Privacy — Undercut
This site (getundercut.sh) is a static page. It sets no cookies and runs no analytics — there is no tracker following you around while you're here. A few pages make plain, unauthenticated calls to GitHub's public API to show live data (details below), and if you use a form on this site your email goes exactly where we say it goes. Nothing is sold. The tool itself is downloaded by your agent and runs locally; the free tier does not phone home at all. Pro adds one authenticated exception — a periodic policy-file sync — covered separately and in full at What we can see, not on this page, because it's a licence check rather than a privacy question about your browsing here.
GET request directly from your browser to api.github.com (public repo/stargazer counts, public Actions run history). No cookie, account info, or anything identifying you is attached — just the standard headers your browser sends on any request. That request, and whatever GitHub logs from it (e.g. your IP address, per GitHub's own privacy policy), happens between your browser and GitHub directly; we don't see or store it. The star count is cached in your browser's sessionStorage for an hour, on your device only./api/lead endpoint. That endpoint validates the submission (allowed fields only, size-capped) and forwards it as JSON to a webhook URL the site operator configures — an email or spreadsheet automation tool — so we can send you your audit, send you your Pro trial sign-in details, or reply to your Teams or Enterprise request. The Teams flow's list of onboarding windows is a static file (/teams-availability.json) your browser fetches from this site — no calendar service, no third party. If no webhook is configured, submissions are rejected outright, not silently dropped. We don't sell this data or hand it to anyone beyond that configured destination.Questions about privacy or this policy: Justin Winter.
Updated 2026-09-15. Back to Undercut · What we can see · Accessibility · Brand