Privacy Policy
What we collect when Autometric reviews your code, why we hold it, how long it stays, and what you can make us do with it. Your source code is not training data and never will be.
Scope
This policy explains what Autometric collects, why, how long we keep it, and what you can ask us to do about it. It covers the platform, the console, our APIs, integrations and this website.
Where we process source code and review records on behalf of a customer, that customer is the controller and we are the processor, acting on their documented instructions under a data processing agreement. Where we process account and website data for our own purposes, we are the controller.
What we collect
We collect the minimum needed to run review and to prove that review happened.
| category | what it includes | retention |
|---|---|---|
| Source code | File contents fetched at review time, the diffs computed from them, and pull request titles and descriptions | transient · 24h cache |
| Review records | Findings, severities, gate decisions, rule overrides, and the hash-chained gate record | 7 years or your term |
| Commit metadata | For commits on the pull requests we review: the commit hash and authored date, the author name, email address and account login, and the repository, team and pull request it belongs to | 7 years or your term |
| Account data | Names, work emails, roles, SSO identifiers, invitation state | life of account + 90d |
| Usage and billing | Credit consumption per repository, model profile, invoices and payment records | 7 years (tax law) |
| Website data | Page views, referrer, coarse location and demo-request form submissions | 14 months |
How we handle your source code
Source code is fetched at review time, held in a per-tenant encrypted cache for at most 24 hours, and then discarded. What persists afterwards is the review record: findings, line references and hashes — not the code itself.
We do not train models on your code. We do not use your code or findings to improve detection for other customers. Aggregate operational metrics we do use are computed so that no customer, repository, or individual is identifiable.
Why we process it
We process data to deliver the service you asked for (contract), to keep the platform secure and metered correctly (legitimate interests), to comply with tax and accounting obligations (legal obligation), and — for marketing email only — where you have opted in (consent). You can withdraw consent at any time without affecting the service.
Model providers and subprocessors
Running a review means sending code fragments to the model providers configured in your model profile. Those providers act as subprocessors, are bound by contract to zero-retention terms, and do not train on the content we send them.
You control which providers are in play by choosing a model profile at the organisation level or per repository. Customers on self-hosted or air-gapped deployments send nothing to third-party providers.
- › Model providers: as configured by your model profile, under zero-retention agreements.
- › Cloud infrastructure: AWS, in the region you select at onboarding (us-east-1, eu-central-1, or ap-southeast-2).
- › Operational tooling: error monitoring, transactional email, and billing — each scoped to the minimum data required.
- › The current subprocessor list is available on request; we give 30 days notice before adding one, and you may object.
International transfers
Your tenant data is stored in the region you choose and does not leave it for storage. Where support or a subprocessor requires a transfer out of the EEA or UK, we rely on standard contractual clauses with the UK addendum, plus supplementary technical measures including encryption in transit and at rest and per-tenant key separation.
Security
Encryption in transit (TLS 1.3) and at rest (AES-256), per-tenant key separation, SSO with enforced 2FA, SCIM deprovisioning, least-privilege internal access with every access logged, annual penetration testing, and SOC 2 Type II and ISO 27001 audits. The ledger itself is append-only and hash-chained, so review history cannot be rewritten — including by us.
We notify affected customers of a personal data breach without undue delay and within 72 hours of becoming aware, with what we know at the time and what we are doing about it.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing, and to receive your data in a portable format. Where we act as a processor, direct the request to the customer who controls the data and we will support them in answering it.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used under California law. We do not use your data for automated decision-making that produces legal effects about individuals.
Retention and deletion
Retention periods are listed in section 02. Review records, and the commit metadata attached to them, are kept for the length of your term or seven years, whichever is longer, because their value is evidentiary — an audit two years from now needs the record of a gate decision made today, and of which commits it covered. We keep no commit metadata for commits on pull requests we did not review.
On termination we keep your ledger readable in export-only mode for 30 days, then delete tenant data within 90 days, except records we are legally required to retain (invoices, tax records) and backups, which age out on a 35-day cycle.
Changes to this policy
We update this policy as the product and the law change. Material changes are announced in the console and by email to account owners at least 30 days before they take effect, and the version number at the top of this page increments. Previous versions are available on request.