Privacy
Sunset reads repository text to compare it with the official OpenAI deprecations page. A free scan is not stored. The response is a count summary for that request.
A purchased Migration Report stores a snapshot in Postgres: report id, Stripe Checkout Session id, Stripe customer id when Stripe has one, repository identity, commit or ref when it can be read, scan time, the findings snapshot, the rule dataset retrieval date, the price recorded at purchase, and the time the row was created. The snapshot does not include GitHub tokens, Stripe secrets, the database connection string, or matched source lines.
Continuous Monitoring does not rewrite that purchased snapshot. A monitoring check reads the repository again only after Stripe says the subscription is active.
Payments are handled by Stripe. Sunset retrieves the Checkout Session from Stripe before it shows a paid report. The browser return URL is not treated as payment.