OpenACA

Privacy Policy

Last updated: September 2, 2026

This policy describes how OpenACA handles information for the public website, the open-source scanner, and the Claude Code plugin.

Website

When you visit openaca.dev, our hosting and infrastructure providers may process standard request metadata such as IP address, user agent, requested URL, and timestamps to serve the site, protect it from abuse, and debug reliability issues.

If you contact us by email, we use the information you provide to respond and to support the request.

Open-Source Scanner and Claude Code Plugin

The OpenACA Claude Code plugin runs OpenACA commands from Claude Code. Scanner and BOM commands run locally and do not upload scan results to OpenACA.

When you run scan or BOM commands, OpenACA may read local agent configuration and manifest files, including Claude Code settings, MCP configuration, plugin manifests, skills, hooks, commands, package manifests, and lockfiles. Command output may appear in your Claude Code session; Anthropic's handling of Claude Code sessions is governed by Anthropic's own policies.

To match known advisories, OpenACA may query public advisory services such as OSV.dev using package names, versions, source repositories, or other match coordinates required for vulnerability lookup.

How We Use Information

We use information to provide, secure, improve, and support OpenACA.

We do not sell personal information. We may share information with service providers that help operate OpenACA, when required by law, or to protect OpenACA and its users.

Retention and Requests

We retain information for as long as needed to provide the service, satisfy legal obligations, resolve disputes, and maintain security. To request access, correction, deletion, or other privacy help, contact us.

Contact

Questions about this policy can be sent to vinod@openaca.dev.