Privacy
Privacy
Last updated 3 September 2026
Version 1.0 — effective 3 September 2026
Who is responsible
Berat Gökdemir, an individual in Türkiye, operates EXC and is the data controller (KVKK: veri sorumlusu).
Contact for anything on this page: exc-analyzer@outlook.com. We answer every request within 30 days, free of charge. You do not need an EXC account to write to us.
Object to being listed
If you are a GitHub user or repository owner who appears on this site and you did not put yourself here, you can have it removed. Email exc-analyzer@outlook.com with your GitHub login, or use the takedown page. We remove it within 7 days. You do not have to give a reason, and you do not need an account.
If you never signed in but appear on this site
EXC shows public GitHub data about repositories and their contributors. Some of that is personal data, and you did not give it to us — we read it from GitHub's public REST, GraphQL and search APIs.
What we may hold about you:
- your GitHub login, and the repository names you own or contribute to
- repository metadata: stars, primary language, topics, last push date
- results of scans other people ran on your repositories: a score out of 100, the individual checks that produced it, and the date of the scan
What we do not hold about you: your email address, your avatar image file (avatars are loaded live from GitHub, we do not copy them), your real name, or anything from a private repository.
Why: to let developers compare the public security posture of open-source projects. Legal basis: legitimate interests, GDPR Art. 6(1)(f) / KVKK m.5/2-f. Our legitimate interest is making the public security signals of open-source projects comparable in one place.
How long: scan results are kept until the repository owner asks us to remove them, or until the result is 90 days old and nobody re-runs it — a nightly job deletes anything past that. A result we take down is erased entirely within 30 days. We do not keep a copy of GitHub's repository index — the Explore page queries GitHub live and stores nothing.
You can object at any time and we will honour it — see the box above. When we remove you we also add your GitHub login to a suppression list, so a later scan by someone else cannot put you back.
If you sign in
Sign-in is GitHub OAuth through Supabase Auth. Supabase performs the exchange with GitHub on its servers and issues a GitHub token to your browser. We never receive, log or store your GitHub token. All scan requests go straight from your browser to api.github.com.
We ask GitHub only for read:user. That is read-only access to public information. EXC cannot read your private repositories and cannot change anything on your behalf. Revoke at any time: https://github.com/settings/applications.
What we store when you sign in:
| Field | Where it comes from |
|---|---|
| GitHub numeric id, login, display name, avatar URL, account creation date | GitHub, at sign-in |
| Display name and bio (max 280 characters), if you change them | you |
| Accent colour, banner style, layout density | you |
| Privacy switches: private account, per-scan visibility | you |
| Reputation number | computed from your activity here |
| Posts, comments, follows, follow requests, upvotes, pins | you |
| Scan results you chose to save. Secret scans are never saved at all — the database refuses them | you |
| Items you bookmarked, and a record of who mentioned you | you |
| Abuse reports you file | you |
Legal basis: performance of the service you asked for — GDPR Art. 6(1)(b) / KVKK m.5/2-c. We do not ask for consent for this, because consent is not the right basis for it.
Scans you run
A scan is only published when you have push access to the repository it describes. If you scan a repository you do not work on, the result is shown to you and then discarded — it is never written to our database, so there is nothing about that repository or its owner for us to hold.
Scans run in your browser on your own GitHub token and your own GitHub rate limit. Results of Secret scan, Deep secret scan and User analysis are never sent to our database, and never shared. That is enforced by the database, not only by the website.
Results of the other commands are saved to a public database and shown to everyone. Marking a scan private does not unpublish it. The result describes the repository rather than you, so it stays; what the setting controls is whether your name is attached to it. To have a result removed altogether, use the takedown page.
We are still the data controller for what our code collects and for the results we publish, even though the code runs in your browser.
Where the data is
Our database and authentication run on Supabase. The website is hosted on Google Firebase Hosting. Both operate outside Türkiye. That makes this a cross-border transfer under KVKK m.9 and a third-country transfer under GDPR Chapter V.
We rely on the standard contractual clauses adopted by the European Commission, which both providers incorporate into their data processing terms, together with the technical and organisational measures those terms require. Neither provider is authorised to use the data for its own purposes.
- Supabase — Data Processing Addendum and Privacy Policy
- Google (Firebase) — Cloud Data Processing Addendum and Firebase Privacy and Security
- GitHub — your browser talks to GitHub directly whenever you scan. That exchange is between you and GitHub under their Privacy Statement; it does not pass through us.
If you want a copy of the clauses that apply to your data, write to us and we will send you what our providers give us.
Browser storage
No cookie banner appears, because none of this is used for advertising or cross-site tracking. We still have to tell you what is stored:
| Item | Purpose | Lifetime |
|---|---|---|
| Supabase auth token | keeps you signed in | until you sign out; kept after you close the browser only while “Keep me signed in” is ticked on the scan page, otherwise it is dropped with the tab |
GitHub access token (exc.github_token) | lets a scan run in your browser against your own GitHub account | session storage — dropped when you close the tab, and on sign out |
Cached profile (exc.profile) | avoids a round trip on every page | until you sign out |
Stay signed in (exc.stay-signed-in) | remembers whether you ticked “Keep me signed in” | until you change it |
Layout density (exc.density) | your chosen layout | until you clear it |
| Post draft | so you do not lose a half-written post | until you post or discard |
We run no analytics, no advertising, no error-reporting service and no third-party trackers.
Your rights
Under GDPR you can ask for access, correction, erasure, restriction, portability, and you can object to processing based on legitimate interests. Under KVKK m.11 you can learn whether your data is processed, ask what was done with it, ask for correction or deletion, ask us to tell third parties about a correction, object to a result reached about you by purely automated analysis, and claim compensation for damage.
To use any of these, email exc-analyzer@outlook.com. One month under GDPR, 30 days under KVKK, free of charge.
If you signed in, you can also delete everything yourself: Settings → Delete my account. That removes your profile, posts, comments, follows, bookmarks, mentions and your GitHub sign-in, immediately and without asking us. Scan results you saved stay, because they describe a repository rather than you — but your name is detached from them and cannot be recovered. If you want those removed too, ask us and we will delete them.
If you think we got it wrong, you can complain to your local data protection authority, or in Türkiye to the Kişisel Verileri Koruma Kurumu (kvkk.gov.tr).
Automated analysis
EXC scores repositories, not people. We do not publish an automated judgement about any individual. Where a command analyses a person's public activity, the result is shown only to the person who ran it and is never stored.
The scoring rules are hand-written and fixed. There is no trained or learned model anywhere in EXC.
KVKK Aydınlatma Metni (Türkçe özet)
Bu site İngilizce yayımlanmaktadır. Aşağıdaki özet, 6698 sayılı Kişisel Verilerin Korunması Kanunu kapsamındaki aydınlatma yükümlülüğü için Türkçe olarak sunulmuştur. Bağlayıcı ve ayrıntılı metin bu sayfanın İngilizce bölümleridir.
Veri sorumlusu: Berat Gökdemir, Türkiye. İletişim:exc-analyzer@outlook.com
İşlenen veriler: GitHub ile giriş yaparsanız GitHub kullanıcı numaranız, kullanıcı adınız, görünen adınız, profil fotoğrafınızın adresi ve hesap açılış tarihiniz; sitede yazdığınız gönderi ve yorumlar; takip, yer imi ve tercih kayıtlarınız. Giriş yapmadıysanız yalnızca herkese açık GitHub verileri gösterilir.
İşleme amacı ve hukuki sebep: Hesabınızı tanımlamak ve siteyi çalıştırmak. Hukuki sebep, KVKK m.5/2-c uyarınca hizmetin sunulabilmesi için gerekli olmasıdır. Verileriniz yurt dışında (Supabase, AB bölgesi) barındırılır.
Haklarınız: KVKK m.11 uyarınca verilerinize erişme, düzeltme, silme ve işlenmesine itiraz etme haklarına sahipsiniz. Yukarıdaki adrese yazmanız yeterlidir; 30 gün içinde ücretsiz yanıt veririz. Hesabınızı dilediğiniz an Profil → Close your account bölümünden kendiniz silebilirsiniz.
Siteye hiç üye olmadıysanız: Herkese açık bir GitHub deposu ya da kullanıcı adı burada görünüyorsa ve kaldırılmasını istiyorsanız, yukarıdaki adrese yazın. Gerekçe belirtmenize gerek yok, 7 gün içinde kaldırırız.
Not GitHub
EXC is an independent project, not affiliated with, endorsed by or sponsored by GitHub, Inc. EXC alone is responsible for the data it collects. EXC does not collect any personal data on GitHub's behalf.
Changes
The version and date at the top tell you which notice is in force. If we change something material we will say so on the site.