Privacy Policy

Last updated: July 2026

1. Information We Store

We keep only the information needed to operate your account, provide reviews, and protect the service:

  • Account profile: Email address, username, and sign-in records needed to run your account
  • Review records: Review status, settings, and the findings or summaries returned to you
  • Payment records: Processed securely by Stripe; we do not store your card details
  • Operational data: Product usage, security events, and diagnostic logs needed for reliability and abuse prevention

2. How We Use Your Information

We use your information to:

  • Provide and improve the code review Service
  • Process payments and manage subscriptions
  • Send important account and service notifications
  • Ensure security and prevent fraud

3. Code Privacy

For GitHub App reviews, repository checkout and context extraction run in GitHub Actions. For CLI reviews, the `rmcode` command runs in your local repository. In both cases, RMCode uses the minimum review inputs needed for the requested analysis, such as a pull request diff, repository structure, and condensed source context, and sends those inputs to our AI/model service providers to generate findings. These code and repository inputs are transient for the review request and are not stored by RMCode after analysis completes.

We store the review results shown to you, such as findings, summaries, status, and billing or usage records needed to operate the service. We do not sell your code or use code content to train AI models.

4. Data Sharing and Service Providers

We do not sell your personal information. We share data only with service providers essential to operating the platform:

  • Google Cloud (infrastructure hosting) and Google Gemini (AI review analysis)
  • Amazon Web Services, including Amazon Bedrock (AI review analysis) and Amazon SES (transactional email)
  • Stripe (payment processing)

AI/model providers receive transient review inputs only to generate the review you requested and do not retain them for training.

5. International Data Transfers

Our services and the providers above process data in the United States. If you use the Service from outside the United States, including from the European Economic Area or the United Kingdom, your account information and review inputs are transferred to and processed in the United States. Where required, transfers rely on our providers' safeguards, such as standard contractual clauses or participation in the EU-U.S. Data Privacy Framework.

6. Data Security

We implement industry-standard security measures including encrypted data transmission (TLS), encrypted storage for sensitive credentials, and regular security audits.

7. Your Rights

You have the right to:

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion of your account and data
  • Export your review history

If you are in the European Economic Area or the United Kingdom, you also have rights under the GDPR, including the right to object to or restrict certain processing, the right to data portability, and the right to lodge a complaint with your local supervisory authority. We process account data to perform our contract with you (Art. 6(1)(b) GDPR) and operational and security data for our legitimate interest in running a reliable, safe service (Art. 6(1)(f) GDPR). To exercise any right, contact privacy@review-my-code.com.

8. Children

The Service is not directed to children under 16, and we do not knowingly collect personal data from anyone under 16. In the EU, users aged 16 or older may consent to this policy themselves, in line with Article 8 GDPR and applicable member state law. If you believe a child under 16 has created an account, contact us and we will delete it.

9. Data Retention

We retain account, billing, configuration, review result, and usage records while your account is active. Code and repository inputs used for analysis are transient and are not retained after the review request completes. When you delete your account, we cancel active Stripe subscriptions, delete account-linked API keys, installation and configuration records, saved review results, findings, SSO/OAuth sessions, webhooks, and GitHub App review records tied to your account, and unlink or anonymize related usage and marketing records. Some limited records may be retained when required for security, fraud prevention, tax, accounting, or legal obligations.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification.

11. Contact

For privacy-related questions, please contact us at privacy@review-my-code.com.