Privacy

Privacy Policy

This policy covers the RepoD software and the getrepod.com marketing website. Last updated: May 2026.

RepoD software — self-hosted

Zero telemetry. All your data stays in your infrastructure.

RepoD is fully self-hosted. When you run RepoD on your own servers:

  • No data is transmitted to RepoD or any third party
  • No usage metrics, crash reports, or analytics are collected
  • Package metadata, user accounts, and audit logs remain exclusively on your infrastructure
  • CVE data is fetched directly from public feeds (NVD, FIRST.org, CISA) — your package names are never sent externally
  • EPSS scores are fetched in bulk from first.org/epss — no per-package queries that would reveal your inventory

RepoD can be operated in fully air-gapped mode with no outbound internet access whatsoever. See the documentation for air-gap configuration.

This website (getrepod.com)

The marketing website is a static site with no tracking scripts, no advertising cookies, and no analytics that identify individual visitors.

We use a CDN (Content Delivery Network) to serve this website. Server access logs may record standard HTTP metadata (IP address, user agent, timestamp, URL requested) for security and operational purposes. These logs are retained for a maximum of 30 days and are never sold or shared with third parties.

When you submit the demo request form, your name, email, company and message are transmitted to Resend (our transactional email provider) to deliver your enquiry to our team. Resend acts as a data processor on our behalf and does not use your data for its own purposes. See the Cookie Policy for the full list of data processors.

We use this information solely to respond to your enquiry and retain it for as long as necessary for that purpose.

Cookies & browser storage

This website does not set any tracking or advertising cookies. A single entry in your browser's localStorage remembers your cookie preference — this is never transmitted to our servers. See our dedicated Cookie Policy for the full details.

The RepoD application itself may set a session cookie for authentication purposes only — this cookie never leaves your own domain.

Your rights (GDPR / CCPA)

If you are located in the European Union or California, you have rights regarding your personal data. To exercise any of these rights, contact us at:

[email protected]

Data controller

RepoD
[email protected]

For privacy-specific requests: [email protected]

Changes to this policy

We may update this privacy policy from time to time. Material changes will be announced on this page with a revised "last updated" date. Continued use of the website or software after changes constitutes acceptance of the updated policy.

Last updated: May 2026 · [email protected]