Erayaha maintains a strict zero-telemetry policy for Slop-Scan. When you run `slop-scan` locally or in your CI/CD runner, only package names extracted from your code are sent as public HTTP GET requests to the public npm registry (`registry.npmjs.org`) and npm downloads API (`api.npmjs.org`).
Your private source code, file paths, repository secrets, credentials, and business logic are never uploaded, retained, or transmitted to any third-party server or Erayaha infrastructure.
Our hosted GitHub Pages documentation site does not use tracking cookies, analytics trackers, or user fingerprinting scripts. Any web requests in our in-browser verifier connect directly from your browser to public registry endpoints without intermediary logging.
For privacy questions or security feedback, reach out to contact@erayaha.org.