Legal
Privacy Policy
Last updated:
The short version: your code is read to review it and stored nowhere afterwards. We never train on it. What we keep is the finding — a file, a line, an explanation, and the few lines a suggested fix rewrites. Everything below is the detail behind those sentences.
01Who we are and what this covers
This policy explains how Patchlight handles personal data across the website at patchlight.dev, the Patchlight web app, the Patchlight GitHub App, the CLI and SDK, and the review and security-monitoring services behind them (together, the “Service”).
For the processing described here, the Patchlight operating entity is the data controller. Where you use Patchlight to review your organization's repositories, you are the controller of the repository content and personal data inside it, and we act as your processor on your instructions — the instruction being your configuration of the Service. Our Terms & Conditions govern the commercial relationship; this policy governs the data.
Questions, requests, or complaints: privacy@patchlight.dev.
02What we collect
We collect only what the Service needs to run, and most of it arrives because you connected GitHub or paid for something.
- Account data — your GitHub user id, login, display name, avatar URL, and the email address GitHub releases to us at sign-in. We never receive your GitHub password, and we never ask for one.
- Installation data — the repositories you select when installing the GitHub App, their names, default branches, visibility, and the installation token scope you granted.
- Repository content, in transit — the diffs, file contents, and commit metadata of the pull requests, commits, and trees you ask us to review or scan. We process this to produce a review and we do not retain it; section 04 is the detail.
- Review output — the findings we generate: severity, category, file path, line, title, explanation, and any suggested fix. A suggested fix quotes the few lines it changes, so a small fragment of your code is stored as part of the finding it belongs to.
- Usage and billing data — token counts, cost per operation, prepaid balance, ledger entries, spend caps, and the record of which account ran which review or scan and when. That last record is also what an abuse investigation reads (see Responsible use).
- Support and feedback — anything you send us by email, through the in-app feedback widget (including a screenshot, if you attach one), or in the in-app assistant.
- Product analytics — which screens of the signed-in app are opened and which flows fail, so we can fix the ones that do. Collected through an EU-hosted analytics service, tied to your account id, and never pointed at your repository content.
- Website data — see section 09. The marketing site sets no analytics or marketing cookies without your consent.
03Why we process it, and on what legal basis
Under the GDPR we rely on the following bases:
- Performance of a contract (Art. 6(1)(b)) — running reviews and scans, maintaining your account, metering usage, and taking payment. Without this processing there is no Service.
- Legitimate interests (Art. 6(1)(f)) — keeping the Service secure and available, debugging failed reviews, preventing abuse of the scanner, and improving product quality in aggregate. We have weighed these against your interests; where the balance was close, we chose the narrower option.
- Legal obligation (Art. 6(1)(c)) — tax and accounting records for payments, and responses to valid legal process.
- Consent (Art. 6(1)(a)) — optional cookies on the marketing site, and product or marketing email you opt into. You can withdraw consent at any time, and withdrawing it is as easy as giving it.
04Your code: what happens to it
This is the section most people came here for, so it is the specific one.
When a review runs, we fetch the diff — and, for a scan, the files the scanner selected — using the access you granted, and pass it to a third-party AI provider (for example OpenAI, Anthropic, or Google) for analysis. The answer comes back, we turn it into findings, and we post them to your pull request and dashboard. That round trip is the entire life of your code inside the Service.
We do not store your code. There is no Patchlight-side copy of your repository, no index of it, and no archive of the diffs we have reviewed. Repository content is held in memory for the length of the operation and released when it ends. Scans clone onto isolated compute that is destroyed with the job. Reviews triggered through the SDK or CI hand us a payload that is deleted the moment the worker has consumed it.
The exception is the finding itself, and it is a narrow one. To show you a result we keep the file path, the line number, the severity, and our explanation — plus, when the finding comes with a fix, the few lines of code that fix rewrites. That fragment is stored because it is the suggestion; there is no way to show you a patch without keeping the patch.
We run our AI providers under zero-data-retention terms: prompts and completions are not persisted on their side, and are not used to train, fine-tune, or evaluate any model. We do not train models on your code ourselves, and we do not sell, license, or share it with anyone outside the processors described in section 05.
You can ask us to delete everything associated with your account at any time. Revoking the GitHub App's access stops new reviews immediately; ask us and we will remove the account and its findings as well.
05Processors and subprocessors
We rely on a small number of processors, each bound by a data-processing agreement and each used for the purpose named and nothing else:
- GitHub — the source of your code and identity, and where review comments are posted. Your use of GitHub stays governed by GitHub's own terms and privacy statement.
- Third-party AI providers (for example OpenAI, Anthropic, or Google) — the models that analyse a diff and return findings, under zero-data-retention and no-training terms.
- Cloud infrastructure providers — hosting, the application database, queues, transactional email, and the isolated compute that runs a scheduled scan.
- Our payments provider, acting as merchant of record — it collects and processes your payment details directly; we never see or store a card number.
- Product analytics and error reporting, hosted in the European Union — which screens of the signed-in app are used and which flows crash. Never pointed at your code.
- Our consent management platform — the cookie banner on the marketing site and the record of what you chose.
We name categories rather than vendors here on purpose: which provider serves which workload changes as the product evolves, and publishing a live map of our infrastructure helps an attacker more than it helps a reader. Customers who need the current named list — for a vendor review, a DPA annex, or a security questionnaire — get it by writing to us, and we will tell you before a change to it affects your data.
06International transfers
Patchlight is operated from the European Union, and the systems that hold your account, your findings, and our analytics are configured to keep that data in the EU. Some of the processors above are established outside the EEA, including in the United States.
Where personal data leaves the EEA we rely on the European Commission's Standard Contractual Clauses, on an adequacy decision where one covers the recipient, and on the transfer terms of each processor's data-processing agreement. Because we do not retain your code, the data crossing a border is your account and finding records rather than your repository.
If your organization needs processing confined to particular jurisdictions — a common requirement in regulated industries — write to us before you connect a repository. We would rather scope it correctly at the start than have you discover a constraint later.
07How long we keep things
Retention is tied to what the data is for:
- Repository content — not retained. It lives for the length of the review or scan and is gone when the operation ends.
- Account, repository, review, and finding records — for as long as your account is open, and deleted on request or within 30 days of account closure.
- Uploaded review payloads (SDK/CI) — deleted as soon as the review worker has consumed them.
- Scan checkouts — destroyed with the compute instance when the scan job ends; nothing survives the run.
- Billing and tax records — retained for the period required by law, typically seven years, and not deleted on request during that period.
- Notifications, feedback, and support email — swept on a retention schedule or deleted on request.
- Consent records — kept as long as needed to prove the consent was given, and refreshed when you change your choices.
08Your rights
If the GDPR applies to you, you have the right to access your data, to correct it, to have it erased, to restrict or object to processing, to receive it in a portable format, and to withdraw consent where consent is the basis. Where you are a customer's team member rather than the customer, we will route your request to that customer, since they are the controller of their repository content.
Write to privacy@patchlight.dev. We will answer within one month, and tell you promptly if a request is one we need to extend or cannot fulfil. Identity verification for these requests is done through the GitHub account the data belongs to — it is the strongest signal we have, and it does not require you to send us more personal data.
You also have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to fix it first, but that right is yours regardless.
09The website, cookies, and tracking
The marketing site sets only what is strictly necessary until you say otherwise. Measurement and marketing categories are off by default, are gated behind the consent banner, and can be changed at any time through the “Cookie preferences” link in the footer. Declining costs you nothing: no feature of the site or the Service depends on it.
The signed-in web app uses a session cookie, which is strictly necessary — it is what keeps you logged in — and cannot be declined while you are using the app. It also carries the product analytics described in section 02, hosted in the EU and scoped to how the app itself is used. We run no advertising networks and no cross-site trackers on any of our properties.
We do not sell personal data, and we do not engage in “sharing” for cross-context behavioural advertising as those terms are used in US state privacy laws.
10Automated decision-making
Review findings, severity ratings, and suggested fixes are generated by AI models. They are advisory: nothing Patchlight produces blocks a merge, a hire, a payment, or any other decision with a legal or similarly significant effect on a person. No decision within the meaning of Art. 22 GDPR is made about you by the Service.
11Security
Access to production data is limited to the people who need it and is authenticated through individual accounts. Secrets are held in the platform's secret store, never in the repository. API keys are stored as hashes, expire, and can be rotated in place. Data is encrypted in transit and at rest by the underlying platforms.
The Service is an early-access product and we describe our security posture as what it is rather than as a certification we do not hold. If you found a vulnerability in Patchlight itself, tell us privately first — the reporting path is on our Responsible use page.
12Children
The Service is for professional use and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to us and we will delete it.
13Changes to this policy
We will update this policy as the Service changes. For material changes — a new category of data, a new purpose, a new processor handling your code — we will give notice in the product or by email before they take effect. The “Last updated” date above always reflects the current version.
Contact
Privacy requests and questions: privacy@patchlight.dev. Commercial terms are in our Terms & Conditions, and what stops the scanner being pointed at code it has no business reading is on Responsible use.
This page describes the Service as it stands today. If something here stops being true, this page changes with it.