Heimdall Scan logo, AI security scanner for vibe coders
Heimdall Scan

Legal

Privacy Policy

Last updated: September 2026

What We Collect & Store

Identity: When you connect GitHub, we store your GitHub ID, username and email. This is strictly to manage your scan quotas and account tier (Basic/Pro/Ultra).

Authentication: We use short-lived OAuth tokens. They are used only to access the repos you select and are never stored permanently in our database.

Scanning: To analyze your code, we send relevant files to Google's Gemini AI. We do not store your code on our servers after the scan is complete.

Payments: If you upgrade to Pro/Ultra, payment processing is handled securely by our third-party provider (Stripe). Heimdall never sees or stores your credit card details.

Our Security Commitments

  • No AI Training: We use Google's Enterprise API. Your code is never used to train third-party AI models.
  • Product Analytics: We count anonymous usage, like how many people finish a scan, so we know what to fix. Masked session replays and anything tied to your GitHub account wait until you click Accept on the cookie banner.
  • No Data Selling: We don't sell, rent, or share your data with anyone. Ever.
  • Minimal Logging: We log technical errors so we can keep the tool running. We don't build ad profiles, and we don't sell anything we collect.

Third-party services

GitHub OAuth handles authentication and repo access. See GitHub's Privacy Statement.

Google Gemini AI processes your repo files during each scan. See Google's Privacy Policy.

Mixpanel records anonymous product analytics after you accept cookies. See Mixpanel's Privacy Policy.

If you accept cookies, Mixpanel may also record a session replay. It rebuilds your clicks, scrolling and the page layout; it isn't a video of your screen. Anything you type is hidden. So is all the text on the scan, results and history pages, your GitHub name, and every image. We don't record network requests or console logs. Mixpanel deletes replays after 30 days. If you decline cookies, or switch your choice later with the Cookies link in the footer, recording stops.

Sentry captures crash reports so we can fix bugs. Session Replay only activates after you accept cookies. See Sentry's Privacy Policy.

Cookies and local storage

Here's every cookie and storage entry Heimdall Scan sets, and why. You can change your analytics choice any time by clicking Cookies in the footer.

NamePurposeCategory
heimdall_sessionSigned session token after sign-inStrictly necessary
heimdall_authShort-lived OAuth handoff (cleared after one read)Strictly necessary
heimdall_consentRecords your accept/decline choice on the cookie bannerStrictly necessary
heimdall-themelocalStorage entry remembering your light/dark themeFunctional
mp_*Mixpanel anonymous usage analytics. Only set after you accept.Analytics (consent required)
__mprec_*, mp_tab_id_*Temporary session replay data. It's deleted once Mixpanel receives it. Only set after you accept.Analytics (consent required)
sentryReplaySessionSentry Session Replay for crash debugging. Only set after you accept.Analytics (consent required)

Contact

Questions about this policy? Email us at legal@heimdallscan.com