Privacy Policy
Last updated: September 2026
1. Information We Collect
We collect information you provide directly: email address, password (stored as a bcrypt hash), and name or profile display name. We also collect usage data including searches, monitor activity, news interactions, and technical data such as IP address, browser type, and session information.
2. How We Use Information
Your information is used to provide and improve Catalayer services, manage your account and subscriptions, deliver monitor alerts and matched results, prevent abuse and enforce platform rules, and comply with legal obligations.
3. Cookies and Authentication
Catalayer uses session cookies (cl_session) for authentication. These are httponly, secure, and samesite=lax cookies that maintain your login state. We do not use third-party tracking cookies or cookies for targeted advertising.
4. Billing and Third-Party Services
Payment processing is handled by Stripe. We store your Stripe customer ID and subscription status but do not store credit card numbers. Email delivery is handled by Resend.
5. Data Retention
Account data is retained while your account is active. Operational data and news headlines are retained to provide ongoing search and platform capabilities. You can request account deletion at any time.
6. Security
All data is encrypted in transit using HTTPS/TLS. Passwords are hashed with bcrypt. Session tokens are generated using cryptographically secure random bytes. Access to production systems is restricted to authorized personnel.
7. Browser Extensions & Catalayer Code Inspector
Source Finder Extension: Catalayer Find Suppliers runs on supported marketplace domains so it can identify product pages and keep the side panel synchronized with the active page. On pages within these domains, it may read the page URL and, when present, visible product identifiers or product context, including product and variant changes, before a supplier search is started. This information is used only for product detection, extension state, and Catalayer supplier-matching functionality. The extension does not read or collect browsing content from unrelated websites. It sends product title, image URL, and price to Catalayer servers for supplier matching. It does not access cookies from third-party sites or track browsing activity.
Catalayer Code Inspector Extension: The GitHub AI Code Inspector Chrome side panel extension inspects public GitHub repositories, pull requests, and source files for security, quality, and AI-agent risks.
Catalayer ID & Authentication: When you sign in with your Catalayer ID via the browser handoff (accounts.catalayer.com), the extension receives and securely stores an authenticated session token in local browser storage. This credential is used solely to authenticate API requests with Catalayer servers (api.catalayer.com), retrieve your account profile (user_id, email, display_name), verify your entitlement tier, and synchronize inspection history across devices.
Authoritative Server-Side Scanning: The current Catalayer Code inspection pipeline uses deterministic server-side analysis via HTTPS requests to api.catalayer.com. The extension transmits public repository identifiers, pull request numbers, or source diff snippets necessary to evaluate the requested code and returns structured analysis findings. Repository content submitted for inspection is not sent to third-party AI model providers.
GitHub Personal Access Tokens (PAT): If you optionally provide a GitHub Personal Access Token in the extension settings to raise GitHub API rate limits, the token is stored strictly in your local Chrome browser storage. The token is used exclusively for direct, client-to-GitHub HTTPS calls (api.github.com and raw.githubusercontent.com). Your GitHub PAT is never transmitted to, processed by, or stored on Catalayer servers.
Anonymous Installation Identifier: For users who use the extension without signing in, the extension generates a random anonymous installation identifier (anonymous_client_id) stored locally in Chrome. This identifier is used solely to enforce anonymous usage quotas and allow claiming previous inspections when you subsequently sign in with a Catalayer ID.
No Sale or Advertising: Catalayer does not sell, rent, or monetize your personal data or repository inspection metadata to third parties. We do not use your information for targeted advertising, credit evaluation, or lending eligibility.
Security & Encryption: All communications between the extension, GitHub APIs, and Catalayer servers are encrypted in transit using industry-standard HTTPS/TLS. Passwords and sensitive server-side credentials are cryptographic hashes; extension session credentials can be revoked immediately upon sign-out.
Data Retention & Deletion: Catalayer may store inspection records to provide inspection history and synchronization. We do not currently publish a fixed automatic retention period for Code inspection records. You can sign out of Catalayer ID and remove locally stored GitHub credentials from the extension settings at any time.
Support & Inquiries: For questions, troubleshooting, or technical assistance regarding Catalayer Code and the extension, visit https://docs.catalayer.com/code/support or report community issues at https://github.com/stephenywilson/GitHub-AI-Code-Inspector/issues.
8. Your Rights
You may request access to your personal data, correction of inaccurate data, deletion of your account and associated data, or export of your data. Inquiries can be submitted via the Support portal at https://docs.catalayer.com/code/support or through project channels at https://github.com/stephenywilson/GitHub-AI-Code-Inspector/issues.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated through the platform or by email. Continued use of Catalayer after changes constitutes acceptance.
10. Contact
For privacy-related questions, account inquiries, or technical support, visit our Support portal at https://docs.catalayer.com/code/support or report issues at https://github.com/stephenywilson/GitHub-AI-Code-Inspector/issues.