Privacy policy

Last updated: 10 October 2026

GiTRay is a free, non-commercial project. It has no accounts, no analytics, no advertising and no tracking. This page lists everything the site keeps or passes on, and why.

What you send us

The address of the repository you want scanned. It is used to scan that public repository and is stored with the result (see below), never together with anything about you.

Like every website, your browser sends your IP address with each request. GiTRay uses it only to limit how many scans one visitor can start (6 a minute). The server holds it briefly in memory for this; the database never stores the address itself, only a keyed hash (HMAC) of it with a counter, and deletes these counters after about a day. Your IP address is not written to GiTRay's logs and is never sent to the services listed below.

Scan results are public

The latest scan of each repository is stored: the repository's name, description, star count, commit, verdict, score and the findings, with short excerpts of the repository's files. Anyone can see these results on the scan page and in the public lists (Recent scans, Safe Zone, Scammer). Nothing about who started a scan is stored with it. At most 5,000 results are kept; the oldest are deleted first.

Cookies and browser storage

GiTRay sets no tracking or advertising cookies, so there is no cookie banner. There are two small preferences, and both are only saved when you change them yourself:

gitray-lang: the language you picked in the language menu, so the site opens in it next time (one year).

gitray-theme: the theme you picked (light or dark). It stays in your browser's local storage and is never sent to the server. Choosing System removes it.

Services that take part in a scan

During a scan GiTRay's server contacts the following services. They receive information about the scanned repository, never about you:

GitHub: the repository's details and files are read from GitHub's API and download servers.

OSV (osv.dev): the names and versions of the packages the repository depends on, to look for known malicious packages.

VirusTotal: only SHA-256 fingerprints of programs and release files. No file is uploaded.

Links to GitHub and VirusTotal on a report take you to those sites, where their own privacy policies apply.

Hosting

The site runs on Vercel, and scan results and the rate-limit counters are kept in a Postgres database at Neon. Vercel may keep standard request logs, which include IP addresses, under its own policy. Fonts and scripts are served from this site; no third-party scripts are loaded in your browser.

Changes

If this policy changes, the date at the top changes with it.