https://reposcope-api.latescodrin.com/privacy
RepoScope
Privacy Policy
Effective July 30, 2026 · Operator: LATES CODRIN-GABRIEL
Who controls the processing
RepoScope is operated by LATES CODRIN-GABRIEL. Website: latescodrin.com. Privacy, safety, data-rights, and legal requests may be sent to support@latescodrin.com. Legal notices may be sent to the same address.
What stays in your browser
Folder ZIPs, copied directory trees, and generated MCP packages are produced locally in the browser. RepoScope stores only your own choices in extension storage: packaging preferences, source-inclusion preferences, the Terms and Privacy acknowledgement version and time, your AI consent choice, the server-provided AI availability state, and the state of the update notice. The optional GitHub token and the signed anonymous service session are held in memory only and are never written to browser storage. RepoScope does not use analytics or advertising trackers, does not sell user data, and does not collect general browsing history or keystrokes.
GitHub access
RepoScope reads only the repository and folder you have open, and only for the action you start. Public repositories need no token. If GitHub requires a fine-grained token for a private repository, RepoScope asks at the point of use, keeps it only until that tab closes, and sends it only to GitHub API and raw-content endpoints. It is never sent to RepoScope's AI service, Fingerprint, Cloudflare, or the AI provider.
Anonymous AI quota and Fingerprint
AI export and anonymous identification stay disabled until you enable AI export and accept the anonymous-quota consent control. When RepoScope needs an anonymous session it briefly opens an HTTPS verification page operated by LATES CODRIN-GABRIEL. That page uses Fingerprint Identification, provided by FingerprintJS, Inc. Fingerprint may process browser and device characteristics, IP address and network information, user agent, storage and cookie signals, the verification-page URL, timestamps, and related identification metadata, and returns a workspace-scoped visitor ID and a unique event ID.
To stay reliable when browser privacy tools block Fingerprint domains, the verification page sends the identification request through the RepoScope API. The API forwards it to Fingerprint over HTTPS, does not retain the raw browser-identification payload, and does not use it for any other purpose.
This information is used only to prevent quota evasion and to enforce a maximum of 10 accepted AI exports per device per UTC day without requiring an account. It is not used for advertising, marketing attribution, cross-site tracking, or eligibility decisions. The Fingerprint secret API key stays only on the RepoScope server. The server retrieves each event through Fingerprint's Server API and verifies the event ID, visitor ID, timestamp, verification-page origin, challenge tag, linked challenge, and replay status. A Fingerprint event can be used only once. RepoScope converts the verified visitor ID into a keyed one-way quota identifier and does not store the raw visitor ID in its quota ledger. The extension receives only a signed RepoScope session token. The deployed configuration uses Fingerprint's EU region.
When repository content leaves your browser
Before an AI export, RepoScope shows the repository and folder, the file count, the selected source size, estimated tokens and cost, the exclusions applied, the destination host, and your source-inclusion choice. Requests above the warning thresholds require you to type "I understand". Requests above the hard limits are refused.
After you confirm, the selected text file paths and contents are sent over HTTPS to the RepoScope AI service and then to DeepSeek, the configured third-party AI provider, to create the requested file descriptions and prompt package. RepoScope does not use repository content for advertising and does not use it to train RepoScope-owned models. Queued source is encrypted at rest with AES-256-GCM and removed from the job record after completion or failure. Expired job records are deleted after the configured retention period, six hours by default, and generated descriptions and minimal job metadata follow the same default.
DeepSeek is an independent provider and controls its own retention and model-improvement settings; RepoScope makes no zero-retention or no-training promise on its behalf. Do not send secrets, confidential information, or sensitive personal data. Review the DeepSeek Open Platform Terms and DeepSeek Privacy Policy.
Data categories, purposes, recipients, and retention
Local package data - used to produce the local ZIP, tree, or MCP package. Never transmitted.
GitHub metadata, file paths, and file contents - read from GitHub for the action you start. Recipients: GitHub, and for an AI export the RepoScope API and DeepSeek.
Optional fine-grained GitHub token - held in tab memory, sent only to GitHub. Not stored, not transmitted anywhere else.
Fingerprint browser, device, and network signals, challenge and event IDs - used to enforce the anonymous daily quota. Recipients: FingerprintJS, Inc. Used event IDs are kept up to 35 days to prevent replay.
Keyed one-way quota subject, daily quota and cost records - used for quota and cost limits. Kept up to 35 days.
Signed anonymous session - valid up to 30 days.
Encrypted queued source, generated descriptions, job metadata - six-hour default retention.
Request and security metadata - IP address, timestamps, request paths, response status, and coarse network and security information, used to secure the service, enforce rate limits, investigate abuse, and maintain reliability. Recipients: Cloudflare and Hetzner. Authorization headers and submitted source content are redacted from application logs. Logs are written to container standard output, so host and container log rotation determines log retention.
Legal bases
Where data-protection law requires a legal basis, the operator relies on your request and your consent for optional AI export and Fingerprint identification; on performance of the service you requested for processing selected repository content; and on legitimate interests in preventing abuse, enforcing quotas, protecting credentials, controlling cost, and maintaining reliability. Withdrawing consent stops future Fingerprint identification and AI exports but does not invalidate processing already completed.
Subprocessors and international transfers
FingerprintJS, Inc. - anonymous device identification and event verification. Deployed EU workspace.
Hetzner - RepoScope API hosting on an ARM64 Ubuntu host in the Helsinki (hel1) region.
Cloudflare - tunnel, TLS proxy, WAF, and rate limiting. Global edge processing.
DeepSeek - generates the requested file descriptions from user-selected repository text and paths. DeepSeek's published policies describe international and PRC storage.
GitHub - the source you chose to read from.
An AI export can therefore involve a transfer outside the EEA, including to DeepSeek. Where a provider offers a data-processing agreement and standard contractual clauses, the operator relies on those published terms for the transfer. If you do not want repository content transferred to an AI provider, leave AI export off; every other RepoScope feature works without it.
Your controls and rights
You can use folder download, directory-tree copy, and MCP packaging without ever enabling AI. You can withdraw anonymous-quota consent and disable AI export at any time, which stops new repository-content and Fingerprint transmissions. Closing the GitHub tab or the browser clears the in-memory GitHub and service sessions. Uninstalling RepoScope removes its extension-local preferences according to your browser's storage behaviour.
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection, and you may withdraw consent. Contact support@latescodrin.com. For an anonymous-data request, include the approximate date and time, the browser used, and any non-secret challenge or session reference. Because the quota ledger stores a keyed one-way subject rather than a raw visitor ID, some anonymous records cannot be located without such a reference. The operator may ask for additional non-sensitive details to confirm the request concerns you, and will never ask for a GitHub token or a repository secret by email. If you are in the EEA, the UK, or Switzerland, you also have the right to lodge a complaint with your local supervisory authority.
AI safety and generated output
RepoScope does not execute repository code, generated code, MCP tools, commands, or configuration, and does not modify your repository. Source files can contain malicious or misleading instructions, including prompt injection, and generated output can be incomplete, inaccurate, insecure, or unsuitable for your purpose. Review generated prompts, packages, code, commands, and configuration before use, inspect dependencies and permissions, remove secrets, and test generated artifacts in an isolated environment appropriate to their risk.
Security and incident reporting
RepoScope uses HTTPS, server-only provider credentials, authenticated Fingerprint Server API calls, HMAC-signed sessions, one-time event replay protection, server-side quotas and rate limits, encryption of queued source at rest, restricted container privileges, and redacted logs. No system is perfectly secure. Report a suspected incident to support@latescodrin.com.
Chrome Web Store Limited Use
RepoScope's use and transfer of information received through browser permissions complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. RepoScope uses that information only to provide the user-facing folder-packaging features described in this policy. RepoScope does not use or transfer it for advertising, does not sell it, does not use or transfer it for purposes unrelated to the extension's single purpose, does not use or transfer it to determine creditworthiness or for lending purposes, and does not permit humans to read it except with your specific consent, where necessary for security or to comply with applicable law, or as part of an aggregated and anonymised operational review.
Children
RepoScope is a developer tool and is not directed to anyone under 18, or under the minimum age required to enter a binding agreement where they live. The operator does not knowingly collect children's personal information. Contact support@latescodrin.com if you believe a child has provided information.
Changes
Material changes are reflected by updating the effective date above and, where appropriate, by an in-extension or store-listing notice. Data practices will not be expanded through remote configuration without an extension update and an updated disclosure. Remote configuration can only turn existing features off or restrict them; it can never add code, permissions, hosts, or new collection.
Contact
LATES CODRIN-GABRIEL, support@latescodrin.com, latescodrin.com. Public product feedback and feature requests: reposcope.featurebase.app. See also the Terms of Service.