npx seenrelay scan reads supported project files locally. It does not contact SeenRelay, upload source code, create an account, or enable reuse.Collect only what the validation job needs.
Effective September 25, 2026. This notice explains what SeenRelay processes, why it is processed, how long application data is retained, and which infrastructure providers may process service traffic.
Local scanner and hosted service are different.
What the hosted service processes.
The hosted service processes only data needed for deterministic fact matching, freshness evidence, abuse controls, and bounded operational measurement.
Do not submit passwords, API keys, access tokens, private cryptographic keys, signed URLs, or unnecessary sensitive personal data.
Why SeenRelay processes this data.
The purpose is to operate a validation-reuse service that can compare recent observations without treating them as universal truth, preserve authoritative fallback, prevent unsafe or abusive reuse, and measure whether the service is useful. SeenRelay does not sell personal data and does not use submitted values to train an AI model.
Application retention is bounded where operational state permits.
Fact summaries and aggregate operational measurements may be retained longer where needed for STALE/latest-observed semantics, abuse controls, or historical measurement. Infrastructure-provider backups and security logs follow the providers' own retention practices.
Service providers.
Use the local path when you do not want hosted processing.
You can use the local scanner without sending project source to SeenRelay. If you use the hosted service, submit only eligible public or legitimately accessible source-backed facts under your own policy. For product or privacy questions, contact the repository owner through GitHub. Do not post secrets or sensitive personal data in a public issue. For security vulnerabilities, use the repository's private vulnerability-reporting channel described in SECURITY.md.
Because SeenRelay has no user accounts and application identifiers are pseudonymous, locating data associated with a particular person may require enough information to identify the relevant pseudonymous record without exposing additional sensitive data.