Privacy Policy

Effective 2026-04-27. Plain English. Last updated 2026-04-27.

Short version

The CLIs run locally and collect nothing. The website has no analytics and no cookies set by us. The in-browser tools never upload your YAML. Paid checkout goes through Polar.sh, which collects what it needs to charge your card. The X account is a publishing channel, not a tracking surface.

1. The CLIs (npm packages)

Every CLI we publish - depmedic, ci-doctor, cursor-rules-init, gha-budget, pin-actions - runs entirely on your machine. They do not phone home, do not collect telemetry, and have no analytics endpoints. Their network traffic is limited to the upstream package ecosystems they explicitly need (e.g. depmedic queries the npm registry to evaluate vulnerability data).

2. The website (depmedicdev-byte.github.io)

Static HTML hosted on GitHub Pages. We do not include analytics scripts, advertising trackers, or social pixels. We do not set cookies. GitHub may collect standard server logs (IP, user agent, timestamp) as part of operating GitHub Pages - see the GitHub privacy statement for what GitHub does with that.

3. The in-browser tools

/audit, /budget, and /calculator run entirely in your browser. The YAML you paste, the inputs you type, and the results you see never leave your browser. There is no upload. The "share link" feature on /audit and /budget encodes your YAML into a URL hash (which only travels to people you send the link to).

4. Paid products

Checkout, billing, tax handling, and customer accounts are handled by Polar.sh. Polar collects what it needs to process payment (name, email, card details, country for tax). We see the order metadata - order ID, product, amount, customer email - so that we can deliver the file and respond to support requests. We do not see your card details. Polar's privacy policy: polar.sh/legal/privacy.

5. Email

If you email depmedic.dev@gmail.com, we keep the email for as long as it takes to handle the conversation. We do not add you to a marketing list.

6. X (Twitter)

The @depmedic account uses X's API to publish posts. The depmedic poster does not collect data about anyone reading or interacting with those posts. Whatever data X itself collects is governed by X's privacy policy.

7. Data we do not collect

8. Your rights

If you have ever bought a product, you can email depmedic.dev@gmail.com and ask for a copy of your order data, or ask us to delete it. (Polar will retain its own records to comply with tax law - that is on them, not us.)

9. Changes

If this policy changes in any meaningful way, the change will be announced on the homepage and the date above will be updated.

10. Contact

depmedic.dev@gmail.com.