Legal

Terms & Conditions

Last updated:

The short version: Patchlight is an early-access AI code review tool. You keep all rights to your code, we never train on it, billing is prepaid through Paddle, unused top-ups are refundable under our Refund Policy, and AI findings are assistance — not a security audit. The details follow.

01Agreement to these terms

These Terms & Conditions (“Terms”) govern your access to and use of Patchlight — the website at patchlight.dev, the Patchlight GitHub App, and the related review and security-monitoring services (together, the “Service”). By installing the GitHub App, creating an account, or otherwise using the Service, you agree to be bound by these Terms. If you use the Service on behalf of an organization, you represent that you have authority to bind that organization, and “you” refers to it.

02The Service — early access

Patchlight is an AI-assisted code review and security monitoring tool. It analyzes pull requests, commits, and repositories you connect, and posts findings as comments, dashboards, and reports.

The Service is currently offered as an early-access product. Features may change, be interrupted, or be discontinued at any time, and output quality will evolve as the product matures. We will make reasonable efforts to communicate material changes, but we do not guarantee backwards compatibility of features, APIs, or pricing during early access.

03Accounts and GitHub access

You sign in with your GitHub account and grant the Patchlight GitHub App access to the repositories you select. You are responsible for maintaining the security of your GitHub account and for all activity that occurs under it. You may revoke the App's access at any time through GitHub; doing so stops new reviews but does not automatically delete data already processed (see “Your code and data” below).

04Billing and refunds

The Service is billed through a prepaid balance. New accounts receive a one-time free allowance. Reviews, scans, and other metered operations are charged in USD against that balance at the prices shown in the product before or at the time of the operation.

Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders. Paddle provides all customer service inquiries and handles returns.

Purchased funds are prepaid, non-transferable, and usable only within the Service. Refund eligibility for prepaid top-ups — including the 14-day money-back guarantee for unused balance — is set out in our Refund Policy at patchlight.dev/refund. We may change pricing prospectively; changes never apply retroactively to amounts already spent.

05Your code and data

You retain all rights to your code and repository content. You grant us a limited, non-exclusive license to access, transmit, and process that content solely to provide the Service — for example, sending diffs to an AI model provider to generate a review.

We do not use your code to train machine-learning models, and we do not permit our model providers to do so under the terms we have with them. You can request deletion of all stored content and derived data at any time from the product or by contacting us, and we will delete it within a commercially reasonable period, except where retention is required by law.

06AI-generated output

Review findings, severity ratings, suggested fixes, and security reports are generated in whole or in part by AI models. They can be incomplete, inaccurate, or wrong.

The Service is an assistant, not a substitute for human review, professional security audits, or your own testing. A clean Patchlight review is not a representation that code is free of defects or vulnerabilities, and you remain solely responsible for the code you merge, deploy, and ship.

07Acceptable use

You agree not to:

  • use the Service to analyze code you do not have the right to access or share;
  • publish, sell, or otherwise act on findings about code you do not maintain, other than through coordinated disclosure to the people who do — the project’s published security policy, or a private advisory;
  • attempt to probe, disable, overload, or circumvent the Service's security or usage limits;
  • resell or white-label the Service without our written consent;
  • use the Service to develop a competing product by systematically extracting its output;
  • use the Service in violation of applicable law, including export-control and sanctions rules.

08Third-party services

The Service depends on third parties, including GitHub and AI model providers (such as Google, Anthropic, and OpenAI). Their availability and terms affect the Service, and your use of GitHub remains governed by GitHub's own terms. We are not responsible for third-party outages or changes, though we will make reasonable efforts to work around them.

09Intellectual property

We retain all rights in the Service, including its software, design, and branding. These Terms grant you no rights in the Service other than the limited right to use it. Feedback you choose to send us may be used to improve the Service without obligation to you.

To the extent review comments or suggested fixes generated for your repositories are protectable, we assign to you any rights we hold in that output.

10Availability, suspension, and termination

We aim for high availability but provide no uptime guarantee during early access. We may suspend or terminate access that violates these Terms, creates risk for the Service or other users, or is required by law. You may stop using the Service at any time; unused free reviews lapse on termination, and purchased funds are handled per the billing section above.

11Disclaimer of warranties

The Service is provided “as is” and “as available”, without warranties of any kind, whether express, implied, or statutory, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement. Some jurisdictions do not allow the exclusion of certain warranties, so parts of this section may not apply to you.

12Limitation of liability

To the maximum extent permitted by law, we will not be liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, data, or goodwill — including damages arising from code that was merged or deployed after a Patchlight review. Our total aggregate liability for all claims relating to the Service is limited to the greater of the amount you paid us in the twelve months before the claim arose or USD 100. Nothing in these Terms excludes liability that cannot be excluded by law.

13Changes to these terms

We may update these Terms as the product evolves. For material changes we will give notice — for example, in the product or by email — before the changes take effect. Continuing to use the Service after the effective date constitutes acceptance of the updated Terms. The “Last updated” date above always reflects the current version.

14Reporting abuse

If you believe someone has used the Service against code they had no right to analyze, or has acted on findings outside coordinated disclosure, write to abuse@patchlight.dev. Tell us the repository and roughly when, and we will investigate.

We keep a record of every scan — which account ran it, against what, and when — and that record is what an investigation reads. We will suspend or terminate accounts that breach the acceptable-use section above. We do not disclose a user’s identity to a third party outside a valid legal process, so we cannot tell you who scanned your project, only that we have looked into it. What we can do about the account, we will.

How we handle these reports, and what we ask of everyone scanning code they do not maintain, is set out at patchlight.dev/security.

15Governing law and contact

These Terms are governed by the laws of the jurisdiction in which the Patchlight operating entity is established, without regard to conflict-of-law rules, and disputes belong to the courts of that jurisdiction unless mandatory local law provides otherwise.

Questions about these Terms: hello@patchlight.dev. Abuse reports: abuse@patchlight.dev.