Docs menu
How RepoReady handles your data
Where code and manuscripts go, how long they are kept, who can see reports, and how to delete them.
Last updated
RepoReady analyzes your repository and manuscript with static checks and AI review. This page summarizes the binding privacy policy and Terms of Service.
Shared only when you choose
- Share link
- Badge
- Pull request
Shared only when you choose
- Share link
- Badge
- Pull request
What is sent where
The privacy policy names each of these services.
| Step | Service | What it receives |
|---|---|---|
| Fetching code | GitHub | The snapshot you select, plus details such as the README, releases and recent Actions runs. |
| Fetching manuscripts | Overleaf | Read-only clones of the projects you add, with your Git token. |
| Storage and processing | Our hosting provider in Germany | Code snapshots, uploads, manuscripts, reports and fix drafts. |
| Analysis | Model providers listed in our privacy policy | The files, excerpts and manuscript content the AI review reads. |
| Error monitoring | Our error-monitoring service | Error reports. While AI tracing is on for debugging, traces can include code or manuscript excerpts. |
| Network and delivery | Our network provider | All requests to the website, web app, API and analysis engine. |
| Sign-in | Our sign-in provider | Name, email address and sign-in data. No code. |
| Coding agents | Your agent and its provider | What your agent uploads, and the report it receives. |
API keys you add are stored encrypted.
How long data is kept
| Data | Kept |
|---|---|
| Latest code snapshot and manuscript of each project | While the project exists |
| Older code snapshots and manuscripts | Deleted within 14 days, unless an open fix session still uses the manuscript |
| Repository details from GitHub | Deleted within 3 days |
| Reports and findings | Until you delete the project or your account |
| Fix drafts | Files up to 14 days; proposed changes cleared 7 days after a session ends |
| AI request records, only while debugging is on | Normally deleted within 15 days |
| Security audit logs | 90 days |
| Email logs | 6 months |
| Web server logs | Typically 14 days |
| Copies at model providers, error monitoring and network provider | Their own rules apply |
Model training
RepoReady does not train its own models on your content (Terms of Service § 9(3)). The model providers’ training rules apply:
- Free analyses and organization plans run on RepoReady’s account, with the training opt-out switched on wherever the provider supports it.
- With your own API key, or your organization’s, that key’s account settings decide which providers receive requests.
Who can see reports
Projects and reports belong to your account; organization members do not see them. Others see a report only when you:
- Create a share link. Anyone with the link can open the report until you delete the project.
- Publish a badge. Anyone with the badge link can view the pinned analysis, including its manuscript findings, until you re-pin or delete the badge.
- Open a pull request. Everyone who can see the repository on GitHub can see it.
Shared report and badge pages ask search engines not to index them. Anyone with a link can pass it on.
GitHub App permissions
- Public repositories need no installation; RepoReady reads them through the GitHub API.
- Private repositories need the RepoReady GitHub App. You grant it all or selected repositories, and GitHub shows the exact permissions.
- Read access fetches the snapshot you choose and the repository details.
- Write access is used only when you ask for a pull request, for accepted fixes or the badge. RepoReady commits to a new branch; merging is up to you.
- Administration access lets RepoReady open a pull request on a public repository it cannot write to, by forking it into an account with the App first.
- Change or remove its access at any time in your GitHub settings; deleting your RepoReady account uninstalls it.
Deleting your data
- Delete a project to remove its code snapshots, repository details, manuscripts, fix drafts, reports and share links; delete a published badge first. Cached manuscript text and figures follow within 14 days, unless another of your projects uses the same manuscript.
- Delete your account in the settings to remove all projects, uploads, API keys, Overleaf tokens, memberships, email preferences and your sign-in account. Security audit log entries are kept, anonymized.
- Content leaves active systems within 30 days of account deletion; backups are overwritten in the regular rotation.
- Copies outside RepoReady remain: requests already processed by model providers, error reports, and forks, branches or pull requests on GitHub.
Before you upload
- Do not upload special categories of personal data, such as patient data that is not pseudonymized (Terms of Service § 5(2)).
- Rotate committed secrets: RepoReady flags them, and the AI review may read files that contain them.
Contact
Questions about your data: [email protected].
Suspected unauthorized access to your account: [email protected].