Privacy

Gawlo is pre-release. This page describes what the product stores today and who it is shared with. If a practice changes, this page changes with it.

What we store

Your account email and authentication state (handled by Supabase Auth); your organisation and its members; the projects you create, including each target URL and its scan configuration; and the scans, findings, and remediations those projects produce. Findings include the request and response that triggered them — that evidence is the point of the product, and it can contain data from your own system.

Secrets you give us

Credentials a scan needs — session tokens, a GitHub token for private source discovery, your own model API key — are write-only. Once stored they are never sent back to the browser: the UI is told only that a secret exists. Gawlo API keys are stored hashed; the full key is shown exactly once, at creation, and cannot be recovered afterwards.

Who else sees it

Findings that you ask to remediate are sent to Anthropic's API to generate the explanation and patch. Payment details, if you are on a paid plan, are handled by Stripe — we never see or store a card number. Application data lives in Supabase (PostgreSQL). We do not sell your data and we do not share it with anyone else.

Access and deletion

You can delete a project, and its scans and findings go with it. To delete your account and everything attached to it, email support@gawlo.dev and we will do it and confirm when it is done.

Questions

Ask us anything about this at support@gawlo.dev. If a detail on this page turns out to be wrong, tell us and we will correct it.