Privacy
Short version: The Ironheights CLI has no telemetry. The in-browser scanner never sends your skill’s content anywhere; it runs in your browser. With your consent, the site records only the scan verdict (no content) through Google Analytics.
The Ironheights CLI
Scans, baselines, and quarantine stay on your machine. There is no telemetry, no account, and no default network call. The baseline is written to ~/.ironheights/baseline.json with owner-only permissions, or under IRONHEIGHTS_HOME if you set it.
Scans make no network call. Only the commands you choose can: fetch and safe-install talk to clawhub.ai, advisories update talks to ironheights.dev, and scan --llm or review talk to a model server you pick (off by default; the default is a loopback Ollama-compatible endpoint). The CLI prints each URL before it requests it, and none of this is telemetry. The guard plugin writes a redacted audit line for each flagged tool call to a local log (mode 0600) and sends it nowhere.
Installing through npm is subject to npm’s own policies. Reports you file on GitHub are subject to GitHub’s.
The in-browser scanner and the checklist
The scanner on /tools/scanner/ runs the rule engine inside your browser tab. The scanner never sends your skill’s content anywhere: your skill text, file names, and findings never leave the tab. Share links keep the text after the #, which browsers never send to a server. The risk checklist keeps your answers in this browser’s local storage only.
With your consent (site analytics, below), the site records only the scan verdict (no findings, review, or block), with no content, and that a checklist was completed with its result level. Nothing else from these tools is sent.
Website analytics (only with your consent)
ironheights.dev uses Google Analytics 4 (measurement ID G-1VW743D63T) to count visits and see which pages and tools are useful. It runs only after you choose “Accept analytics” in the banner. Until then, and if you choose “No thanks”, the Google script is not loaded, no analytics cookie is set, and nothing is sent to Google. We use Google Consent Mode v2 with every storage type denied by default; advertising storage, ad user data, and ad personalization stay denied even after you accept.
What is collected after you accept:
- Pages you view, as the address without any query string or
#part, the page title, and the referring page. - Device and browser details (type, operating system, browser, screen size, language) and visit timing.
- Approximate location (country and region or city), which Google derives from your IP address. Google Analytics 4 does not log or store IP addresses, and we ask for IP anonymization on top.
- A few events with fixed values only: a scan’s verdict label, a click on a scanner example, a completed checklist or risk quiz (with its result level), a click on the tracker’s report link, copying an
npx ironheightscommand (the subcommand name only), and clicks on links to GitHub, npm, or ClawHub (the domain only).
Never collected: skill text you paste or upload, file names, findings, search terms, checklist answers or notes, or anything else you type. The analytics helper accepts only a fixed list of events and values and drops anything else. Google Signals, advertising features, and ad personalization are off.
Cookies: _ga and _ga_<id>, first-party cookies holding a random identifier, set only after you accept and kept for up to 13 months. Your choice itself is stored in this browser’s local storage, not in a cookie.
Retention: Google Analytics keeps event-level data for 2 months, after which only aggregated reports remain. Legal basis: your consent (GDPR Article 6(1)(a)). Google acts as our processor; data may be processed in the United States under the EU-US Data Privacy Framework and Google’s standard contractual clauses.
Change your mind at any time: use (also in the footer) and choose “No thanks”. Analytics stop at once and the _ga cookies are deleted. You can also block Google Analytics everywhere with Google’s opt-out browser add-on or your browser’s tracker blocking; the site works the same either way.
Hosting
ironheights.dev is a static site hosted on Vercel. Our hosting provider keeps standard server logs (such as IP address, user agent, and requested URL) to operate and secure the service. There are no advertising scripts and no other third-party scripts.
Contact
Questions about privacy, or a request to access or delete data: open an issue on GitHub. Last updated 2026-10-11.