Legal · Privacy

Privacy Policy

All Still Good is built to be the safe way to check an app you can't read. This policy explains what we collect, what we deliberately do not store, and who processes data on our behalf.

Last updated: August 1, 2026

1. Who we are

All Still Good, operated by Eastbase Studio (“All Still Good”, “we”, “us”), provides continuous health and security monitoring for web applications. This policy describes how we handle personal data when you use the service.

2. Information we collect

  • Account data — your email address and authentication details. If you sign in with GitHub or Google, we receive basic profile information from that provider.
  • Project data — the URL of an app you've verified you own, your ownership-verification details, optional scan settings, and (optionally) a Supabase anon key or a connected GitHub repository you choose to add.
  • Scan results — the findings, health scores, and history produced when we monitor your verified app (see Section 4 for what we deliberately do not keep).
  • Billing data — handled by our payment provider (Lemon Squeezy). We receive your subscription status and plan, not your full card details.
  • Usage & diagnostics — product-analytics events and error reports that help us understand activation and fix bugs (see Section 6).
  • Communications — anything you send us by email or support request.

3. How we use information

  • To run the monitoring you ask for and deliver findings, alerts, and fix briefs.
  • To verify ownership of a target before any scan runs.
  • To operate billing, send service emails (such as alerts), and provide support.
  • To understand activation and improve the product, and to keep the service secure and reliable.

We do not sell your personal data, and we do not use the contents of your app or your scan results to advertise to you.

4. What we deliberately do not store

The way All Still Good handles sensitive data is a core design decision, not an afterthought:

  • Secrets are stored only as redacted fingerprints — never the raw value. If a scan detects a leaked key, we keep enough to identify and de-duplicate the finding, not the secret itself.
  • Personal data exposed by your app is counted, not retained. If an endpoint leaks user records, we record that it happened and roughly how much — we do not copy your users' data into All Still Good.
  • We never accept or store a Supabase service_role key. It is rejected at the validation layer by design.
  • All probes are read-only and non-destructive — we do not write to, change, or exploit your application.

5. AI processing

To write plain-English findings and translate a synthetic-journey description into safe observational steps, we send redacted finding metadata (such as the issue type and the affected path) or the journey description you provide through Vercel AI Gateway to OpenAI’s GPT-5.6 models. We do not send raw secrets discovered by scans or retained user records for this purpose; do not put credentials or personal data in a journey description. If AI access is not configured, findings still work without AI explanations.

6. Cookies & analytics

We use a small number of cookies and similar technologies:

  • Essential — to keep you signed in and operate the app. These are required for the service to work.
  • Product analytics — PostHog helps us understand how people activate (sign up → verify → first scan) so we can improve the flow.
  • Traffic analytics — Vercel Analytics counts page views and referrers. It is cookieless and does not track you across other sites.
  • Error monitoring — Sentry captures diagnostic information when something breaks so we can fix it.

You can control cookies through your browser settings. If you are in a region that requires consent for non-essential cookies, we will honor your choices where required by law.

7. Third-party providers (subprocessors)

We rely on the following providers to operate All Still Good. Each processes only the data needed for its function:

  • Neon — database hosting for your account, projects, and findings.
  • Lemon Squeezy — payments and subscription billing (Merchant of Record).
  • Vercel — application hosting, AI Gateway routing for AI-generated content, and cookieless traffic analytics.
  • OpenAI (GPT-5.6) — AI-generated explanations, fix briefs, scan summaries, and journey steps.
  • Resend — transactional and alert emails.
  • PostHog — product analytics.
  • Sentry — error monitoring.
  • Inngest — background job scheduling for scans.
  • OSV.dev — open-source vulnerability data for dependency checks.
  • GitHub and Google — optional OAuth sign-in and repository access, only if you connect them.

This list may change as the product evolves; we will keep it current.

8. Data retention

We keep account and scan data for as long as your account is active so the watch-over-time history stays meaningful. Self-serve deletion isn’t built yet: email privacy@allstillgood.com to have a project or your whole account deleted, and we delete the associated data, except where we must retain limited records for legal, accounting, or security reasons.

9. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can change your email and password in your account settings; for access, export, or deletion requests, contact us and we will respond as required by applicable law.

10. Security

We use industry-standard measures to protect your data, including encryption in transit, encryption of sensitive stored values, ownership verification before scanning, and the minimization described in Section 4. No system is perfectly secure, but reducing what we store is our first line of defense.

11. International transfers & children

Our providers may process data in countries other than yours; where required, we rely on appropriate safeguards for those transfers. All Still Good is not directed to children, and we do not knowingly collect data from anyone under 18.

12. Changes & contact

We may update this policy as the product changes; material updates will be reflected in the “last updated” date above. For privacy questions or requests, email privacy@allstillgood.com or see our Terms of Service.