed to answer the request.

Signing in

The dashboard is reached by signing in with GitHub or Google. We store the provider you used, the stable account identifier that provider gives us, and the verified email address on that account — never your password, and never any other profile data. Your API key is not a login credential, so losing it does not lock you out.

Signing in creates a browser session, stored only as a hash so it cannot be reused if our database were ever exposed. Sessions expire after 30 days and are deleted after that; signing out deletes yours immediately.

Account & billing

If you buy a plan, we store your email, your API key (hashed — we can't recover the original), the Stripe customer and subscription identifiers needed to manage your subscription, and a few dates marking your progress through the service: when your trial began, when your key was created, when you first ran an analysis, when an analysis first found something removable, when you last ran one, and when you became a paying customer. Payment details are handled entirely by Stripe; we never see your card number.

Who we share with

We use Stripe for payments, GitHub and Google for sign-in, and a managed Postgres database to store the data above. Signing in tells your chosen provider that you signed in to Backpatch; we request only your profile identifier and verified email address. We disclose data only as required to operate the service or comply with the law.

Your choices

Decline analytics in the banner, or contact us to access or delete your data. Reach us at [email protected].