- Home
- Privacy Policy
Privacy Policy
Last updated
Translation for convenience; the German version is binding.
On this page
- 1. Controller and data protection officer
- 2. Scope
- 3. Data we process, purposes, and legal bases
- 4. Recipients of your data
- 5. International transfers
- 6. Retention / deletion
- 7. Cookies and similar technologies
- 8. Your rights
- 9. Duty to provide data
- 10. Automated decision-making / profiling
- 11. Changes to this notice
1. Controller and data protection officer
RepoReady is operated by Helmholtz Zentrum München (Helmholtz Munich; see the imprint). The controller within the meaning of the GDPR and other applicable national data-protection laws is:
Helmholtz Zentrum München
Deutsches Forschungszentrum für Gesundheit und Umwelt (GmbH)
Ingolstädter Landstraße 1
85764 Neuherberg, Germany
Website: www.helmholtz-munich.de
Email for data-protection requests about RepoReady: [email protected]
The data protection officer of Helmholtz Zentrum München can be reached at:
Data protection officer, Helmholtz Zentrum München
Ingolstädter Landstr. 1
85764 Neuherberg
Germany
Email: [email protected]
You can send data-protection requests at any time to [email protected] or directly to the data protection officer.
2. Scope
This policy covers the marketing site repoready.ai as well as the authenticated web application (the "Service"), which we provide to researchers, labs, research institutions, and journals.
- The marketing site uses no cookies, no tracking, and no analytics — see Section 7.
- In the web app we use only strictly necessary cookies and browser storage entries. We use Sentry for error and performance monitoring without session replay (Section 3.7). Details on cookies in Section 7 and our Cookie Policy.
3. Data we process, purposes, and legal bases
3.1 Marketing-site visits
When you visit repoready.ai, our hosting provider Nodion GmbH (see Section 4) automatically processes server logs:
- IP address (truncated where technically possible)
- Date and time of the request
- Requested URL, HTTP status code
- Referrer URL, user-agent (browser/OS)
Purpose: providing the website, stability, defending against attacks.
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in security and operability).
Retention (server logs at the hosting provider): typically 14 days; longer if a security incident is being investigated.
Requests to repoready.ai, the web app, the API and the analysis engine are also routed through the network of Cloudflare, Inc. (see Section 4), which acts as content delivery network and reverse proxy and protects against attacks and automated access (bots). In doing so, Cloudflare processes in particular the IP address, the requested URL, the user-agent and the time of the request. Purpose and legal basis as above (Art. 6 (1)(f) GDPR).
3.2 Registration & sign-in
Using the Service requires an account. Authentication is handled by our identity provider WorkOS, Inc. (see Section 4). We process:
- Name, email address
- Encrypted authentication tokens
- Where applicable, organization membership (for lab / institution accounts)
Purpose: contract performance, account management, organization invitations.
Legal basis: Art. 6 (1)(b) GDPR (contract).
Retention: until account deletion plus any applicable statutory retention periods (§§ 147 AO, 257 HGB).
3.3 Repository and manuscript data
When you connect GitHub repositories or Overleaf manuscripts, we access — under your OAuth authorization — metadata and contents of the explicitly authorized repositories and projects. These contents may include personal data within the git history (e.g. commit author, email) — please bear that in mind.
Purpose: running the reproducibility and manuscript analysis.
Legal basis: Art. 6 (1)(b) GDPR.
Retention: while a project is actively used, we keep the most recent analyzed version of the repository / manuscript so that reevaluations can run without a fresh download. Earlier versions are removed from the cache within 14 days at the latest, unless an open AI fix session still uses the manuscript. Analysis results / reports are kept until you delete your project; deleting the project also removes the most recently cached repository / manuscript files.
3.4 Use of LLM services
For the AI analysis, selected repository excerpts and manuscript content are transmitted to OpenRouter Inc., which forwards the requests to the model providers we use. These are currently OpenAI, Anthropic and Google; which provider handles an individual request depends on the chosen effort level and the sub-task. You can optionally configure your own OpenRouter API key ("BYOK"); in that case the individual settings of your OpenRouter account apply (e.g. zero-data-retention options).
Purpose: automated analysis and suggestions.
Legal basis: Art. 6 (1)(b) GDPR.
Note on Art. 22 GDPR: the LLM-generated assessments do not produce legal effects; the decision to accept or reject suggestions rests entirely with you.
3.5 Service usage & audit logs
For security, abuse prevention, and quota management we keep audit logs:
- User ID, IP address, user-agent
- Action (e.g. webhook verification, rate limit, trial block)
- Timestamp, severity
Purpose: security, fraud prevention, compliance with legal obligations.
Legal basis: Art. 6 (1)(f) GDPR + (1)(c) GDPR.
Retention: 90 days; longer for ongoing security incidents.
3.6 Transactional emails
We send transactional emails (sign-in, analysis, trial). Each email type can be disabled individually in your settings at any time.
Purpose: communication, service functionality.
Legal basis: Art. 6 (1)(b) GDPR (transactional).
Email-log retention: 6 months.
3.7 Error and performance monitoring (Sentry)
We use Sentry (Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA, with EU contracting party Functional Software B.V., Amsterdam, Netherlands; EU data location ingest.de.sentry.io, Frankfurt am Main) to diagnose technical errors and monitor performance in the web app, the API and the analysis engine. Transmitted data includes error stack traces, browser and OS information, an event ID generated by the SDK, and technical identifiers (e.g. the ID of an analysis run). There is no session recording in production; the SDK sets no cookies and does not use local / session storage for tracking purposes.
AI tracing in the analysis engine: if AI tracing is enabled, the analysis engine's performance traces may additionally contain truncated content of requests to language models (system and user prompts), outputs of the tools used in the process (e.g. excerpts of files that were read) and the models' responses. This content can include excerpts of your code and your manuscript. The purpose is debugging and monitoring the quality, run time and token usage of the analysis.
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in stability, security, and bug fixing). You can object to this processing at any time under Art. 21 GDPR.
4. Recipients of your data
We share data only with the following processors (Art. 28 GDPR) or independent controllers, with whom corresponding agreements are in place:
| Recipient | Purpose | Location / data residency | Transfer safeguards |
|---|---|---|---|
| WorkOS, Inc. | Authentication, identity, organization management | USA | EU Standard Contractual Clauses (SCCs) pursuant to Art. 46 (2)(c) GDPR, embedded in the WorkOS DPA |
| Functional Software, Inc. (d/b/a Sentry) / Functional Software B.V. | Error and performance monitoring (web app, API, analysis engine; see Section 3.7) | USA / Netherlands; data residency Frankfurt (EU) | EU-US Data Privacy Framework (DPF) + Standard Contractual Clauses (SCCs) as DPA fallback |
| Cloudflare, Inc. | Content delivery network and reverse proxy for repoready.ai, the web app, the API and the analysis engine; protection against attacks and bots | USA; global server network | EU-US Data Privacy Framework (DPF) + Standard Contractual Clauses (SCCs) as fallback |
| Nodion GmbH | Server hosting, database, S3 storage for reports / artifacts, email delivery | Germany (EU) | EU — no third-country transfer |
| OpenRouter Inc. (model providers: OpenAI, Anthropic, Google) | LLM inference for AI analysis (see Section 3.4) | USA | Art. 46 GDPR (SCCs); with BYOK, the individual settings of your OpenRouter account additionally apply |
| GitHub, Inc. (Microsoft) | Repository connectivity via OAuth/App, webhooks | USA | EU-US DPF / SCCs |
| Digital Science UK Limited (Overleaf) | Manuscript connectivity | UK | UK adequacy decision of the EU Commission |
A list of the specific contractual documents (DPAs / SCCs) is available on request at [email protected].
5. International transfers
Where data is transferred to recipients outside the EEA, we ensure the level of protection required by Art. 13 (1)(f) GDPR through:
- EU Standard Contractual Clauses (SCCs, Art. 46 (2) GDPR),
- The EU-US Data Privacy Framework where the recipient is certified,
- The UK adequacy decision of the EU Commission.
A copy of the safeguards in place is available on request. Following the Schrems II judgement (CJEU C-311/18) we continually review the level of protection in the recipient country (transfer impact assessment).
6. Retention / deletion
We store personal data only as long as necessary for the respective purposes or required by statutory retention periods (§§ 147 AO, 257 HGB). You can delete your account and the associated content at any time in the settings. All content is removed from active systems within 30 days of account deletion at the latest; remaining backups are overwritten in the regular rotation cycle.
7. Cookies and similar technologies
Marketing site (repoready.ai): we use no cookies and no local / session storage for tracking purposes.
Web app (production): we use only strictly necessary cookies and browser storage entries: the session cookie wos-session (HttpOnly, encrypted and signed) for authentication, short-lived cookies that protect sign-in (wos-auth-verifier-…), connecting the RepoReady GitHub App (gh_app_state) and organisation invitations (rr_invite_conflict_org), a local storage entry for the sort order you chose for the project list (projects:sortChoice) and a session storage entry that prevents repeated reloads after a web app update (rr-chunk-reload) — legal basis § 25 (2)(2) TDDDG; no consent required. There is no tracking, analytics, or session recording.
Detailed description of the cookies in use, providers, and retention periods: see our Cookie Policy.
8. Your rights
You have the right to:
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing based on legitimate interests (Art. 21 GDPR),
- withdraw a granted consent with effect for the future (Art. 7 (3) GDPR),
- lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent supervisory authority for Helmholtz Zentrum München is the Federal Commissioner for Data Protection and Freedom of Information (Bundesbeauftragte für den Datenschutz und die Informationsfreiheit, BfDI), Bonn.
Please send requests to [email protected] or to the data protection officer (Section 1).
9. Duty to provide data
Providing the data required for performing the contract (email, name) is necessary to use the Service. Without these data, registration is not possible. Any further provision of data is voluntary.
10. Automated decision-making / profiling
No solely automated decision producing legal effects within the meaning of Art. 22 GDPR is taken. AI-supported assessments of your repository are advisory in nature; you decide freely whether and which suggestions to accept.
11. Changes to this notice
We update this privacy notice when our processing changes. For material changes we will inform you by email or in the Service.