BGBusleyden Guard
TrustTermsProduct

Privacy notice

Your data boundary should be explicit.

This notice describes how the Busleyden Guard operator processes information when you use the public site, public pull-request preview, GitHub App, Guard workflows, or subscription flows.

Source-code default: Guard's repository analysis runs in GitHub Actions and customer source code is not stored in operator-controlled systems by default. Reports stay in the customer repository unless another sink is configured.

Information processed

  • Public pull-request URLs, public changed paths, file statistics, and bounded public diff snippets submitted to the preview.
  • Repository and pull-request identifiers, title and author metadata, changed paths, owner routes, test and scanner summaries, policy status, blockers, and unknowns.
  • Business contact information supplied for intake, feedback, approval, support, scheduling, or payment handoff.
  • Subscription metadata used to verify Guard Pro access.
  • Optional reviewer usefulness reactions stored in the customer repository.

Why it is processed

We use this information to produce Guard checks and previews, connect selected repositories, support customers, verify subscriptions, operate optional ledgers or configured handoffs, prevent abuse and disputes, and meet accounting or legal obligations.

Services that may receive data

GitHub Actions is required to run the installed workflow. Stripe may process checkout and payment data when card checkout is enabled. Optional private GitHub ledgers, configured webhooks or CRM systems, and customer-selected scanners may receive the limited data needed for their configured purpose. Their own terms and privacy practices apply.

Storage and retention

Customer repository artifacts remain under customer control. Operator-controlled records are intended to be retained only as long as needed for service operation, accounting, fraud prevention, dispute handling, or written legal obligations. Public sample assets must not contain customer source code, secrets, approval evidence, or live revenue evidence.

Your choices

  • Select only the repositories Guard may access.
  • Keep output in workflow artifacts rather than pull-request comments.
  • Disable optional scanners, ledgers, and webhooks.
  • Remove the workflow, uninstall the App, and cancel a subscription.
  • Request access, correction, deletion, or redaction of operator-controlled records, subject to applicable retention needs.

Security

Published controls include least-privilege GitHub workflow permissions, secret redaction, private storage for configured operator ledgers, signed configured webhooks, and keeping source code out of operator storage by default. No security measure eliminates all risk; the trust center documents the current boundary and limitations.

Children

Guard is a developer and business service and is not directed to children.

Requests and changes

Use the support route shown in the Busleyden Guard GitHub App listing or your existing product or billing correspondence to make a privacy request. We may update this notice as the service changes; the date below identifies the published version.

For procurement review, see the data handling summary and its source artifact.

Effective and last updated: July 10, 2026.

Busleyden GuardTrust centerData handlingTerms