Legal
Privacy Policy
Draft — pending legal review. These terms are published early so you can read what we intend to agree to before you install anything. They have not been reviewed by outside counsel and are not yet in force. Nothing here creates a contract until it is executed or you accept it at sign-up, and we will not apply a materially worse version to an existing customer without 30 days notice.
1. The short version
- We hold very little personal data: essentially your GitHub identity and billing contact.
- We hold a lot of code, and we treat it as confidential customer content, not as data about people.
- We do not train models on it, sell it, or use it for advertising.
- Uninstalling deletes everything within 30 days through one audited pipeline.
The long version is below, and the operational detail — subprocessors, retention per data type, the isolation model — is on the trust centre.
2. Who is responsible
SuperDiffs, Inc., a Delaware corporation, is the controller of the personal data described here. Registered address published once incorporation completes. Contact: privacy@superdiffs.com.
For repository content processed on your behalf, we act as a processor and you are the controller. Those terms are in the Data Processing Addendum.
3. What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | GitHub user ID, login, display name, avatar URL, email address, organisation membership. | GitHub, when you sign in or install |
| Installation data | Repository names and IDs, visibility, default branch, installation ID. | The GitHub App |
| Repository content | Diffs, file excerpts needed for context, pull-request titles and descriptions, comments in review threads, and the configuration and instruction files you ask us to read. | Your repositories |
| Review data | Findings and the evidence snippets behind them, model and prompt versions, token counts and cost, timings, status. | Generated by us |
| Billing data | Organisation name, billing contact, plan, seat counts, invoices. Card details are held by our payment processor, not by us. | You, and the payment processor |
| Product analytics and logs | Pages viewed in the dashboard, feature usage, IP address and user agent in request logs, error traces. | Your browser and our servers |
| Support correspondence | What you write to us, and our replies. | You |
4. Why, and on what legal basis
| Purpose | Data used | Legal basis (UK/EU GDPR) |
|---|---|---|
| Provide reviews | Installation data, repository content, review data | Contract |
| Authenticate you and keep accounts secure | Account data, logs | Contract; legitimate interests |
| Bill you and collect payment | Billing data, seat counts | Contract; legal obligation |
| Prevent abuse and enforce limits | Usage counters, logs, installation data | Legitimate interests (protecting the service and other customers) |
| Improve reliability and quality | Review metadata, error traces, aggregate outcomes — not code | Legitimate interests |
| Product analytics | Account identifiers, in-app events | Consent, where required |
| Meet legal and tax obligations | Billing records | Legal obligation |
Where we rely on legitimate interests, we have weighed them against your rights and you may object at any time — see section 9.
5. Your code is not marketing data
6. Who we share it with
Only the subprocessors listed on the subprocessor page, each for the purpose stated there, each under a written agreement with confidentiality and security terms. The most important one is the model provider that produces the review: it receives diff content and the file excerpts needed as context, and never receives credentials, because secrets are redacted before a prompt is built.
We may also disclose data where the law requires it. If we receive a compelled request for customer content, we will tell you unless we are legally prohibited, and we will challenge requests that appear overbroad.
If the company is acquired, data may transfer as part of it, subject to this policy and with notice to you.
7. International transfers
Our primary infrastructure is in the European Union. Some subprocessors — notably the model providers and the payment processor — are in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies, plus the technical measures described on the trust centre. The transfer mechanism for each subprocessor is named in the DPA.
8. How long we keep it
| Data | Where | Retention |
|---|---|---|
| Repository checkout (working copy) | Sandbox instance | Destroyed with the sandbox at the end of the review |
| Git bundle used to seed a sandbox | Object storage, encrypted per installation | 7 days, then swept |
| Finding evidence snippets | Postgres | Life of the finding — they are what lets us re-anchor a comment after a force-push without re-reading the old commit |
| Review and pull-request metadata | Postgres | 13 months, for usage history and billing disputes |
| Learnings (embedded team preferences) | Postgres (vector index) | Until deleted by the org, or on uninstall |
| Prompts and completions | Model provider | Provider default until a zero-retention amendment is executed |
| Everything, on uninstall | All stores | Deleted within 30 days through a single audited erasure pipeline |
Billing records are kept for as long as tax law requires, typically seven years, regardless of deletion elsewhere.
9. Your rights
Depending on where you live, you have some or all of these rights: access, correction, deletion, restriction, objection, portability, and withdrawal of consent. Californian residents additionally have the right to know, to delete, to correct, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising them.
- Exercise any of them by writing to privacy@superdiffs.com. We respond within 30 days.
- We do not charge for a request, and we do not require an account to make one.
- If your data is in a repository belonging to an organisation, we may need to route the request to that organisation, because they are the controller of that content. We will tell you if that happens.
- You may complain to your supervisory authority. In the EU that is your national data protection authority; in the UK, the Information Commissioner’s Office. We would rather you told us first.
10. Cookies and analytics
- Strictly necessary cookies only, by default. A session cookie to keep you signed in, and a CSRF token. No advertising cookies, ever.
- Product analytics run only with consent where consent is required, and record in-app events and account identifiers. They never receive repository content, diff content, or finding text.
- The marketing site sets no cookies until you sign in.
11. Security
Encryption in transit and at rest, per-installation encryption of stored bundles, hardware backed key storage for the GitHub App key, disposable sandboxes with default-deny egress, least-privilege tokens, logged staff access, and mandatory review on our own changes. The detail, including what is not yet done, is on the trust centre.
If a breach affects your personal data, we notify you and, where required, the relevant authority without undue delay and within 72 hours of confirming it.
12. Children
The service is not directed at children and we do not knowingly collect data from anyone under 16. If you believe we have, write to privacy@superdiffs.com and we will delete it.
13. Changes and contact
Changes are posted here with an updated date. Material changes are notified to your account email 30 days before they take effect.
Privacy questions: privacy@superdiffs.com. Security reports: security@superdiffs.com. Everything else: support@superdiffs.com.