Policy

Privacy

What Bivouac stores, what we look at on your GitHub repos, and what we never see.

What we collect from your repositories

Bivouac reads public and private advisory feed metadata, your repository dependency manifests (package.json, lockfiles, and equivalent files in your stack), and the events those produce — pull requests, runs, and merges. We do not read source code on your repositories except the manifests the triage loop needs to operate.

Telemetry and session data

We record the signals we triage, the decisions we took, and the patch PRs we opened and merged — that is the audit trail you see in the dashboard. Session data is handled inside the Bivouac app; we do not resell or share repository telemetry with third parties.

Contact

For data-subject requests, write to bivouac-c3gb0w@polsia.app.