Privacy Policy
Last updated: July 28, 2026. This policy applies to Ispravko and its website at ispravko.com.
Ispravko analyzes Python files, reports code issues, stores analysis history for signed-in users, and can generate corrected Python output when a fixed-code credit is used.
Static analysis is performed with automated developer tools. Corrected-code generation may also use an external code-processing provider when that stage is enabled.
You may sign in with GitHub or Google. Depending on the provider, Ispravko may receive your name, username, verified email address, profile image, stable provider account identifier, and authentication-related metadata.
Auth.js and the database adapter may store OAuth account records, session records, token expiry information, granted scopes, and OAuth tokens returned by GitHub or Google as part of establishing and maintaining the account connection.
Ispravko does not receive or store your GitHub or Google password.
OAuth information is used for authentication, session security, account linking, and maintaining access to your Ispravko account. Ispravko does not intentionally use OAuth tokens to read unrelated GitHub repositories, Gmail messages, Google Drive files, contacts, calendars, or other provider content.
When supported, GitHub and Google sign-in methods may be linked to the same Ispravko user when they provide the same verified email address.
For ordinary gmail.com and googlemail.com addresses, Ispravko may normalize letter case, the googlemail.com domain, and dots in the part before the @ symbol to reduce duplicate accounts caused by equivalent Gmail address forms.
This Gmail-specific normalization is not applied to business, school, or other custom email domains.
If two accounts cannot be linked safely or automatically, contact support before purchasing credits on both accounts.
Uploaded code: the content and filename of the Python file needed to perform analysis or corrected-code generation.
Usage data: saved analysis results, issue summaries, daily usage counters, account plan, credit balances, and payment request status.
Payment data: Lemon Squeezy processes checkout and card information. Ispravko receives order and refund events but does not store full card numbers.
Technical data: limited request metadata, error logs, rate-limit information, deployment logs, and security events needed to operate and protect the service.
Optional analytics data: public pages viewed, approximate location, browser and device category, referral source, session information, scroll activity, and outbound-link interactions when Analytics has been accepted.
To authenticate users through GitHub or Google and maintain secure account sessions.
To connect permitted sign-in methods to the correct Ispravko account and preserve analysis history and purchased credits.
To provide file analysis, dashboard history, corrected-code generation, copying, and downloads.
To apply the one guest trial, five daily signed-in analyses, and purchased credit balances.
To confirm purchases, handle refunds, prevent abuse, diagnose failures, and improve service reliability.
When optional Analytics is accepted, to understand which public pages are useful, how visitors reach Ispravko, and where the public product experience can be improved.
Only UTF-8 Python files with the .py extension and a maximum size of 1 MB are accepted.
Temporary backend files are deleted after processing on a best-effort basis.
Signed-in analysis summaries and issue rows may be saved to your dashboard. The full uploaded source file is not intentionally stored in the application database.
Do not upload API keys, passwords, private keys, access tokens, production credentials, confidential code, personal data, or third-party code you are not authorized to process.
When corrected-code generation is requested and the external stage is enabled, the Python source and a limited issue list may be sent to OpenAI or another configured provider solely to produce a corrected candidate.
Generated output can be incomplete or incorrect. Ispravko performs syntax and static-analysis validation where possible, but you remain responsible for reviewing and testing all output before use.
Do not use corrected-code generation for code that cannot be shared with an external provider.
Ispravko uses Google Analytics 4 only after a visitor accepts optional analytical measurement through the privacy-choice panel.
The Google Analytics tag is not intentionally loaded before Analytics is accepted.
Analytics is configured without Google Signals and without advertising-personalization signals.
Ispravko does not intentionally send Python source code, filenames, email addresses, GitHub usernames, Google account names, database user IDs, analysis IDs, payment identifiers, OAuth tokens, or other account secrets to Google Analytics.
Analytics page-view events are not intentionally sent for dashboard, billing, authentication callback, or API routes.
Public page URLs sent to Analytics are reduced to the site origin and pathname. Query parameters and URL fragments are not intentionally included.
Essential cookies or browser storage may be used for authentication, database-backed sessions, security, and core service functionality.
GitHub or Google may set their own cookies while you use their authentication pages. Those cookies are controlled by the relevant provider.
When Analytics is accepted, Google Analytics may set first-party cookies such as _ga and _ga_<container-id> to distinguish visitors and maintain session state.
Your Analytics choice is stored in your browser under the local-storage key ispravko_analytics_consent. This preference is not intended to contain your identity or account information.
After you make a choice, the Cookie settings button allows you to reopen the privacy panel and change that choice.
When Analytics is rejected or withdrawn, Ispravko stops future Analytics loading where technically possible and attempts to remove Google Analytics cookies created for the Ispravko domain.
Temporary uploaded files are removed after processing on a best-effort basis.
Saved analysis history remains in your account until you delete it or until a future retention policy is introduced.
Account, OAuth connection, session, payment, and operational records may be retained while needed to provide the service, protect accounts, maintain credits, meet accounting obligations, prevent fraud, or diagnose failures.
Expired or revoked provider tokens may remain in historical database records until they are replaced, cleaned up, or the related account is deleted, but they should no longer provide valid provider access after revocation.
Google Analytics event and user data may be retained for up to 14 months according to the configured Google Analytics property settings.
Your local Analytics-consent choice remains in your browser until you change it, clear browser storage, or use another browser or device.
GitHub and Google provide OAuth authentication and account profile information used for sign-in.
Lemon Squeezy provides checkout, payment processing, receipts, taxes, and refund events.
Render or another infrastructure provider may host the frontend, backend, and database.
OpenAI or another configured provider may process code only during corrected-code generation.
Google may process optional website-analytics data only after analytical measurement has been accepted.
Ispravko does not sell account information, OAuth profile information, uploaded code, analysis history, or credit balances to advertisers.
Information may be disclosed where necessary to provide the service, protect users, investigate abuse, comply with legal obligations, or respond to valid legal requests.
You can use the single guest analysis without creating an account, choose not to upload a file, delete saved analyses from the dashboard, or stop using the service.
You can revoke Ispravko access from your GitHub or Google account settings. Revoking provider access does not by itself delete your Ispravko account, analysis history, payment records, or remaining credits.
You can reject optional Analytics when the privacy panel appears and later change that choice through Cookie settings.
Clearing the Ispravko site data in your browser removes the locally stored Analytics-consent preference.
You may request access, correction, unlinking of a provider, or deletion of account-related information by contacting support@ispravko.com.
Some billing, fraud-prevention, security, or accounting records may need to be retained where required by law or legitimate operational needs.
Ispravko uses OAuth authentication, database-backed sessions, file validation, size limits, credit checks, internal service authentication, rate limits, temporary processing, and server-side validation to reduce risk.
Google sign-in is accepted only when the Google OAuth profile reports a verified email address.
Account-linking rules are designed to reduce duplicate accounts while avoiding normalization of non-Gmail business or custom domains.
Do not publish OAuth access tokens, refresh tokens, ID tokens, session cookies, database URLs, provider secrets, or private deployment values.
No online service can guarantee complete security. Ispravko may change as reliability, features, and protections are improved.
For privacy questions, OAuth account-linking requests, provider unlinking, Analytics questions, or account-deletion requests, contact support@ispravko.com.