Skip to content
Docs menu

How RepoReady handles your data

Where code and manuscripts go, how long they are kept, who can see reports, and how to delete them.

Last updated

RepoReady analyzes your repository and manuscript with static checks and AI review. This page summarizes the binding privacy policy and Terms of Service.

What is sent where

The privacy policy names each of these services.

StepServiceWhat it receives
Fetching codeGitHubThe snapshot you select, plus details such as the README, releases and recent Actions runs.
Fetching manuscriptsOverleafRead-only clones of the projects you add, with your Git token.
Storage and processingOur hosting provider in GermanyCode snapshots, uploads, manuscripts, reports and fix drafts.
AnalysisModel providers listed in our privacy policyThe files, excerpts and manuscript content the AI review reads.
Error monitoringOur error-monitoring serviceError reports. While AI tracing is on for debugging, traces can include code or manuscript excerpts.
Network and deliveryOur network providerAll requests to the website, web app, API and analysis engine.
Sign-inOur sign-in providerName, email address and sign-in data. No code.
Coding agentsYour agent and its providerWhat your agent uploads, and the report it receives.

API keys you add are stored encrypted.

How long data is kept

DataKept
Latest code snapshot and manuscript of each projectWhile the project exists
Older code snapshots and manuscriptsDeleted within 14 days, unless an open fix session still uses the manuscript
Repository details from GitHubDeleted within 3 days
Reports and findingsUntil you delete the project or your account
Fix draftsFiles up to 14 days; proposed changes cleared 7 days after a session ends
AI request records, only while debugging is onNormally deleted within 15 days
Security audit logs90 days
Email logs6 months
Web server logsTypically 14 days
Copies at model providers, error monitoring and network providerTheir own rules apply

Model training

RepoReady does not train its own models on your content (Terms of Service § 9(3)). The model providers’ training rules apply:

  • Free analyses and organization plans run on RepoReady’s account, with the training opt-out switched on wherever the provider supports it.
  • With your own API key, or your organization’s, that key’s account settings decide which providers receive requests.

Who can see reports

Projects and reports belong to your account; organization members do not see them. Others see a report only when you:

  • Create a share link. Anyone with the link can open the report until you delete the project.
  • Publish a badge. Anyone with the badge link can view the pinned analysis, including its manuscript findings, until you re-pin or delete the badge.
  • Open a pull request. Everyone who can see the repository on GitHub can see it.

Shared report and badge pages ask search engines not to index them. Anyone with a link can pass it on.

GitHub App permissions

  • Public repositories need no installation; RepoReady reads them through the GitHub API.
  • Private repositories need the RepoReady GitHub App. You grant it all or selected repositories, and GitHub shows the exact permissions.
  • Read access fetches the snapshot you choose and the repository details.
  • Write access is used only when you ask for a pull request, for accepted fixes or the badge. RepoReady commits to a new branch; merging is up to you.
  • Administration access lets RepoReady open a pull request on a public repository it cannot write to, by forking it into an account with the App first.
  • Change or remove its access at any time in your GitHub settings; deleting your RepoReady account uninstalls it.

Deleting your data

  • Delete a project to remove its code snapshots, repository details, manuscripts, fix drafts, reports and share links; delete a published badge first. Cached manuscript text and figures follow within 14 days, unless another of your projects uses the same manuscript.
  • Delete your account in the settings to remove all projects, uploads, API keys, Overleaf tokens, memberships, email preferences and your sign-in account. Security audit log entries are kept, anonymized.
  • Content leaves active systems within 30 days of account deletion; backups are overwritten in the regular rotation.
  • Copies outside RepoReady remain: requests already processed by model providers, error reports, and forks, branches or pull requests on GitHub.

Before you upload

  • Do not upload special categories of personal data, such as patient data that is not pseudonymized (Terms of Service § 5(2)).
  • Rotate committed secrets: RepoReady flags them, and the AI review may read files that contain them.

Contact

Questions about your data: [email protected].

Suspected unauthorized access to your account: [email protected].