What we collect. Why it is here.
Metal Mantra uses information needed to run public agent scans, display reports, handle support requests and understand basic site performance. We do not ask you to submit private source code.
Information we handle
When you sign in, the service receives an account identifier, name and email from GitHub or ChatGPT authentication. GitHub sign-in requests read-only access to your public profile and verified email addresses; it does not request repository access. A scan includes the public GitHub repository URL, a domain, your account email and a consent acknowledgement. Metal Mantra fetches supported public source files and checks the named domain for DNS, HTTPS and links labeled privacy or terms. Reports store scores, source-derived findings, scope, method and scan time.
A support request stores its topic, email, message, optional repository URL and, if signed in, account identifier.
When you buy a re-audit pass, Metal Mantra records the repository URL, your account identifier, the number of credits, the purchase status, Dodo Payments’ session and payment identifiers, timestamps and the type of each payment webhook received. Card and billing details are entered on Dodo’s checkout and are never received or stored by Metal Mantra.
The first completed Agent Signal v0.2 report is public; sensitive critical-finding details are temporarily withheld as described in the disclosure note.
Usage and operations
First-party analytics record a pseudonymous session ID, route, event, time and limited event metadata, including Web Vitals. The analytics endpoint rejects search queries, form contents and fields outside its allowlist. Scan quotas use a daily hashed identifier; the application does not retain a raw IP address in that quota record.
We use these records to operate scans and accounts, display reports, detect limits and failures, respond to requests and improve usability. Public report details may be accessible to anyone and may be indexed by search engines.
Storage and sharing
Assessment, account-related, support and usage records are stored with the site’s application data. Public reports and source links are deliberately visible. Service infrastructure and the external sources necessary to run a scan, including GitHub and DNS lookups, process the information required for those functions. Dodo Payments acts as Merchant of Record and payment processor for purchases; it receives the payment details and contact information you give at checkout and handles them under its own privacy policy, and it tells us whether a payment succeeded. We do not publish support messages or account email as part of a public report.
No fixed deletion period is currently implemented for all record types. We will not promise automatic erasure on a schedule the product does not yet support.
Questions and requests
Use the Metal Mantra support form to request access, correction or removal review, or to ask about a repository claim. Include enough context to locate the record, but never include a password or private key. A request does not itself immediately remove a public report or third-party source.