1. What LidPush Collects
LidPush is a desktop application that requires GitHub authentication via OAuth 2.0. To operate securely, the following data is collected and stored:
- GitHub profile: GitHub user ID (numeric), username, display name, email address (if public on GitHub), and avatar URL — collected during OAuth authentication.
- Push history: Repository name, repository URL, visibility (public/private), files pushed, files cleaned, secrets blocked, total and clean size in MB, lines of code, upload mode, and timestamp for each push operation.
- Last seen / account timestamps: When your account was created and updated.
No file contents, source code, or project data are ever transmitted. The cleaning engine copies your project locally and only sends aggregate statistics (file counts and sizes, not file contents) to the database.
2. Security & Activity Logging
To detect abuse and trace a compromised account back to its source, every desktop OAuth hop logs a light-weight security record. Each log entry may contain:
- IP address from which the request originated.
- Approximate location derived from the IP address: country, region, and city.
- Internet Service Provider (ISP) name.
- User-agent string, plus parsed device type, operating system, and browser.
- Screen size, and the channel used (web or desktop).
- Which OAuth step it was (authorization, callback, error, token issuance).
One-time login codes are stored only as SHA-256 hashes — the raw code is never persisted and expires within minutes of issuance.
3. Data Storage
Data is stored in a Neon PostgreSQL database (cloud-hosted PostgreSQL). The following tables are used:
users— github id, username, name, email, avatar, encrypted token, timestampspush_history— repository stats and timestamps of each pushactivity_logs— security events (IP, geo, device, channel)refresh_tokens— hashed session tokens (SHA-256) with expirylogin_codes— hashed one-time codes (SHA-256) with expiryrepo_cache— a short-lived per-user cache of repository/org metadata
This data feeds the Lidprex platform for operational analytics and product improvement. No third-party analytics SDKs are used.
4. GitHub Access Token
Your GitHub OAuth access token is used only to call the GitHub API on your behalf (listing repos, reading metadata, and performing the pushes you request). It is handled in two places:
- On your machine: cached in Windows Credential Manager via the
keyringRust crate. The React frontend never has access to the token — it only sees success/failure responses from the internal API. - On the server: stored encrypted with AES-256-GCM using a per-user derived key (
githubTokenEncrypted/githubTokenIvin theuserstable). It is never stored in plaintext and never exposed through any API.
5. Internal API Security
The embedded API server starts on a local port every launch. Every request requires an x-lidpush-secret header containing a session secret. Nothing on the machine can call the internal API without knowing both the port and the secret.
6. What We Do NOT Collect
- No file contents or source code from your projects
- No credentials, API keys, or secrets found during scans
- No keystrokes, clipboard, mouse movements, or UI interactions
- No third-party analytics (no Google Analytics, Sentry, etc.)
- No cookies or tracking pixels on the desktop app
- No crash reports or error telemetry
7. Data Deletion
To request deletion of your data from the Lidprex platform, contact us through Lidprex Labs with your GitHub username. We will process deletion within 30 days. Deleting your Lidprex account also removes the server-side copy of your GitHub token.
8. Contact
For privacy-related inquiries, visit Lidprex Labs or open a discussion on GitHub.