Scrub Disclaimer
Effective date: August 12, 2026 · Provider: Todd Fishman (doing business as Cinderella FYI; "Cinderella").
What "scrubbing" means
When you upload a Submission, Cinderella runs an automated process that:
- Removes files that should never ship (e.g.
.envfiles, database dumps,
private keys, certificates).
- Scans text for secrets (API keys, tokens, private keys) and **personal
data (emails, phone numbers) and redacts** matches.
- Never ingests git history — only the current files — so historical secrets
cannot travel with a Submission. The scrubbed bundle, not your original repo, is the deliverable in every sale.
- Produces a report of everything it removed or redacted.
The scrubber checks for known secret patterns — including provider API keys (e.g. OpenAI, Anthropic, AWS, Stripe live keys, GitHub tokens), JWTs, private key blocks, and generic secret = "..." assignments — as documented in our technical documentation, which may be updated from time to time. The pattern list is not exhaustive.
What scrubbing does NOT mean
- It is not a guarantee. Automated detection can miss novel key formats,
obfuscated secrets, secrets inside binaries or images, or personal data that doesn't match a known pattern.
- It is not a security audit, code review, or legal review.
- It does not verify ownership or licensing of the code.
- It does not make code safe to run. Buyers must review before deploying.
Your responsibilities
- Sellers: remove secrets and personal data *before* uploading, and review
the scrub report and cleaned files before listing. The scrub is a safety net, not your first line of defense. Under the Seller Agreement, sellers remain responsible for secrets they introduced and indemnify Cinderella and buyers for claims arising from them.
- Buyers: independently review any purchased Submission for secrets, license
terms, and security before using it.
Human review
High-risk Submissions (where the scrubber flags blocking findings) are held for manual review before they can be listed. Our target is to complete review within 72 hours of the flag. This is a service target, not a guarantee. If review cannot resolve a flagged item, the Submission stays unlisted until the seller fixes and re-uploads it; unresolvable Submissions are rejected.
If a secret survives
If you discover a live secret, credential, or personal data in a purchased Submission:
- Notify us immediately at support@cinderella.fyi (and rotate/revoke the
credential if it is yours).
- We will pull the listing from the marketplace pending investigation.
- We will notify the seller, who is obligated to rotate the credential and
remediate.
- We will re-scrub the Submission and investigate why the pattern was
missed, updating the scrubber where possible.
- If the discovery happens during the 7-day inspection window, it is valid
grounds for a dispute and refund under the Buyer Agreement.
This process is a good-faith commitment to respond; it does not create liability beyond the limits below.
Limitation of liability
To the maximum extent permitted by law, Cinderella provides the scrub "as is" and is not liable for any secret, credential, or personal data that survives it. Sellers remain responsible for what they upload; Buyers for what they deploy.
Cinderella's total liability for any claim arising out of or relating to the scrub is capped at $1,000 per claim (or the fees the claiming party paid Cinderella for the transaction giving rise to the claim, if greater). This cap and the "as is" disclaimer do not apply to Cinderella's fraud, gross negligence, or willful misconduct, or to any liability that cannot be limited under applicable law.
