Skip to content

Privacy Policy

Last updated

Translation for convenience; the German version is binding.

On this page

1. Controller and data protection officer

RepoReady is operated by Helmholtz Zentrum München (Helmholtz Munich; see the imprint). The controller within the meaning of the GDPR and other applicable national data-protection laws is:

Helmholtz Zentrum München
Deutsches Forschungszentrum für Gesundheit und Umwelt (GmbH)

Ingolstädter Landstraße 1
85764 Neuherberg, Germany
Website: www.helmholtz-munich.de
Email for data-protection requests about RepoReady: [email protected]

The data protection officer of Helmholtz Zentrum München can be reached at:

Data protection officer, Helmholtz Zentrum München
Ingolstädter Landstr. 1
85764 Neuherberg
Germany
Email: [email protected]

You can send data-protection requests at any time to [email protected] or directly to the data protection officer.

2. Scope

This policy covers the marketing site repoready.ai as well as the authenticated web application (the "Service"), which we provide to researchers, labs, research institutions, and journals.

  • The marketing site uses no cookies, no tracking, and no analytics — see Section 7.
  • In the web app we use only strictly necessary cookies and browser storage entries. We use Sentry for error and performance monitoring without session replay (Section 3.7). Details on cookies in Section 7 and our Cookie Policy.

3. Data we process, purposes, and legal bases

3.1 Marketing-site visits

When you visit repoready.ai, our hosting provider Nodion GmbH (see Section 4) automatically processes server logs:

  • IP address (truncated where technically possible)
  • Date and time of the request
  • Requested URL, HTTP status code
  • Referrer URL, user-agent (browser/OS)

Purpose: providing the website, stability, defending against attacks.
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in security and operability).
Retention (server logs at the hosting provider): typically 14 days; longer if a security incident is being investigated.

Requests to repoready.ai, the web app, the API and the analysis engine are also routed through the network of Cloudflare, Inc. (see Section 4), which acts as content delivery network and reverse proxy and protects against attacks and automated access (bots). In doing so, Cloudflare processes in particular the IP address, the requested URL, the user-agent and the time of the request. Purpose and legal basis as above (Art. 6 (1)(f) GDPR).

3.2 Registration & sign-in

Using the Service requires an account. Authentication is handled by our identity provider WorkOS, Inc. (see Section 4). We process:

  • Name, email address
  • Encrypted authentication tokens
  • Where applicable, organization membership (for lab / institution accounts)

Purpose: contract performance, account management, organization invitations.
Legal basis: Art. 6 (1)(b) GDPR (contract).
Retention: until account deletion plus any applicable statutory retention periods (§§ 147 AO, 257 HGB).

3.3 Repository and manuscript data

When you connect GitHub repositories or Overleaf manuscripts, we access — under your OAuth authorization — metadata and contents of the explicitly authorized repositories and projects. These contents may include personal data within the git history (e.g. commit author, email) — please bear that in mind.

Purpose: running the reproducibility and manuscript analysis.
Legal basis: Art. 6 (1)(b) GDPR.
Retention: while a project is actively used, we keep the most recent analyzed version of the repository / manuscript so that reevaluations can run without a fresh download. Earlier versions are removed from the cache within 14 days at the latest, unless an open AI fix session still uses the manuscript. Analysis results / reports are kept until you delete your project; deleting the project also removes the most recently cached repository / manuscript files.

3.4 Use of LLM services

For the AI analysis, selected repository excerpts and manuscript content are transmitted to OpenRouter Inc., which forwards the requests to the model providers we use. These are currently OpenAI, Anthropic and Google; which provider handles an individual request depends on the chosen effort level and the sub-task. You can optionally configure your own OpenRouter API key ("BYOK"); in that case the individual settings of your OpenRouter account apply (e.g. zero-data-retention options).

Purpose: automated analysis and suggestions.
Legal basis: Art. 6 (1)(b) GDPR.
Note on Art. 22 GDPR: the LLM-generated assessments do not produce legal effects; the decision to accept or reject suggestions rests entirely with you.

3.5 Service usage & audit logs

For security, abuse prevention, and quota management we keep audit logs:

  • User ID, IP address, user-agent
  • Action (e.g. webhook verification, rate limit, trial block)
  • Timestamp, severity

Purpose: security, fraud prevention, compliance with legal obligations.
Legal basis: Art. 6 (1)(f) GDPR + (1)(c) GDPR.
Retention: 90 days; longer for ongoing security incidents.

3.6 Transactional emails

We send transactional emails (sign-in, analysis, trial). Each email type can be disabled individually in your settings at any time.

Purpose: communication, service functionality.
Legal basis: Art. 6 (1)(b) GDPR (transactional).
Email-log retention: 6 months.

3.7 Error and performance monitoring (Sentry)

We use Sentry (Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA, with EU contracting party Functional Software B.V., Amsterdam, Netherlands; EU data location ingest.de.sentry.io, Frankfurt am Main) to diagnose technical errors and monitor performance in the web app, the API and the analysis engine. Transmitted data includes error stack traces, browser and OS information, an event ID generated by the SDK, and technical identifiers (e.g. the ID of an analysis run). There is no session recording in production; the SDK sets no cookies and does not use local / session storage for tracking purposes.

AI tracing in the analysis engine: if AI tracing is enabled, the analysis engine's performance traces may additionally contain truncated content of requests to language models (system and user prompts), outputs of the tools used in the process (e.g. excerpts of files that were read) and the models' responses. This content can include excerpts of your code and your manuscript. The purpose is debugging and monitoring the quality, run time and token usage of the analysis.

Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in stability, security, and bug fixing). You can object to this processing at any time under Art. 21 GDPR.

4. Recipients of your data

We share data only with the following processors (Art. 28 GDPR) or independent controllers, with whom corresponding agreements are in place:

RecipientPurposeLocation / data residencyTransfer safeguards
WorkOS, Inc.Authentication, identity, organization managementUSAEU Standard Contractual Clauses (SCCs) pursuant to Art. 46 (2)(c) GDPR, embedded in the WorkOS DPA
Functional Software, Inc. (d/b/a Sentry) / Functional Software B.V.Error and performance monitoring (web app, API, analysis engine; see Section 3.7)USA / Netherlands; data residency Frankfurt (EU)EU-US Data Privacy Framework (DPF) + Standard Contractual Clauses (SCCs) as DPA fallback
Cloudflare, Inc.Content delivery network and reverse proxy for repoready.ai, the web app, the API and the analysis engine; protection against attacks and botsUSA; global server networkEU-US Data Privacy Framework (DPF) + Standard Contractual Clauses (SCCs) as fallback
Nodion GmbHServer hosting, database, S3 storage for reports / artifacts, email deliveryGermany (EU)EU — no third-country transfer
OpenRouter Inc. (model providers: OpenAI, Anthropic, Google)LLM inference for AI analysis (see Section 3.4)USAArt. 46 GDPR (SCCs); with BYOK, the individual settings of your OpenRouter account additionally apply
GitHub, Inc. (Microsoft)Repository connectivity via OAuth/App, webhooksUSAEU-US DPF / SCCs
Digital Science UK Limited (Overleaf)Manuscript connectivityUKUK adequacy decision of the EU Commission

A list of the specific contractual documents (DPAs / SCCs) is available on request at [email protected].

5. International transfers

Where data is transferred to recipients outside the EEA, we ensure the level of protection required by Art. 13 (1)(f) GDPR through:

  • EU Standard Contractual Clauses (SCCs, Art. 46 (2) GDPR),
  • The EU-US Data Privacy Framework where the recipient is certified,
  • The UK adequacy decision of the EU Commission.

A copy of the safeguards in place is available on request. Following the Schrems II judgement (CJEU C-311/18) we continually review the level of protection in the recipient country (transfer impact assessment).

6. Retention / deletion

We store personal data only as long as necessary for the respective purposes or required by statutory retention periods (§§ 147 AO, 257 HGB). You can delete your account and the associated content at any time in the settings. All content is removed from active systems within 30 days of account deletion at the latest; remaining backups are overwritten in the regular rotation cycle.

7. Cookies and similar technologies

Marketing site (repoready.ai): we use no cookies and no local / session storage for tracking purposes.

Web app (production): we use only strictly necessary cookies and browser storage entries: the session cookie wos-session (HttpOnly, encrypted and signed) for authentication, short-lived cookies that protect sign-in (wos-auth-verifier-…), connecting the RepoReady GitHub App (gh_app_state) and organisation invitations (rr_invite_conflict_org), a local storage entry for the sort order you chose for the project list (projects:sortChoice) and a session storage entry that prevents repeated reloads after a web app update (rr-chunk-reload) — legal basis § 25 (2)(2) TDDDG; no consent required. There is no tracking, analytics, or session recording.

Detailed description of the cookies in use, providers, and retention periods: see our Cookie Policy.

8. Your rights

You have the right to:

Please send requests to [email protected] or to the data protection officer (Section 1).

9. Duty to provide data

Providing the data required for performing the contract (email, name) is necessary to use the Service. Without these data, registration is not possible. Any further provision of data is voluntary.

10. Automated decision-making / profiling

No solely automated decision producing legal effects within the meaning of Art. 22 GDPR is taken. AI-supported assessments of your repository are advisory in nature; you decide freely whether and which suggestions to accept.

11. Changes to this notice

We update this privacy notice when our processing changes. For material changes we will inform you by email or in the Service.