What we collect, and what we don't

Last updated 2026-08-24

01The short version

We do not sell your data. We do not run advertising, we set no third-party cookies, and we do not track you across other sites. The package.json or lockfile you paste into the scanner is never stored.

What follows is the long version. It is written to be checkable rather than reassuring — if any of it turns out not to match what the product does, that is a bug and we want to hear about it.

02Who holds this data

Install Safe is a product of PrivJs OÜ, a private limited company registered in Estonia. Under the GDPR, PrivJs is the controller of everything described on this page: it decides what is collected and why, and it is who you hold responsible for it.

Ask us anything about your data at support@installsafe.io — access, correction, export, deletion, or an objection to something here. It reaches the people who build the product.

If we get it wrong and you want someone above us to look, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), or to the equivalent authority where you live.

03The scanner

When you paste a manifest into the scanner, it is parsed in memory to run the scan and discarded once the response is sent. It is never written to disk and never logged.

To check your dependencies against known advisories, the package names and versions from your file are sent to OSV.dev, the open-source advisory database this scanner is built on. That lookup is the scan. The file itself is never sent anywhere.

If you choose to share a report — and only if you choose to — we store the findings behind an unguessable link: package names, versions, advisory IDs, severities, counts, and how many times the link has been opened. Never the file you pasted. Shared links stop working after 7 days.

04The registry proxy

The proxy earns its keep by showing you what it kept out of your installs. Your activity dashboard, and the audit trail behind it — which versions were blocked, which were served, and why — are built from a record of what the proxy did on your behalf.

That record contains, for each install: the package name and version, how many times it was requested, how many bytes were served, any advisory IDs involved, and which of your registry tokens made the request.

We keep it for 7 days on the free plan and 90 days on paid plans, after which it is deleted automatically.

We do not use it for anything else. It is not sold, not shared with anyone, and not used to build a profile of you or your company.

05Your account

When you create an account we store your email address, a name if you give one, a hashed password — never the password itself — your plan, your payment provider IDs, your protection policy settings, and your team membership.

We also store how you first arrived: the campaign tags on the link you followed, the host of the referring site, and the first page you landed on. We keep the referring host and never the full referring URL, because referrer URLs routinely carry search terms and session identifiers that are none of our business.

06Cookies

All first-party. There are no third-party cookies, no advertising trackers, and no cross-site tracking, and our product analytics runs in a mode that writes nothing to your device at all — no identifier, no session, nothing.

Two are set whatever you choose, because the site cannot do what you asked without them. A session cookie, set when you sign in and lasting 30 days, which is what keeps you signed in. And a cookie named is_consent, lasting six months, which remembers your answer to the banner so we stop asking.

The rest are set only if you accept. A cookie named is_attr, lasting 90 days, holding the campaign tags and referring host described above. And three cookies named _oo_s, _oo_s_v and _oo_c, set by our analytics and session-replay tooling to tie a visit together.

Session replay means a reconstruction of how pages behaved for you — what loaded slowly, what you clicked, where a layout broke. Anything you type is masked before it leaves the browser, so passwords, registry tokens and email addresses are never in a recording. We record half of accepted sessions and keep them 30 days.

Decline and none of that is loaded at all — not merely switched off, but never downloaded. The product behaves identically. Change your mind either way by clearing cookies for this site, which brings the banner back.

07Who else sees your data

Polar handles payments and subscriptions. Your card details go to them and never touch our servers.

OSV.dev receives the package names and versions from a scan, as described above.

pug.sh is our product analytics provider. If you have an account, they receive your email address, your account ID and your plan, so we can understand how the product is actually used. They do not receive your dependencies, your scan results, or your install history.

Our error tracking and monitoring run on our own servers rather than a third party, so nothing about how the product behaves for you is handed to anyone else.

08How long we keep things

Shared scan reports: 7 days.

Registry activity: 7 days on the free plan, 90 days on paid plans.

Your account and its settings: until you ask us to delete it.

Your email address on our contact list: until you ask us to remove it.

09Getting your data deleted

Email support@installsafe.io and we will do it. That covers your account, a shared report link you want taken down before it expires, and your email address on our contact list.

There is no form, no account requirement, and we will not ask you for a reason.

10Changes to this policy

If we start collecting something new, or send data somewhere new, this page changes in the same release that makes the change — not afterwards.

This is a plain description of what the product does, written in our own words. It is not a lawyer-drafted instrument and does not pretend to be one.

Questions about any of this, or something here that doesn't match what you see? support@installsafe.io