Privacy Policy
Last updated: July 2026
1. Who we are
Ripplex is a developer tool built and operated by Reabot6. We provide an MCP server, a GitHub App, and associated web services that scan pull requests and codebases for security issues, dead code, duplicate logic, and blast radius. Our contact email is onimisiadeolu@gmail.com.site.
2. What we collect
When you sign up, we collect:
- Your name and email address
- Your GitHub username (optional, used to link your subscription to the GitHub App)
- Your API key, generated at signup and stored in our database
When you use the service, we collect:
- Request timestamps and IP addresses, used to enforce daily limits and detect API key sharing
- Which MCP tools were called (check_impact, analyze_files, scan_project, etc.) and when
- Total daily request counts per API key, reset each day
We do not collect, store, or retain your source code. Code scanned by Ripplex is processed in an ephemeral sandbox and discarded immediately after the scan completes. Nothing is written to disk, nothing is retained, and nothing is used to train any model.
3. How we use your information
- To send you your API key and connection instructions on signup
- To send you usage warnings when you approach your daily request limit
- To enforce plan limits and prevent abuse
- To detect API key sharing and contact you if suspicious activity is found
- To send service updates and billing notices when paid plans launch
We do not send marketing emails beyond what you explicitly signed up for. We do not sell your data to any third party.
4. API key security and sharing
Your API key is personal to you. It grants access to all features on your plan. You are responsible for keeping it secure. Do not share it in public repositories, Discord servers, or with other users.
We monitor for suspicious usage patterns, including requests from multiple distinct IP addresses in a single day, which is a strong signal of key sharing. If we detect this, we will:
- Email you a warning at the address you signed up with
- Flag your key internally for review
- Revoke your key if sharing continues after the warning
If you believe your key has been compromised, email us immediately and we will issue a replacement.
5. Data storage
Your account data is stored in Supabase, a PostgreSQL database hosted on infrastructure in the EU West region. Request logs are retained for 30 days and then deleted. We use Railway to host our API server. Both providers maintain their own security and compliance standards.
6. Cookies
The Ripplex website does not use tracking cookies, advertising cookies, or analytics cookies. We do not use Google Analytics or any third-party tracking scripts. The only storage used is what your browser requires to render the page.
7. Third-party services
- Supabase -- stores your account data and request logs
- Railway -- hosts our API server and processes your scan requests
- Resend -- sends transactional emails (API key delivery, usage warnings)
- GitHub -- when you install the GitHub App, GitHub sends us webhook payloads containing PR metadata and file names. We use this to run scans. We do not store this data beyond the scan.
- Dodo Payments -- will handle payment processing when paid plans launch. Their privacy policy applies to payment data.
8. Your rights
You may request deletion of your account and all associated data at any time by emailing onimisiadeolu@gmail.com.site. We will process deletion requests within 5 business days. Deleted accounts cannot be recovered.
9. Changes to this policy
We will notify you by email if we make material changes to this policy. Continued use of Ripplex after notification constitutes acceptance of the updated policy.
10. Contact
onimisiadeolu@gmail.com.site