Privacy Policy

Last Updated: July 14th 2025

Licensable (“we”, “our”, or “us”) respects your privacy and is committed to protecting it through this Privacy Policy. This policy describes how we collect, use, and handle your information when you use our service.

1. Information We Collect

a. GitHub Account Data

When you connect Licensable to your GitHub account, we collect the following information:

  • Your GitHub username and public profile details,
  • OAuth access tokens to interact with GitHub APIs,
  • Repository metadata, including names, topics, and configurations.

b. Source Code

We access your source code only for the purpose of:

  • Extracting license information,
  • Resolving ambiguous license data,
  • Analyzing code for compliance-related metadata (e.g., license headers).

We do not modify, permanently store, or share your source code. Access is restricted to what is required for compliance analysis.

c. Dependency and License Data

We analyze your repositories’ dependency information (from manifests, SBOMs, or GitHub’s dependency graph) to generate compliance reports. This may include:

  • Package names and versions,
  • Associated licenses and metadata.

d. Billing Information

Licensable uses GitHub Marketplace for billing. We do not collect or store your payment information. All billing-related data is handled directly by GitHub according to their Privacy Policy.

2. How We Use Your Information

We use the collected data to:

  • Generate open-source license compliance reports,
  • Identify potential license conflicts or obligations,
  • Improve the accuracy and coverage of license detection,
  • Manage your subscription (via GitHub Marketplace),
  • Communicate with you about service updates or critical issues.

We do not use your information for advertising, profiling, or resale.

3. Data Sharing

We do not sell, rent, or trade your personal or project data. Your data may be shared under the following limited circumstances:

  • With GitHub, to access your repositories as authorized by you,
  • With service providers, only as needed to operate and improve Licensable (e.g., hosting providers),
  • As required by law, if compelled by legal process or to protect rights and safety.

4. Data Retention

We retain repository metadata and analysis results only as long as necessary to provide the service or as required by law. We do not retain source code beyond the scope of an active analysis session unless you enable persistent storage explicitly (e.g., for caching or CI integration).

5. Security

We implement reasonable safeguards to protect your data, including:

  • OAuth scopes limited to read-only access
  • Encrypted communications (HTTPS)
  • No persistent storage of source code unless explicitly enabled.

6. Your Rights and Choices

You have the right to:

  • Revoke GitHub access at any time,
  • Request deletion of metadata or analysis results associated with your account,
  • Contact us with privacy-related concerns.

To revoke access, go to your GitHub Authorized OAuth Apps settings and remove Licensable.

7. International Users

If you access Licensable from outside the country where we operate, your information may be transferred to and processed in countries where privacy laws may be different. By using the service, you consent to this transfer.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via GitHub Marketplace notifications, our website, or via email (if applicable). Continued use of the service after such changes constitutes your acceptance.

9. Contact Us

If you have questions or concerns about this Privacy Policy, contact us at contact@licensable.io.