codqual is a code-review service operated by [OPERATOR LEGAL NAME], [REGISTERED ADDRESS] ("codqual", "we"). Contact for anything in this policy: hello@codqual.com.
We play two roles. For your account, organization, and billing data we are the data controller. For the contents of repositories your organization enrolls, we act as a processor on your organization's behalf: your organization decides which repositories we analyze, and we analyze them only to provide the service.
The GitHub App can only read repositories your organization has explicitly granted it — installing the app enrolls nothing automatically. A PR review reads the pull request's diff; a scan fetches a snapshot of the whole repository.
We do not keep a copy of your repository. Repository contents are processed transiently: analyzed in memory and temporary storage that is deleted when the run finishes. What we store afterwards are the results: findings and review verdicts (file and line references, explanations, and short quoted evidence excerpts where a finding needs them), health scores, and a per-repository memory that is derived from those stored results — never from raw code.
To run analysis, excerpts of your code (up to roughly 12 KB per file, plus the diff under review) are sent to large-language-model providers. Which providers, depends on your plan:
We do not train our own models on your code, and we do not sell your code or your account data to anyone. More detail on what is sent and kept is in the security documentation.
| Provider | Purpose | Location |
|---|---|---|
| Anthropic | LLM analysis (paid plans) | United States |
| OpenRouter (and the downstream model hosts it routes to) | LLM analysis routing (all plans; sole provider on the free plan) | United States |
| GitHub | Source hosting, GitHub App, repository access | United States |
| Brevo | Transactional email (invitations, password resets, alerts) | European Union (France) |
We update this table when a provider is added or replaced; material changes are reflected in the "last updated" date above. Transfers of EU/EEA personal data to US providers rely on the EU-US Data Privacy Framework where the provider is certified, and on Standard Contractual Clauses otherwise.
| Data | Retention |
|---|---|
| Repository contents during analysis | Duration of the run only; deleted when it finishes |
| Findings, reviews, scores, repo memory | While your organization's account is active, or until deletion is requested |
| LLM call audit logs | 90 days |
| Sessions | Removed within 7 days of expiry |
| Sign-in links and OAuth handshake state | Removed within 1 day of expiry |
| Invoices and payment-proof images | For the period required by tax and accounting law |
You can ask us to access, correct, export, restrict, or delete your personal data, or object to a use of it, by emailing hello@codqual.com from your account email. We verify identity and respond within one month. Deleting your account removes your account data and personal identifiers; it is currently handled by us on request rather than by an in-product button. If you are in the EU/EEA you may also complain to your supervisory authority; if you are in a US state with a privacy law that applies to you, the same channel serves those requests.
Personal data that appears inside a customer repository we process on that customer's instructions — please direct requests about it to the organization that owns the repository, and we will assist them.
We use only functional cookies, all httpOnly and secure: session and
rid (keeping you signed in), oauth_state (sign-in
integrity), and short-lived cookies for invitations and connecting GitHub. No
advertising or analytics cookies, no tracking — which is why there is no cookie
banner. Your browser's local storage holds only UI preferences (selected repository,
language).
Data is encrypted in transit (TLS). GitHub tokens and webhook secrets are encrypted at rest at the application level (AES-256-GCM); passwords are hashed with bcrypt; session tokens, reset tokens, and API keys are stored hashed. Access is role-based, and API keys are structurally read-only — they can never trigger analysis or change data beyond recording feedback.
codqual is a professional tool and is not directed to children under 16; we do not knowingly collect their data.
When this policy changes materially we update this page and its date, and notify organization billing contacts by email for significant changes. Continued use after a change means the updated policy applies.
Responsable: [NOMBRE O RAZÓN SOCIAL DEL RESPONSABLE], con domicilio en [DOMICILIO EN MÉXICO] ("codqual"). Contacto: hello@codqual.com. Este aviso se emite en cumplimiento de la Ley Federal de Protección de Datos Personales en Posesión de los Particulares (2025). Para titulares en México, esta versión en español rige respecto de la información de privacidad.
Datos de identificación y contacto (correo electrónico, identidad en GitHub/ GitLab/Google/Forgejo); datos de sesión (dirección IP y navegador); datos de facturación, incluyendo datos patrimoniales o financieros (comprobantes de pago por transferencia bancaria que usted sube), los cuales requieren su consentimiento expreso y se usan únicamente para verificar su pago; y el contenido de los repositorios que su organización inscribe, el cual se procesa de forma transitoria para generar los resultados del análisis y no se conserva.
Finalidades necesarias: prestar el servicio de revisión y análisis de código, administrar su cuenta y organización, facturación y verificación de pagos, envío de correos transaccionales, y seguridad del servicio. No realizamos tratamiento con fines de mercadotecnia o publicidad; si en el futuro existieran finalidades no necesarias, se solicitará su consentimiento por separado.
Para prestar el servicio, remitimos extractos de código a proveedores de modelos de inteligencia artificial en Estados Unidos: Anthropic y OpenRouter (que enruta a los proveedores de modelos configurados, incluidos modelos de código abierto en el plan gratuito, cuyos proveedores pueden registrar y usar los mensajes conforme a sus propios términos). También usamos GitHub (EE.UU., acceso a repositorios) y Brevo (Francia, correo transaccional). No vendemos sus datos personales ni su código.
Usted puede ejercer sus derechos de Acceso, Rectificación, Cancelación y Oposición, así como revocar su consentimiento o limitar el uso o divulgación de sus datos, enviando una solicitud desde el correo de su cuenta a hello@codqual.com, indicando el derecho que desea ejercer. Verificaremos su identidad y responderemos dentro de los plazos que marca la ley. La autoridad competente en materia de protección de datos es la Secretaría Anticorrupción y de Buen Gobierno.
Cualquier cambio a este aviso se publicará en esta página, actualizando la fecha al inicio; los cambios significativos se notificarán además por correo electrónico al contacto de facturación de su organización.
This page describes what the product actually does today, verified against the codebase. It is not legal advice, and the bracketed operator name and addresses must be filled in and the whole page reviewed by a lawyer before it is relied on as a binding notice.