Zero Data Retention

Privacy Policy

Effective Date:

1. Data Handling Overview

Our platform handles highly sensitive intellectual property (your source code). To guarantee absolute security, we have engineered our systems around a strictly Zero-Retention Code Policy. If data isn't necessary to execute an immediate operation, we do not store it.

2. Zero-Retention Code Policy

We do not clone, index, store, or cache your source code. When a Pull Request is triggered, our worker nodes intercept the GitHub webhook. The system dynamically pulls exclusively the .diff files into volatile memory (RAM). Once analysis is complete and feedback has been posted back to GitHub, the memory buffer is instantly purged.

Your codebase never touches a persistent database on our infrastructure.

3. AI Training Exemption

Our Guarantee

Under no circumstances is your source code, architecture, or PR metadata used to train AI models.

PRInspector runs on AI models hosted entirely on our own infrastructure. Your code is never sent to OpenAI, Anthropic, or any other third-party AI provider, so no outside company can store it or use it for training. Your code remains yours.

4. Metadata Collection

To operate our dashboard and routing, we store aggregate metadata:

  • GitHub OAuth Credentials Used to generate access tokens required to post inline comments on PRs.
  • Repository Identifiers Repository names and IDs required for webhook routing.
  • Pull Request Metadata PR ID, author, timestamps, and state to populate analytics and history.
  • Billing Information Processed entirely via Stripe. We do not store credit card data on our servers.

5. Website Visitors, Sign-ups & Surveys

When you use our website — separately from the product — we collect the information below. We never sell it, and we don't share it with advertisers.

Early-access sign-ups (Get Started)

When you join the early-access list, we store:

  • Details you enter Your name and email address, and optionally your company, role, team size and what you'd like Diffnix to help with.
  • How you found us The referring website, the first page you visited, the page you signed up from, and any campaign (UTM) tags in the link.

We use this to contact you about early access, to prioritise which teams we onboard, and to understand which channels bring people to Diffnix.

Website survey

Our short website survey is anonymous and optional. It doesn't ask for your name or email and isn't linked to an early-access sign-up. We store:

  • Your answers Including partial answers, so you can pick up where you left off, and whether you completed or postponed the survey.

We use survey answers only in aggregate, to decide what to build.

Investor inquiries

If you contact us through our investors page, we store the contact details, firm information, investment profile and message you submit. We use them only to respond to and follow up on your inquiry.

Cookies and browser storage

  • Session storage Remembers the page and link that first brought you to our site during your visit, so a sign-up can be attributed correctly. It is cleared when you close the tab.
  • Analytics If we enable Google Analytics, it sets its own cookies to measure website traffic. We don't use advertising cookies.

Retention and your choices

We keep this information for as long as we need it for the purposes above, or until you ask us to delete it. You can ask to access, correct or delete your data at any time using the contact address below.

6. Third-Party Integrations

We do not use any third-party LLM APIs. All AI analysis is performed by models running on our own servers.

We use a limited set of third-party services only where needed to run the product:

  • GitHub To receive pull request events, read the changes under review, and post review comments, using only the permissions you grant our GitHub App.
  • Stripe To process payments. We never see or store your full card details.

All data exchanged with these services is encrypted in transit using TLS.

7. Government Requests

Because we operate zero-retention code pipelines, we physically cannot surrender your repository code to any authority. We can only provide aggregate metadata associated with your account if presented with a legally binding subpoena.

8. Policy Updates

We may update this Privacy Policy to reflect new features or compliance requirements. All active users will receive email notification prior to any substantive changes.

Contact Us

For privacy inquiries or GDPR/CCPA data deletion requests, contact: [email protected].