OpenACA
Privacy Policy
Last updated: September 2, 2026
This policy describes how OpenACA handles information for the public website, the open-source scanner, and the Claude Code plugin.
Website
When you visit openaca.dev, our hosting and infrastructure providers may process standard request metadata such as IP address, user agent, requested URL, and timestamps to serve the site, protect it from abuse, and debug reliability issues.
If you contact us by email, we use the information you provide to respond and to support the request.
Open-Source Scanner and Claude Code Plugin
The OpenACA Claude Code plugin runs OpenACA commands from Claude Code. Scanner and BOM commands run locally and do not upload scan results to OpenACA.
When you run scan or BOM commands, OpenACA may read local agent configuration and manifest files, including Claude Code settings, MCP configuration, plugin manifests, skills, hooks, commands, package manifests, and lockfiles. Command output may appear in your Claude Code session; Anthropic's handling of Claude Code sessions is governed by Anthropic's own policies.
To match known advisories, OpenACA may query public advisory services such as OSV.dev using package names, versions, source repositories, or other match coordinates required for vulnerability lookup.
How We Use Information
We use information to provide, secure, improve, and support OpenACA.
We do not sell personal information. We may share information with service providers that help operate OpenACA, when required by law, or to protect OpenACA and its users.
Retention and Requests
We retain information for as long as needed to provide the service, satisfy legal obligations, resolve disputes, and maintain security. To request access, correction, deletion, or other privacy help, contact us.
Contact
Questions about this policy can be sent to vinod@openaca.dev.