Privacy Policy
The short version. Your source code is analyzed and immediately deleted — we keep your report card, not your code, and we keep it under a pseudonym, not your name. Anonymized, aggregate stats from your scans (bin counts — never your code) keep everyone's grades calibrated. No client telemetry, no ad trackers, no selling data. One button deletes everything.
1. What we collect
- Account identity: the handle your key is issued to (your GitHub login for GitHub sign-in, or a chosen name), and your email if you contact us or it's part of your plan's billing. API keys are stored only as SHA-256 hashes.
- Report cards: scores, grades, gate outcomes, and findings (including file paths of flagged code) for the repositories you scan — stored under a pseudonymous account id derived one-way from your handle, so the stores themselves never contain your name.
- Operational data: request logs and service telemetry keyed by the same pseudonym, plus rate-limit counters by IP address for abuse protection.
- Cookies: an http-only session cookie when you log into the dashboard. No advertising or cross-site cookies.
- Waitlist email: if you join the beta waitlist we store the email you submit until you are invited or ask us to remove it (privacy@bench.fit). It is used only to invite you. So we can act on your signup quickly, the signup notification — including that email — is delivered to our founder operations feed on Slack (see section 5); it is not used for anything beyond inviting you.
2. What we never keep
- Your source code. Uploads are extracted to a temporary directory, scored, and deleted the moment scoring finishes — every scan, no exceptions.
- Your git history. The CLI computes git statistics locally;
.gitnever leaves your machine. - Client telemetry. The CLI phones home nothing; all measurement is server-side.
3. Plan-dependent visibility
On the Community plan, your handle is deliberately your public profile — that visibility is the price of free, and it is disclosed at signup and shown in your dashboard. Your scores remain private until you create a share link. On Vibe and Enterprise plans your identity is never displayed. Public share pages are opt-in, redacted (scores and structure only — never file paths or findings), and deletable.
4. Calibration — the community standard
BenchFit's grades only mean something if they're calibrated against how real code actually measures. To keep that honest, every scan contributes a set of anonymized, aggregate statistics to a shared calibration set: bin counts and distributions — for example, how many files fell into each size bucket, or how scores spread within a grade. These are counts, not contents. They never include your source code, your file paths, your project or repository names, your identity, or anything traceable to you; your source is still deleted the moment scoring finishes (section 2). This is not an AI model, and we do not train models on your code — it is deterministic, statistical calibration of the scoring itself.
Contributing is on by default, and disclosed here, in the CLI when you log in, and on your dashboard's Training page. On the free Community plan it is always on — like the public handle, it is part of the price of free — and it is how a free tool stays sharp for everyone who uses it. On any paid plan (Vibe or Enterprise) you can opt out with one switch on your Training page, and from then on your scans stay out of the calibration set. Opting out is going-forward-only: aggregate counts already folded in carry nothing that identifies you and are not reversible, which is the same reason they are safe to keep. We do not sell or distribute this data.
5. Who processes data for us
We use a small set of infrastructure providers: Fly.io (hosting, US), GitHub (sign-in verification only — we see your public login, never your repositories), Google Workspace (email), Slack (our founder operations feed — a private, single-operator ops channel, never a public or shared space. Most notifications carry only your pseudonymous account id. The exceptions stay on this feed alone: a waitlist signup includes the email you submitted; product feedback or a feature request includes the message you wrote; and — so we can reach out and actually help — a notification about an operational failure (a scan or sign-in that errored) or a lifecycle milestone (for example becoming a regular user, going quiet, or coming back) includes your GitHub handle when we know it. Your source, file paths, and findings never reach this feed, and your handle never leaves it for any public page or third-party analytics), Honeycomb (service telemetry keyed by pseudonym, when enabled), and Stripe (payment processing for paid plans, when you buy one: Stripe collects your payment details itself under its own privacy policy — we send Stripe only your pseudonymous account id, and we store only Stripe's opaque customer and subscription references, which are removed and any subscription cancelled when you delete your account; Stripe retains its own transaction records as the law requires it to). We do not sell or rent personal information to anyone.
6. Retention and deletion
Report cards and score history are kept until you delete them. Delete my data in your dashboard permanently removes every report, score row, and share link tied to your account, immediately. The key registry retains your key's issued-to name until the key is revoked — email privacy@bench.fit and we'll remove that too. Backups age out on a short rotation.
Re-score measurements. So we can verify that an improvement to our grading engine actually helps real repositories — and, over time, tell you when your own grade improved — we keep a redacted, replayable measurement of each cloud scan going forward. It is a structural summary — size and count distributions plus the gate outcomes needed to re-derive a grade — with no source, no file paths, no symbol names, no project name, and nothing traceable to you; like everything else it is stored under your pseudonymous account id, never your name. It lets us re-run scoring on the measurement alone, without asking you to scan again and without ever holding your code. It preserves a little more than the calibration counts in section 4 — enough to reproduce a repository's structural shape — and it is deleted with everything else the moment you use Delete my data.
7. Your rights
Ask us at privacy@bench.fit to access, correct, or delete the data tied to your account, wherever you live; we honor these requests without requiring a legal citation. If you are in a jurisdiction with statutory privacy rights (e.g., GDPR or CCPA), those rights apply to the data described above.
8. Security
Transport is TLS-only; API keys are stored hashed; identity is pseudonymized end to end; retention is minimal by design. No system is perfectly secure — if we learn of a breach affecting your data we will notify you at the email we have for you.
9. Children and changes
BenchFit is not directed to children under 16. We'll post any material changes to this policy here with a new effective date. See also the Terms of Service.