Skip to content

Privacy Policy

Last updated: 15 June 2026

Latch (“we”, “us”) is operated by Yellow Pine. This policy explains what we collect, why, who we share it with, and the choices you have. We keep it short and specific — the way we try to keep the product.

What we collect

  • Repositories you analyze. Latch analyzes public GitHub repositories. For each analysis we store the report we generate, the bounded repository snapshot it was derived from (README, file tree, key manifests), the model and prompt version used, and token usage. These records are kept and are publicly viewable at their result page — see “Public content”.
  • Account data. If you sign in with GitHub, we store your GitHub account id, email address (or, where GitHub does not expose one, a stable @users.noreply.github.com address), and display name. Your session is held in a secure, http-only cookie.
  • Payments. Purchases (one-off unlocks and subscriptions) are processed by Stripe. We store the purchase and entitlement records (what you bought, when, the amount, and your plan) — we never see or store your card number; Stripe handles that.
  • Organizations. If you create or join an organization, we store the org, its memberships, roles, and seat allocation.
  • Product telemetry. We use Vercel Analytics and Speed Insights for aggregate, privacy-friendly usage and performance metrics. We record lightweight, append-only “interest” signals (e.g. a repo submission or a README-badge fetch, with the referring page) to understand demand and backlinks.
  • Feedback you send. If you send feedback — a one-tap reaction or a message through the in-product widget — we store what you submit: the message, the optional reaction and category, the page it came from, and, when you’re signed in or choose to give one, your email. We use it only to understand and improve the product and to reply if you asked us to; an optional email is never shared.
  • Abuse & security signals. To protect the service and bound costs we use Vercel BotID and edge rate limiting, which process request metadata such as IP address and request fingerprints at the network edge.

Cookies

We use a small number of functional cookies — a secure session cookie when you are signed in, the short-lived OAuth state cookie during the GitHub sign-in round-trip, and (for legacy purchases) an unlock cookie. We do not use advertising or cross-site tracking cookies.

How we use your data

To provide and operate the product (run analyses, render result pages, bind purchases to your account, enforce per-plan quotas), to process payments, to prevent abuse and control costs, and to understand and improve the product in aggregate. Where the GDPR applies, our legal bases are performance of a contract (your account and purchases), our legitimate interests (security, abuse prevention, product improvement), and consent where required.

Who we share it with (subprocessors)

We do not sell your personal data. We share it only with the providers that run Latch:

  • Vercel — hosting, edge network, analytics, bot protection.
  • Neon — our serverless Postgres database.
  • Stripe — payment processing.
  • Anthropic (via the Vercel AI Gateway) — the model that evaluates repositories.
  • GitHub — sign-in and reading public repository data.

We may also disclose data where required by law.

Public content

Analyses are of public repositories, and each result page is public, indexable, and shareable (that is the point — the score and badge are meant to be shared). The underlying repository data is already public on GitHub. If you are a repository owner and want an analysis of your repo removed, email us.

Retention

Analyses and their snapshots are kept as a durable record (append-only) so results stay stable and shareable over time. Account, organization, and billing records are kept for as long as your account exists and as required for tax and accounting.

Your rights

You can export everything that references you from your account page. Depending on where you live, you may have rights to access, correct, delete, or restrict processing of your data, and to data portability. To exercise them — including deletion, which we currently handle by hand while we finalize how it interacts with our append-only billing records — email hi@latch.fyi.

Security, transfers, and children

We use reputable infrastructure and encrypt data in transit. Our providers may process data in other countries under appropriate safeguards. Latch is not directed to children and is not intended for anyone under 16.

Changes & contact

We will update this policy as the product evolves and revise the date above. Questions or requests: hi@latch.fyi.