Privacy notice
Last updated 13 September 2026
bibup is building software for engineering organisations. For now, this site does two things with personal data: it keeps a waitlist, and it runs a repository report when you ask for one. This page says exactly what each involves.
Who is responsible
bibup is an early project and has not been incorporated yet. Its founder is responsible for the data described here. Write to contact@bibup.ai about anything on this page, and if you ask for the name and postal address of the person responsible, you will get them.
When bibup becomes a company, this notice will name that company, and the waitlist will move to it under the terms written here.
What we collect
- Your email address, when you join the waitlist.
- The channel that brought you, if the link you followed named one, such as
utm_source=linkedin. The page keeps it in your browser's session storage until you close the tab, so it can be sent along with your email. - Your answers to the three optional questions, only if you send them: how many engineers your organisation has, whether anything blocks a merge in your pipeline, and who signs off on an architecture decision.
- Anonymous visit counts. We use Umami, which sets no cookies and does not identify you. We see how many people arrived and through which channel, not who they are.
We set no cookies, use no advertising pixels, and do not buy, sell or rent lists.
The repository report
A report request on bibup.ai takes the public repository addresses you paste, up to ten, and the page or campaign that brought you. It takes an email address only if you leave one. Only public repositories on github.com or gitlab.com are read, and the copy we read is discarded when the run ends. Cloudflare stores the requests, the address lists and the counters below; Loops stores contacts and sends the emails.
- The request, with the repository addresses and the page or campaign that brought you, is kept for up to 7 days while the run works, and for 90 days after the run ends, whether it finished or failed.
- The report is kept for 90 days after the run ends. The report page shows counts, commit identifiers and file paths from the repository's public history, and no commit message, name, handle or email address beyond repository and dependency addresses. Anyone you share its email link with can open the full report, and anyone with its picture address can leave an address to receive that link, up to three addresses per report.
- Your email address is used to send you the link to the report. It is added to our list in Loops as a contact, with the page or campaign that brought you as its source ("reporte" when there is none), and every email we send has a link to leave. The address is kept only until that email is sent; if it never is, it is deleted 90 days after the first address was left on that report, or 90 days after the report arrived if that is later. When a run needs a manual step, the first address left on it is also emailed to bibup's founder through Loops, and that email stays in his inbox and in Loops' send log.
- To allow at most three addresses per report, and to send each one email per report, we keep a fingerprint of each address, a hash of the address and the report's identifier, with which emails it has been sent, for as long as that report's address list: until 90 days after the first address was left on it, or 90 days after the report arrived if that is later. It cannot be matched to the same address on another report.
- To limit requests, we count them per network for each clock hour: an IPv4 address, or the /64 block an IPv6 address belongs to. The count is stored under a hash of a random secret, that network and the hour, never the address itself, and it is deleted within about two hours.
To have a request, an address or a report deleted sooner, write to contact@bibup.ai.
About the third question
It asks for a role, not a person. Please do not type anyone's name there: that person has not agreed to be on our list. If a name reaches us anyway, we will not contact them or use it for anything.
Why we use it
To tell you when there is something to try, to ask you about the problem while we build, and to understand which kinds of organisation have it. Nothing else. We rely on your consent, which you give by submitting the form, and you can withdraw it at any time.
Who else handles it
Three services run this page for us, and each processes data only on our instructions:
- Loops stores the waitlist and sends our emails.
- Cloudflare hosts the site and keeps short security logs, which include IP addresses.
- Umami counts visits, without cookies.
Some of these providers are based in the United States, so your data may be processed there.
How long we keep it
Until you leave the list or ask us to delete it. If the project ends, we delete the list.
Your choices
Every email we send has a link to leave the list. You can also write to contact@bibup.ai to see what we hold about you, correct it, or have it deleted, and we will answer within 30 days. If you are in the European Union or the United Kingdom, you can also complain to your data protection authority.
Children
This site is meant for people at work and is not directed at anyone under 16.
Changes
If this notice changes in a way that affects you, we will tell you by email before the change applies. Every past version of this page is kept.