Skip to main content

What a review uses

  • GitHub installation, repository, pull-request, delivery, base, and head identifiers.
  • Source needed to review the exact immutable revision.
  • Review findings, execution receipts, coverage, and publication state.
  • Capacity, abuse-prevention, and operational records.
Webhook signatures are verified before work is accepted. Installation tokens are resolved only when needed and must not be logged. Workers must not receive a GitHub App private key or standing cloud credential.

Access and minimization

Webhook signatures are verified before work is accepted. GitHub installation tokens are short-lived and repository-scoped. Workers do not receive the GitHub App private key or standing cloud credentials. Customer views omit provider credentials, model routing, raw internal votes, and founder-only cost telemetry. Secrets and secret-bearing environment variables are redacted from receipts.

Retention and deletion

Uninstalling or removing a repository must stop new work, revoke future access, GitHub-visible comments and checks remain subject to GitHub and repository controls. Security, fraud, billing, and audit records may have a separate legal retention basis. For a data request, include only the installation and repository identifiers needed to locate the record and use Status and support. Never email tokens, private keys, raw private source, or unredacted evidence.
Last modified on August 29, 2026