Privacy

Five different things happen, and only two involve us.

This page describes the data flows that exist in the code, in the order you meet them. It is not a template, and it does not use the word "may" to cover things we do not do.

  • Last reviewed 2026-08-21
  • Applies to myrqen@0.2.0 and myrqen.cc
  • Contact support@myrqen.cc

1. A local scan, nothing reaches us

Installing Myrqen and scanning a project creates no relationship with us at all. There is no account, no identifier, no phone-home on install, and no network request required to complete an assessment. Discovery, the static pass, the safety gates, and all four report formats are local computation.

The reports land in .myrqen/reports/ inside the project you scanned, and the session state in .myrqen/sessions/. Configuration lives in a per-machine directory - ~/Library/Application Support/Myrqen/ on macOS, $XDG_CONFIG_HOME/myrqen/ on Linux, %APPDATA%\Myrqen\ on Windows. All of it is yours to delete.

Your source code is never uploaded, on any plan, including paid ones. There is no code path that sends it.

2. An account, the minimum to have one

Creating an account at myrqen.cc stores:

DataWhy
Email addressIt is your identifier for signing in. No marketing mail is sent, and no email is sent at all.
Password, hashedNever stored in a recoverable form.
Recovery codes, hashedThey exist because nothing is emailed: there is no password-reset link, so a code is the only way back in.
Session recordsSo you can sign out, and so a stolen session can be revoked.
Device records, a name you choose, and when it was linkedSo you can see which machines are connected and revoke one.
Workspace and project bindings, a project name and identifierSo a report arrives under the right project. Not the repository, and not its contents.

No third-party sign-in, so no identity provider learns that you use this. No email verification, so no mail service handles your address. The durable device credential is held in your operating system keystore and is never printed to a terminal.

3. A synced report, the only content that leaves

Once per scan, on a linked machine, Myrqen asks whether to sync. It is never a remembered default. Answer no and nothing about that scan leaves the machine.

Answer yes and what is uploaded is the report you generated:

  • The findings, with their evidence snippets, which are excerpts of your source.
  • Severity, verification state, route and file references, and the remediation text.
  • Coverage notes, and the record of any action the safety policy refused.
  • Metadata: which agent ran it, the effort resolved, timings, and counts.

Not uploaded: your repository, your dependency manifests, your .env file, the HTTP traffic recorded during validation, or any secret value. A secret is described by type and location; the value is never carried, and a finding that still contains one is rejected rather than cleaned up.

A synced report body is encrypted with AES-256-GCM before it reaches any storage driver. This is not end-to-end encryption, the server holds the key, because it renders the report and applies per-recipient projections. The exact mechanism.

Support cannot read a synced report body without a time-boxed grant that is written to an audit trail. A request without one fails rather than quietly succeeding.

4. A share, what the recipient gets

A share URL is projected on the server. A recipient receives only the findings and fields their share grants: the withheld ones are never sent to their browser, so there is nothing to reveal by inspecting the page. Share access is recorded, when, and by which kind of principal, so you can see whether a link has been opened.

Share URLs are Disallowed in robots.txt and served with no-store, and they are not in the sitemap. Treat one as a secret anyway: a link you paste somewhere public is public.

5. Analytics, a fixed list of counted events

There is no third-party analytics. No Google Analytics, no session recording, no fingerprinting, no advertising pixel, no cross-site tracking, and nothing that follows you off this site. The Content-Security-Policy on every page forbids connections to another origin, which is a mechanism rather than a promise.

The CLI counts a fixed list of product events, an account created, a scan started, a scan completed, a sync offered and accepted or declined, a fix prompt copied, a share created, and about twenty others. Each carries the event name, a client version, an OS family, an architecture, and numeric metrics from a closed list: durations, counts per severity, counts per verification state. There is no free-form properties bag, so a project name, a file path, a finding title, or a hostname cannot end up in one even by accident. The envelope is validated locally before it is sent.

Two things narrow it further. Events are only sent from a machine that is linked to an account, an unlinked install sends nothing, ever. And you can turn it off:

myrqen config telemetry off          # persists, on this machine
MYRQEN_TELEMETRY=off myrqen auto     # one command only

Server-side, request logs record what a web server records. Rate limiting keys on the client address.

Retention

DataKept for
A local reportForever, or until you delete it. Nothing on our side can remove a file on your machine, and cloud retention does not touch it.
A synced report, free plan21 days, then the object and its row are deleted and an audit event records the deletion.
A synced report, paid plans180 days on Pro, 365 on Team, 1095 on Enterprise. Configurable above Free.
Analytics eventsDe-identified after 90 days, deleted after 395. An event loses its report reference as soon as that report is deleted, whatever its age.
Audit events730 days. They are the record of deletions and of support access, so they outlive what they describe on purpose.
Account and devicesUntil you delete the account.

Retention is enforced by a scheduled job, not by a policy nobody runs. Free-plan reports are deleted 21 days after they synced, and if the object store refuses the delete, database access is cut regardless so the report is unreachable even where the blob has been orphaned.

Your rights, and how to use them

If you are in the EU or UK, the GDPR applies. Wherever you are, these work the same way:

  • Access and export. Every synced report can be exported from the dashboard as HTML, JSON, Markdown, or SARIF, the same four formats you already have locally.
  • Deletion. Delete a report, revoke a device, or delete the account. Deleting a report removes the encrypted object and detaches its analytics rows.
  • Objection to analytics. Turn it off with the command above; nothing degrades.
  • Anything else. Email support@myrqen.cc. We aim to answer within 30 days.

Honest limitation. There is no self-service account-deletion button yet: it is a support request today, handled manually. That is a gap, and saying so is better than implying a flow that does not exist. Report deletion, device revocation, and export are all self-service.

Who else touches it

Only what is needed to run the service. The application and the retention worker run in the EU (europe-west4), on a managed platform, with a managed PostgreSQL database and S3-compatible object storage holding encrypted report bodies. A payment provider is integrated but not configured: nothing can be bought, so no payment data exists and no payment processor holds anything about you.

We have not independently verified the region of every sub-processor's own support tooling, so we do not claim a complete EU data boundary. That, and the rest of what we have not solved, is on the security page.

Data is not sold, rented, or shared for advertising. There is no advertising.


Changes to this page are recorded in the repository's history, and the Last reviewed date above moves when the content does. If a change reduces your privacy rather than describing existing behaviour more accurately, it will be called out on the changelog.