Privacy Policy
Your code is your most valuable asset. GitRabbit operates on an uncompromising Zero Data Retention pledge: we never train AI models on your code, and we never store your source files permanently.
Zero Model Training
Under no circumstances will your code or PR diffs be used to train public or commercial AI models.
Ephemeral Runners
All code reviews execute in isolated RAM memory. Memory is instantly cleared once the review comment posts.
SOC2 & GDPR Compliant
Audited security controls, end-to-end TLS 1.3 transit encryption, and strict role-based access management.
1. Information We Collect
We collect only information necessary to deliver and authenticate your code review service:
- Account Credentials: Name, email, and OAuth identifier from GitHub, GitLab, or Bitbucket.
- Repository Metadata: Repository names, PR numbers, commit hashes, and file paths.
- Transient Code Diffs: Code snippets received via webhooks for the duration of the review cycle.
2. How We Process Source Code
When a pull request is created or updated in your connected repository:
- GitRabbit spawns an isolated sandbox container.
- The diff is parsed in volatile memory against your rules and code graph.
- Review findings are published to your PR conversation thread.
- The container memory is wiped. No source files remain on our servers.
3. Subprocessors & Security
Our infrastructure runs on enterprise cloud providers (AWS, Google Cloud) certified under ISO 27001 and SOC2. All data in transit is encrypted using TLS 1.3 with AES-256 GCM cipher suites.
4. Your Data Rights
You retain the right to delete your account, revoke VCS webhook tokens at any time, and request full export or deletion of any account metadata by contacting privacy@gitrabbit.com.
