On this page
1. Information We Collect
We collect information you provide directly:
- Account Information — Name, email address, organization name, and role
- Authentication Data — OAuth tokens from GitHub, GitLab, Bitbucket, or Google
- Repository Metadata — Repository names, branches, file structure, and source-derived review or scan records
- Usage Data — Scan history, feature usage, and interaction patterns
- Payment Information — Processed securely via Stripe or Razorpay (we do not store card numbers)
2. How We Use Information
- Providing and improving the security scanning service
- Processing scan requests and generating vulnerability reports
- Sending scan completion notifications and weekly security digests
- Billing and subscription management
- Responding to support requests
- Analyzing usage patterns to improve the product (aggregated, anonymized)
3. Source Code & Scan Data
This is the most important section for security-conscious teams:
- Ephemeral Scan Checkout — Repositories are cloned into isolated scan workspaces and the checkout is removed after processing. This does not mean every source-derived record is deleted at scan completion.
- Stored PR Diffs — Changed-file names and unified diff patches are stored per review attempt to display current or historical inline diffs and to ground review findings and governed review chat. Access is authenticated and tenant-scoped; file metadata is paginated, and patch content is fetched one file at a time through a bounded response that reports any truncation.
- Stored Results — Normalized findings, summaries, evidence, remediation guidance, and review records are stored with your organization under account and product retention controls.
- Governed PR AI — When an organization enables PR-review AI, bounded review context is sent only to the provider selected by the effective organization or repository policy. CodeStax fails closed when that route is unavailable.
- Raw AI Cache — For governed PR review analysis with source retention disabled, CodeStax does not read or write its local raw AI-response cache. This control does not erase derived review findings or apply to every generic scan workflow.
- Review Chat Replay — A generated review-chat answer, which may contain source-derived text, is AES-GCM encrypted at rest. Replay eligibility defaults to 10 minutes and is configurable from 30 seconds to 60 minutes. Cleanup is scheduled on a five-minute target cadence after eligibility ends; that cadence is an operating target, not a hard deletion deadline. Overdue ciphertext cannot be replayed and remains cleanup debt until a successful run removes it.
- Navigation During Chat — Leaving a review aborts the browser's wait and prevents a stale answer from appearing on another review. If provider processing already started, it may continue server-side to a terminal result under the same policy, evidence, and encrypted-retention controls.
- Tenant Isolation — All scan data is strictly isolated per organization with enforced access controls
5. Data Security
We implement industry-standard security measures:
- TLS protects browser and public API traffic; the private app-to-scanner and scanner-to-database/Redis paths use an encrypted WireGuard tunnel
- Encryption of sensitive credentials at rest (OAuth tokens, API keys)
- Role-based access control (RBAC) with organization-level isolation
- Regular security audits and penetration testing
- Security practices aligned with SOC 2 principles
6. Data Retention
Scan results, derived review records, and account data are generally retained for the duration of your subscription unless a product control states otherwise. Governed review-chat data follows a narrower server-side contract:
- Generated review-chat answers are not stored as plaintext. AES-GCM encrypted answers are replay-eligible for 10 minutes by default and never longer than 60 minutes
- Expired answer ciphertext becomes ineligible for replay immediately. Cleanup targets the next scheduled run within 5 minutes; delayed or failed runs can make ciphertext overdue until cleanup succeeds, so 15 minutes is a default target rather than a guaranteed physical-retention maximum
- Terminal non-content review-chat reservation metadata is retained for up to 30 days by default and never longer than 365 days
- Changing AI policy, changing a repository override, or revoking a provider credential immediately erases replayable chat answers for the organization
- Derived findings, summaries, evidence, and review results remain governed by normal review and account retention; disabling raw source retention does not delete them
- Stored PR diff patches follow the associated organization review record. Deleting that review or its tenant-owned repository deletes the associated patch rows; deleting one user does not delete shared organization review records while the organization remains active
- Account-deletion requests enter the grace period shown in the product and are then processed by scheduled deletion. Completion is not guaranteed exactly 30 days after the request
- Tenant-owned scan and vulnerability records are removed by the applicable account, organization, repository, and review deletion workflows; shared organization records are not erased merely because one user leaves
- Anonymized, aggregated analytics may be retained
- Residual backup copies follow the infrastructure provider's backup lifecycle and access controls; CodeStax does not promise an exact 90-day purge from this policy
7. Your Rights
Under GDPR (EU/EEA users), you have the right to:
- Right to Access — Download all personal data we hold about you in JSON format
- Right to Rectification — Correct inaccurate information in your account settings
- Right to Erasure — Request account deletion; the product shows the applicable grace period before scheduled processing, and shared organization records follow organization ownership and retention controls
- Right to Data Portability — Export your data in machine-readable JSON format
- Right to Object — Opt out of non-essential email communications at any time
Under CCPA (California users), you have the right to:
- Know what personal information is collected and how it is used
- Request deletion of personal information
- Opt out of the sale of personal information (we do not sell your data)
How to exercise your rights:
- Go to Settings → Privacy & Data in your dashboard to download your data or delete your account
- Email privacy@codestax.co for any data-related requests
- We respond to all requests within 30 days as required by law
9. Children's Privacy
CodeStax is not intended for users under the age of 16. We do not knowingly collect personal information from children.
10. International Transfers
Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place for cross-border data transfers, including standard contractual clauses where required.
11. Policy Changes
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 30 days before they take effect.
12. Contact
For privacy-related inquiries, contact us at privacy@codestax.co.