Skip to content

Legal

Privacy Policy

What we collect, why we have it, and how to get it back or get rid of it. Written in the order you would actually ask the questions.
Draft — pending legal reviewVersion 0.1 · Last updated 12 August 2026

Draft — pending legal review. These terms are published early so you can read what we intend to agree to before you install anything. They have not been reviewed by outside counsel and are not yet in force. Nothing here creates a contract until it is executed or you accept it at sign-up, and we will not apply a materially worse version to an existing customer without 30 days notice.

1. The short version

  • We hold very little personal data: essentially your GitHub identity and billing contact.
  • We hold a lot of code, and we treat it as confidential customer content, not as data about people.
  • We do not train models on it, sell it, or use it for advertising.
  • Uninstalling deletes everything within 30 days through one audited pipeline.

The long version is below, and the operational detail — subprocessors, retention per data type, the isolation model — is on the trust centre.

2. Who is responsible

SuperDiffs, Inc., a Delaware corporation, is the controller of the personal data described here. Registered address published once incorporation completes. Contact: privacy@superdiffs.com.

For repository content processed on your behalf, we act as a processor and you are the controller. Those terms are in the Data Processing Addendum.

3. What we collect

Categories of data
CategoryExamplesSource
Account dataGitHub user ID, login, display name, avatar URL, email address, organisation membership.GitHub, when you sign in or install
Installation dataRepository names and IDs, visibility, default branch, installation ID.The GitHub App
Repository contentDiffs, file excerpts needed for context, pull-request titles and descriptions, comments in review threads, and the configuration and instruction files you ask us to read.Your repositories
Review dataFindings and the evidence snippets behind them, model and prompt versions, token counts and cost, timings, status.Generated by us
Billing dataOrganisation name, billing contact, plan, seat counts, invoices. Card details are held by our payment processor, not by us.You, and the payment processor
Product analytics and logsPages viewed in the dashboard, feature usage, IP address and user agent in request logs, error traces.Your browser and our servers
Support correspondenceWhat you write to us, and our replies.You
Purposes and legal bases
PurposeData usedLegal basis (UK/EU GDPR)
Provide reviewsInstallation data, repository content, review dataContract
Authenticate you and keep accounts secureAccount data, logsContract; legitimate interests
Bill you and collect paymentBilling data, seat countsContract; legal obligation
Prevent abuse and enforce limitsUsage counters, logs, installation dataLegitimate interests (protecting the service and other customers)
Improve reliability and qualityReview metadata, error traces, aggregate outcomes — not codeLegitimate interests
Product analyticsAccount identifiers, in-app eventsConsent, where required
Meet legal and tax obligationsBilling recordsLegal obligation

Where we rely on legitimate interests, we have weighed them against your rights and you may object at any time — see section 9.

5. Your code is not marketing data

6. Who we share it with

Only the subprocessors listed on the subprocessor page, each for the purpose stated there, each under a written agreement with confidentiality and security terms. The most important one is the model provider that produces the review: it receives diff content and the file excerpts needed as context, and never receives credentials, because secrets are redacted before a prompt is built.

We may also disclose data where the law requires it. If we receive a compelled request for customer content, we will tell you unless we are legally prohibited, and we will challenge requests that appear overbroad.

If the company is acquired, data may transfer as part of it, subject to this policy and with notice to you.

7. International transfers

Our primary infrastructure is in the European Union. Some subprocessors — notably the model providers and the payment processor — are in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies, plus the technical measures described on the trust centre. The transfer mechanism for each subprocessor is named in the DPA.

8. How long we keep it

Retention periods
DataWhereRetention
Repository checkout (working copy)Sandbox instanceDestroyed with the sandbox at the end of the review
Git bundle used to seed a sandboxObject storage, encrypted per installation7 days, then swept
Finding evidence snippetsPostgresLife of the finding — they are what lets us re-anchor a comment after a force-push without re-reading the old commit
Review and pull-request metadataPostgres13 months, for usage history and billing disputes
Learnings (embedded team preferences)Postgres (vector index)Until deleted by the org, or on uninstall
Prompts and completionsModel providerProvider default until a zero-retention amendment is executed
Everything, on uninstallAll storesDeleted within 30 days through a single audited erasure pipeline

Billing records are kept for as long as tax law requires, typically seven years, regardless of deletion elsewhere.

9. Your rights

Depending on where you live, you have some or all of these rights: access, correction, deletion, restriction, objection, portability, and withdrawal of consent. Californian residents additionally have the right to know, to delete, to correct, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising them.

  • Exercise any of them by writing to privacy@superdiffs.com. We respond within 30 days.
  • We do not charge for a request, and we do not require an account to make one.
  • If your data is in a repository belonging to an organisation, we may need to route the request to that organisation, because they are the controller of that content. We will tell you if that happens.
  • You may complain to your supervisory authority. In the EU that is your national data protection authority; in the UK, the Information Commissioner’s Office. We would rather you told us first.

10. Cookies and analytics

  • Strictly necessary cookies only, by default. A session cookie to keep you signed in, and a CSRF token. No advertising cookies, ever.
  • Product analytics run only with consent where consent is required, and record in-app events and account identifiers. They never receive repository content, diff content, or finding text.
  • The marketing site sets no cookies until you sign in.

11. Security

Encryption in transit and at rest, per-installation encryption of stored bundles, hardware backed key storage for the GitHub App key, disposable sandboxes with default-deny egress, least-privilege tokens, logged staff access, and mandatory review on our own changes. The detail, including what is not yet done, is on the trust centre.

If a breach affects your personal data, we notify you and, where required, the relevant authority without undue delay and within 72 hours of confirming it.

12. Children

The service is not directed at children and we do not knowingly collect data from anyone under 16. If you believe we have, write to privacy@superdiffs.com and we will delete it.

13. Changes and contact

Changes are posted here with an updated date. Material changes are notified to your account email 30 days before they take effect.

Privacy questions: privacy@superdiffs.com. Security reports: security@superdiffs.com. Everything else: support@superdiffs.com.