Privacy policy
Last updated 2 October 2026. This policy covers DepScout, a plugin and connector for ChatGPT, Claude and other AI assistants published by Yash Chowdhury ("we").
What we collect
Only what your AI assistant (such as ChatGPT, Codex, Claude or Claude Code) sends to DepScout's tools to answer your request: package ecosystems, package names and versions, or a vulnerability ID. We don't receive your name, email, account details, source code, chat history or location, and we don't ask for them. Please don't include private package names you consider confidential.
How we use it
Solely to look up the requested packages or advisory in public vulnerability and package databases and return the result.
Who receives it
OSV.dev (operated by Google), which receives package names, ecosystems, versions and advisory IDs. deps.dev (Open Source Insights, operated by Google), which receives package names, ecosystems, versions and the linked repository name. Cloudflare, which hosts DepScout and processes requests on our behalf. We don't sell or share data with anyone else, and we don't use it for advertising or to train models.
Retention
We don't store your requests or results. Cloudflare may keep short-lived operational logs (such as IP address and request time) for security and reliability, for no more than 30 days, and caches identical public deps.dev and OSV.dev lookups for up to 30 minutes.
Your controls
You choose what to share; you can disable or uninstall DepScout in your AI assistant at any time. For questions or requests about your data, email yc@salesup.club.
Children
DepScout isn't directed to children under 13.
Changes
We'll update this page and its date if this policy changes.