Legal

Your privacy, our commitment

We only touch your PR diffs — never your full codebase. Here's exactly what we collect, why, and how you stay in control.

Last updated: June 22, 20265 min read
01

Overview

Scrutio ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and the choices you have regarding your data.

By using the Service, you consent to the practices described in this policy.

02

Information We Collect

GitHub Account Data: When you authenticate via GitHub OAuth, we receive your GitHub username, display name, email address (if public), and profile avatar. This is used to identify your account.

Repository Metadata: We store the names and GitHub IDs of repositories you connect to Scrutio, along with webhook configuration data needed to receive PR notifications.

Pull Request Diffs: When a pull request is opened in a connected repository, GitHub sends us the diff via webhook. This diff is transmitted to an AI model for review generation and is not stored after the review is complete.

Review Results: AI-generated findings, approval decisions, and ticket data are stored and associated with your account to provide the Service.

Usage Data: We collect anonymized usage metrics such as review counts and credit consumption to operate and improve the Service.

03

What We Do Not Collect

  • We do not access, store, or transmit your full source code — only PR diffs sent by GitHub webhooks.
  • We do not sell your data to third parties.
  • We do not use your code or repository data for AI training purposes.
  • We do not store payment card data — billing is handled by a PCI-compliant payment processor.
04

How We Use Your Information

We use your information to:

  • Authenticate your account and maintain your session.
  • Receive PR webhooks and trigger AI code reviews.
  • Display review results, findings, and tickets in your dashboard.
  • Track credit usage and manage billing.
  • Send transactional emails related to your account (e.g., plan changes, important notices).
  • Investigate security incidents or abuse of the Service.
05

AI Model Providers

PR diffs are transmitted to third-party AI model providers (such as Anthropic or OpenAI) to generate review results. These providers receive only the diff content, not your account details.

Each provider processes data according to their own privacy policies and data processing agreements. We select providers that offer appropriate data handling commitments for enterprise use. Diffs are not used to train AI models.

06

Data Retention

We retain your account data for as long as your account is active. Review findings and ticket data are retained for the lifetime of your account to provide history and audit trails.

PR diff content is not stored after a review is generated. Upon account deletion, your personal data is removed within 30 days, except where retention is required by law.

07

Cookies and Tracking

We use session cookies to maintain your authenticated state. We do not use third-party advertising cookies or cross-site tracking technologies.

Basic analytics (page views, feature usage) may be collected in anonymized, aggregated form to improve the Service.

08

Data Security

We implement industry-standard security measures including HTTPS encryption in transit, secure token storage, and access controls. GitHub OAuth tokens are stored encrypted.

However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security and encourage you to use strong GitHub account security (2FA).

09

Your Rights

Depending on your jurisdiction, you may have rights to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and associated data.
  • Object to or restrict certain processing of your data.
  • Port your data to another service.

To exercise these rights, contact us at privacy@scrutio.dev.

10

Children's Privacy

The Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.

11

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice in the Service or via email. Continued use of the Service after changes take effect constitutes acceptance.

12

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, please contact our privacy team at privacy@scrutio.dev.