A public repository needs no access at all.
Or upload the project folder or a .zip in the app, or run npx broom-design audit in the project with a key from your profile.
Broom is a GitHub App with read-only access to contents and metadata, and only to the repositories you choose on GitHub.
The token from your GitHub sign-in is used once to learn your GitHub id, your username and which installations you can use, then discarded. It is never stored, logged or kept in your browser.
Reading a repository uses a short-lived read-only token — one hour — that our server gets from GitHub and holds in memory only.
UI source, styles, design tokens and config.
Never .git, dependencies, images, or files that look like secrets — .env, keys, .pem and similar.
A folder, .zip or CLI upload makes the same selection on your machine, and the server checks it again.
The findings, one rebuilt screen, your design tokens and the list of file paths we read — you can see it in the report. Never the whole codebase.
Uploaded files are held in memory for the run and not stored.
Delete a project from its results page and every run of it goes. Delete the account to remove everything.
Nothing you send trains a model — not ours, not Google's. The model runs on Google Cloud Vertex AI.
GitHub → Settings → Applications → Installed GitHub Apps → Broom → Uninstall.
CLI keys are revoked in your profile.
A question, or something you found: support@broom.design