Privacy policy
Can I Run That? is a product of Infosec Chicago (“Infosec Chicago,” “we,” “our,” or “us”). This Privacy Policy explains how we collect, use, process, and disclose information when you access or use Can I Run That? (the “Service”).
1. Information we collect
Account and authentication information
- Name, email address, and organization details you provide during signup
- Authentication identifiers and session information provided by Clerk
- Profile information received through social login providers (e.g., Google, Apple, Microsoft, Facebook), if you choose to use them
Submitted software, vendor evidence, and assessment data
- Repository URLs, extension sources, packages, or authorized source archives submitted for analysis
- Vendor documents such as SOC 2 reports, penetration-test summaries, security questionnaires, and trust-center exports
- Cryptographic file hashes used to identify files after source processing
- Assessment outputs, grades/scores, severity counts, and structured findings
- Metadata such as timestamps and processing status
Technical and usage data
- IP address, browser type, and device information
- Session and security logs
- Anonymized usage metrics and feature interaction data
2. How we use information
We process information to:
- Provide, operate, and improve the Service
- Authenticate users and maintain account security
- Generate structured risk assessment reports
- Provide customer support
- Monitor system performance and detect misuse
- Process billing and subscriptions
We process personal information based on legitimate business interests, contractual necessity, compliance with legal obligations, and user consent where applicable.
3. AI processing
Can I Run That? uses third-party AI systems to analyze submitted source code, vendor documents, and contextual assessment data to generate structured reports.
For fully inclusive plans, submitted content and contextual analysis data may be processed via Anthropic Claude under a commercial API agreement that does not permit submitted data to be used for AI model training.
For Bring Your Own Key (BYOK) plans, processing occurs under your own Anthropic API credentials and is governed by your Anthropic account settings and agreement. If AI model training is enabled for that account, your Anthropic terms control that use.
Submitted content is processed solely for generating assessment outputs. We do not sell submitted repositories, submitted code, or analysis data.
4. Your responsibility for submitted content
You are responsible for ensuring you have the legal right to submit any repository, source archive, extension, package, vendor document, or other evidence for analysis. Infosec Chicago acts as a service provider processing submitted content to provide assessment outputs.
5. Infrastructure and third-party providers
Currently implemented third-party providers include:
- Cloudflare (network, performance, and security)
- Railway (application hosting)
- Clerk (authentication)
- Sentry (error monitoring)
- Paddle (billing and subscription management)
- Anthropic (AI processing)
- Chatway (customer support and messaging)
- Google Analytics (website/product analytics)
- HeyCatch (anonymous website interaction analytics)
6. Social login providers
If you authenticate using a third-party identity provider (e.g., Google, Apple, Microsoft, Facebook), we may receive limited profile information such as name and email address, as permitted by your account settings with that provider.
7. Data retention
Source code files are not retained after processing. Cryptographic file hashes and underlying file-level assessment results from code reviews are retained indefinitely by default, including after the code review assessment itself is deleted. For a sensitive codebase, an option available during the initial scan can delete the stored hashes and file-level results created for unique files first seen in that repository after report generation. This option is generally not recommended because it reduces retained analysis history and reuse. A file-level result is primarily a generated summary of the file's purpose and its associated security findings. In rare circumstances it may include a small code snippet. It cannot identify or reconstruct the submitted source file.
Vendor documents are retained with the assessment by default for documentation continuity. Document retention can be disabled, and you may delete the vendor assessment and its retained documents at any time.
We retain account, billing, and other assessment data for as long as your account remains active or as needed for legitimate operational, security, financial, and legal purposes.
Certain security logs and diagnostic records may be retained after account deletion for fraud prevention, legal compliance, or system integrity purposes.
8. Data location
Can I Run That? application information is processed and stored in the United States. Our service providers may operate support or infrastructure in other jurisdictions under their respective agreements.
9. Security
We implement reasonable technical and organizational measures designed to protect information, including encryption in transit and at rest. However, no system can guarantee absolute security.
10. Business transfers
In the event of a merger, acquisition, restructuring, or sale of assets, information may be transferred as part of that transaction, subject to applicable law.
11. Your rights
You may request access, correction, or deletion of personal information by contacting: [email protected]
12. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date reflects the effective date of changes. Continued use of the Service after changes become effective constitutes acceptance of the updated policy.