Skip to content

Privacy Policy

Effective date: 2026-04-26

1. Information We Collect

  • Account data: GitHub user ID, display name, email address, and OAuth access token obtained when you sign in.
  • Repository data: Source code from repositories you connect, accessed only to perform the Service (propose fixes and open pull requests).
  • Job records: Title, description, status, error messages, and PR URL retained for each job you create.
  • Email address: Collected when you join the waitlist or create an account; used only for transactional and product notifications.
  • Agent registration data: A coding agent may submit an email address you provide, the project name, and your yes/no choice about limited setup or product follow-up. We immediately send a transactional claim email regardless of that choice.

2. How We Use Your Information

We use collected data to: authenticate you; clone and analyse your repositories to propose code fixes; open pull requests on your behalf; send transactional and product update emails; and improve the reliability and quality of the Service.

3. Data Processors

We share data with the following sub-processors to operate the Service:

  • GitHub: Repository access and pull-request creation. See github.com/site/privacy.
  • Anthropic: AI code generation when an Anthropic model is configured. See anthropic.com/privacy.
  • OpenAI: AI code generation when an OpenAI model is configured. See openai.com/policies/privacy-policy.
  • Amazon Web Services (SES): Transactional email delivery. See aws.amazon.com/privacy.

4. Data Retention

OAuth tokens are stored only while your account is active and are deleted when you close your account. Repository contents are processed transiently and are not persisted beyond the duration of an individual job. Job metadata (title, status, PR URL) is retained for debugging and audit purposes. Unclaimed agent-created projects, provisional telemetry, and registration records are deleted after seven days. We retain a non-reversible registration identifier to prevent an expired request from being reused. After claim, consent value, timestamp, and source are retained for audit; addresses without consent are used only for the claim transaction and support, while consenting addresses may receive limited manual setup follow-up.

5. Your Rights

You may request deletion of your account and associated data at any time by emailing [email protected]. We will respond within 30 days.

6. Security

We use administrative, technical, and organizational safeguards designed to protect your information. No system is completely secure; use the Service at your own risk.

7. Changes to This Policy

We may update this Privacy Policy from time to time. The effective date at the top of this page will reflect the latest revision.

8. Contact

Privacy questions or data-deletion requests? Email [email protected].