Privacy Policy
Keystone is an audit platform operated by Tech-Bharat ("we", "us"). This policy explains what we collect when you use Keystone, how your code or website is processed during an audit, who we share data with, and how long we keep it. Questions: manan@tech-bharat.com.
What we collect
- Your email address — to contact you about your audit and for your payment receipt (report delivery by email is coming; today the report is available at a private link).
- The target you give us — a GitHub repository or a website URL, plus any optional context or test credentials you provide.
- Payment information — handled entirely by Stripe. We never see or store your card details; we receive only a confirmation and a reference id.
- Audit results — the report we generate and a job record (status, timing, and cost).
- Operational logs — standard server logs (such as IP address and request metadata) for security and reliability.
How an audit processes your code or site
Audits are strictly read-only — we never write to, modify, merge, deploy, or delete anything.
- Code Audit: we make a temporary, read-only clone of the repository and analyze it. To perform the review, portions of your code are sent to our AI provider (Anthropic), and your dependency identifiers are checked against public vulnerability databases (OSV, deps.dev). The clone is deleted after the audit completes.
- SEO Audit: we fetch your publicly reachable pages and query Google PageSpeed Insights for performance data. Page content may be sent to our AI provider (Anthropic) for the review.
Sub-processors we share data with
- Anthropic — AI analysis of the code/pages being audited.
- Stripe — payment processing.
- Google PageSpeed Insights — Core Web Vitals for SEO audits.
- OSV / deps.dev — dependency vulnerability and license lookups.
- DigitalOcean — hosting of the service.
We do not sell your data or use it for advertising.
How long we keep it
Repository clones are deleted as soon as the audit finishes. Audit reports are deleted within 90 days. Minimal job metadata — along with your email and payment references — is kept only as needed for receipts, support, and legal/accounting obligations. You can ask us to delete your data sooner (see below).
Security
The service is served over HTTPS. Any credentials you provide (such as a test-account password for live-app testing) are encrypted at rest and are never stored in plain text.
Your rights
You can request access to, correction of, or deletion of your personal data by emailing manan@tech-bharat.com. Depending on where you live, you may have additional rights under laws such as the GDPR.
Changes
We may update this policy; we'll change the "last updated" date above when we do.