Last updated September 15, 2026
Privacy
Since.dev reads public sources on your behalf and tells you what changed. This page explains what it stores, why, who else touches it, what it will never do, and what you can take with you.
The short version
- Your watch instructions and notifications are private to your account and are never sold. They are not published as a community interest feed.
- What the world did (a package release, a changelog entry, a published price) is a public fact. Since.dev keeps public-source facts without an account identifier, so they are not treated as private account data and may be available to other customers watching the same thing.
- Since.dev watches software artifacts and public pages, not people. See people.
- We do not train models on your content.
- Export and deletion are self-service from Settings for the account owner. Before deleting your login, leave invited teams, delete additional workspaces you own, and remove other members and pending invitations from your primary workspace. Deleting an additional workspace preserves your login and other workspaces.
- This website counts visits with Google Analytics. There is no advertising network, and nothing follows you to other sites. See cookies and analytics.
Who is responsible
Since.dev is the controller of the personal data described on this page. For any privacy question or request, write to privacy@since.dev. We answer every request, including the ones we have to refuse, and we say why.
What is stored
Account
Your name, email address, authentication credentials or the identity your sign-in provider returns, the setting that decides how big a change has to be before you are emailed about it, and your starting sensitivity for new watches. Billing runs through Stripe. Since.dev stores a customer reference and your plan, never card numbers.
Since API keys
A Since API key is a 12-character lookup prefix and a 192-bit secret. Only a SHA-256 digest of the secret is stored, so a key is displayed once at creation and a lost key is replaced rather than recovered. We cannot read your key back to you because the digest cannot be used to recover the secret.
What you asked to watch
The sentence you typed or the subject, aspect, and delivery mode your agent registered; the canonical subject it resolved to; and the sources used to watch it. This is private to your account.
What you were told
Every change we emailed you about and the reasons attached to it, kept for the life of the watch so its timeline can answer whether you were told and when. A change held back by the rate limit is recorded the same way, with the reason, because a change withheld silently is indistinguishable from the product being broken.
Connected repositories and repairs
When you connect GitHub, we store the installation and repository identifiers, selected directories, dependency bindings, repair permissions, and agent access grants. Authorized analysis reads bounded repository content. Impact findings, relevant code excerpts, exact patch contents, base revisions, PR references, review instructions, check results and repair activity are retained so you can inspect the repair history.
This information is private to your account and explicitly authorized agents. It is not included in shared public observations or public interest rankings. GitHub receives authorized branch, commit, and PR changes. Relevant code and external evidence are sent to Since’s hosted model on Free, or to the AI provider your workspace connects on a paid plan, to analyze impact and prepare supported repairs. Do not put credentials in source files or repair instructions.
Revoking GitHub access or disconnecting a repository stops new repository work while retaining its repair history. These actions do not delete existing PRs from GitHub. Account export and deletion apply to your stored repository and repair records.
AI provider credentials are encrypted before storage. We use them only for the selected workspace’s authorized repository AI and connection checks. Settings display a masked credential hint, and account exports exclude credentials. Disconnecting the provider removes the stored credential and stops new requests through that connection. A request already sent to the provider may finish.
Where you asked us to deliver
Webhook endpoint URLs, their signing secrets, and the delivery record for each attempt: status code, timing, and whether it was retried or parked. Delivery records are operational data about your endpoint, not about you.
What the sources said
Facts read from public sources and detected changes are stored without an account identifier. They describe a public record, not you, so they are not personal account data and are not part of an account export.
Technical logs
Request metadata for the API and the website: timestamp, route, response status, approximate location derived from the IP address, and the IP address itself. These exist for reliability, rate limiting, and abuse investigation. They are not used to build a profile of you and are not combined with your watches.
Why we process it
Where the GDPR or a similar law applies, these are the grounds we rely on:
- To perform our contract with you: creating and running your account, registering watches, checking sources, delivering changes and notices, analyzing authorized repositories, preparing requested repairs, and taking payment.
- Our legitimate interests: keeping the service up, preventing abuse and fraud, enforcing plan limits, and maintaining the ability to avoid unnecessary repeat requests to public sources. We use the minimum data each of those needs.
- Legal obligation: keeping invoices and tax records for the period the law requires.
People
This is the boundary that matters most, so it is stated plainly.
- Since.dev watches software artifacts and public pages: registry packages, repositories, changelogs, advisory catalogs, status feeds, documentation, and pricing pages. It does not watch people.
- It refuses any request approximating a person’s location, movements, schedules, presence, relationships, social accounts, household, or private life, and it refuses to compile a profile or dossier about an individual, however the request is framed.
- Refusals are explicit and explained, so the request receives a clear boundary.
This costs us some legitimate use cases. It is the right trade. If you believe someone is misusing Since.dev to monitor you, write to security@since.dev and we will investigate.
How sources are read
- Since.dev identifies itself in every request and checks robots.txt before fetching a page or feed. Where a source disallows automated access, the interest is marked uncoverable and you are told. It is never worked around.
- Public-source monitoring never bypasses a paywall or login. Connected private repositories are accessed separately through the GitHub app permissions you explicitly grant. Where a registry offers an optional token whose only effect is a higher rate limit, one may be used.
- It reads on a cadence set by how fast the underlying thing actually moves, with conditional requests where the source supports them.
- It does not republish source content. A change states the field that moved and where it was read, quotes a short factual excerpt where one is needed, and links to the original.
Models
We use AI to understand plain-language requests, resolve ambiguity, assess whether a change matters, interpret unfamiliar dependency files, analyze authorized repository code, prepare and review supported patches, and check whether a value your agent verifies is the same value written two ways. Reading changes already available to your account does not send their contents to an AI provider.
AI may receive the watch text, relevant source excerpts, dependency data, relevant repository content and repair instructions, or the values compared during a fact verification, as needed for those purposes. It may also help apply our safety rules to ambiguous requests. AI does not create source facts: every reported change remains tied to a difference in a real source.
We do not train models on your content. World State and Free repository analysis use Since’s hosted AI. Paid repository analysis and repairs use the Anthropic, OpenAI, or AWS Bedrock account your workspace connects. Your provider account’s terms and settings govern its processing and retention. Bringing your own credentials does not remove Since’s access to the repository content or saved repair history described above.
Processors
These companies process data on our behalf, under contract, for the stated purpose and nothing else.
| Processor | Purpose |
|---|---|
| Vercel | Hosting and delivery for the public website and the application console, and their request logs. |
| Railway | Hosting for the backend API, background monitoring and repair workers, and their operational logs. |
| GitHub | Authorized repository access, app installation metadata, branches and draft PRs, review feedback, and repository check results. |
| Supabase | Hosting for account and watch data, public-source facts, private repository findings and patches, and change and repair history. |
| Anthropic | Since-hosted AI for watch interpretation, source qualification, change classification, dependency analysis, fact verification, and bounded repository impact analysis on Free. Paid repository work uses the workspace’s selected provider account. |
| Stripe | Subscription checkout, billing, and payment processing. |
| Resend | Transactional email: material-change and source-health notices, and team invitations. |
| Google sign-in when you choose that authentication method, and Google Analytics traffic measurement on the public website. |
We will announce a new processor by email before it starts handling personal data, so that you have time to object or to leave.
International transfers
Our processors operate in the United States and, in some cases, elsewhere. Where personal data leaves the European Economic Area, the United Kingdom, or Switzerland, the transfer is covered by the European Commission’s Standard Contractual Clauses or another lawful mechanism. A copy of the relevant terms is available from privacy@since.dev.
Security
- Traffic is encrypted in transit. Stored data is encrypted at rest by our database provider.
- Since API secrets are stored only as SHA-256 digests. Customer AI provider credentials are encrypted so we can make authorized requests. Passwords, where used, are stored only as salted hashes; we never store a password in a readable form. Card details never reach our systems.
- Access to production data is limited to the people who need it to operate the service.
- Webhook payloads are signed with HMAC-SHA256 over the raw body and a timestamp, so you can verify that a delivery came from us and was not replayed.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulator within the time the law requires, with what we know and what we are doing about it. To report a vulnerability, write to security@since.dev.
Retention
- Account data, watches, the record of what you were told, and delivery records are kept while your account is open.
- Deleting your account removes your account, API keys, watches, the record of what you were told, and webhook endpoints. Public-source facts that are not linked to your account may remain because they do not contain personal data about you.
- Closing a watch stops its checks and deliveries. Its activity and notification history remain available while your account is open.
- Technical logs are kept for a short operational window and then deleted.
- Invoices and tax records are kept for as long as accounting and tax law requires, which is longer than the rest.
Your rights
Export and deletion are self-service in Settings for the account owner and do not require you to ask us. Before deleting your login, leave invited teams and remove other members and pending invitations from your owned workspace. Depending on where you live, you may also have the right to access your data, correct it, restrict or object to how we use it, withdraw consent, and receive it in a portable format.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California law. We have never done either, so there is no opt-out to offer you. We will not discriminate against you for exercising a right.
Write to privacy@since.dev and we will respond within the period the applicable law sets. If you are in the EEA, the UK, or Switzerland and you are unhappy with our answer, you can complain to your local supervisory authority.
Cookies and analytics
This website uses Google Analytics 4 to count visits and see which pages get read. It sets first-party cookies, named _ga and one named for our measurement id, and reports the pages you view, the site that referred you, your device and browser type, and an approximate location that Google derives from your IP address without retaining the full address.
It is used to understand traffic, and for nothing else. It is not advertising, it is not linked to your account or your watches, it is not sold, and it does not follow you to other websites. The application itself carries no analytics at all: only this public site does.
You can opt out by blocking the script with a browser setting or extension, by using a browser that blocks it by default, or with Google’s own opt-out add-on. Blocking it costs you nothing here, because no part of this site depends on it.
Apart from analytics, the application sets a single cookie that keeps you signed in. That one is strictly necessary and cannot be turned off while you are using the app. There is no advertising cookie anywhere in the product.
Children
Since.dev is a tool for developers and professionals. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to privacy@since.dev and we will delete it.
Changes
Material changes to this page will be announced by email before they take effect, and the date at the top will change. General questions: hello@since.dev.