Legal · Privacy
Privacy policy
This policy describes the data used by Longxia’s public, account-free agent skill scanner.
Last updated · July 26, 2026
What Longxia processes
When you start a scan, Longxia processes the public GitHub URL you submit and fetches supported text files from that public repository, folder, or file. The scanner records the canonical repository and source URL, selected ref and commit SHA, file paths and sizes, risk findings, short evidence excerpts, capability indicators, timestamps, and report identifier.
Repository code is treated as untrusted text and is never executed by the scanner. Longxia does not intentionally retain complete source files in the report database.
Rate limiting and operational data
To enforce the anonymous daily limit, Longxia creates a SHA-256 hash from the request IP address and the current UTC date. The scan database stores the hash, date, and request count—not the raw IP address. Cloudflare may separately process request metadata and security logs to deliver and protect the service.
Public reports and retention
A persisted scan receives an unlisted share URL. Anyone who obtains that URL can view the report, so do not submit a URL if its path, repository name, or findings should remain confidential. Ordinary reports are available for 30 days and are then made inaccessible; expired report rows are removed during routine scanner requests. Longxia may keep a small, curated set of clearly labeled public example reports for longer. Those examples may cover Longxia’s own public skill, third-party public repositories, or controlled security fixtures, and remain tied to the scanned commit. Old rate-limit rows are also removed periodically.
Anonymous report feedback
If you answer “Useful?” on a report, Longxia receives the report identifier, your Yes or No choice, and a random response identifier generated by your browser. The random identifier is stored in local storage for that report so repeating an answer updates the same response and changing your choice does not create a duplicate.
The response identifier is not derived from your name, email, IP address, or device information. Longxia stores only its SHA-256 hash with the choice and removes the response when the associated report expires or is withdrawn. You can remove the browser copy by clearing Longxia’s site data.
Service providers
- Cloudflare provides application hosting, network security, logs, and the D1 database.
- GitHub serves the public repository data requested by a scan.
Their processing is governed by their own privacy terms and may occur in multiple countries.
What the current service does not use
The public scanner currently has no user accounts, payment processing, advertising, behavioral analytics, or marketing email signup. If that changes, this policy will be updated before the new processing is introduced.
Your choices and contact
You can avoid report storage by not submitting a scan. To ask about a report or request deletion before its expiry, email hello@longxia.cool and include the report URL. We may need enough information to confirm the exact record. Applicable privacy rights vary by location.
Security, children, and changes
Longxia uses reasonable technical safeguards, but no online service can guarantee absolute security. The service is not directed to children under 13. Material changes will be reflected here with a new update date.