Privacy Policy
Last updated: January 15, 2025
Introduction
Welcome to diffray ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered code review service at diffray.ai (the "Service").
Please read this Privacy Policy carefully. By accessing or using our Service, you agree to the terms of this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
1. Information We Collect
1.1 Information You Provide to Us
Account Information:
When you sign up for diffray through GitHub OAuth, we collect:
- GitHub username
- Email address
- Profile picture/avatar
- Public profile information from your GitHub account
Company Information:
During onboarding, we may collect:
- Company name
- Team size
- Primary use case preferences
Communications:
If you contact us directly, we may receive:
- Name
- Email address
- Phone number (if provided)
- Message contents
- Any attachments you send us
1.2 Information Collected Automatically
Usage Data:
When you access our Service, we automatically collect:
- IP address
- Browser type and version
- Device information
- Operating system
- Pages visited and time spent
- Referring/exit pages
- Click data and interactions
Cookies and Tracking Technologies:
We use cookies, web beacons, and similar tracking technologies to:
- Maintain your session
- Remember your preferences
- Analyze usage patterns
- Improve our Service
You can control cookies through your browser settings.
1.3 Information from GitHub
Repository Access:
When you authorize diffray to access your GitHub repositories, we collect:
- Repository names and metadata
- Pull request data
- Code changes and diffs
- Commit messages and history
- Comments and review feedback
- Branch information
- Contributor data
2. How We Use Your Information
We use the collected information for the following purposes:
2.1 To Provide and Maintain Our Service
- Authenticate your account
- Analyze code and provide review suggestions
- Generate AI-powered feedback
- Process pull requests automatically
- Maintain service functionality
2.2 To Improve Our Service
- Understand how users interact with diffray
- Identify usage patterns and trends
- Develop new features
- Improve AI model accuracy
- Conduct research and analysis
2.3 To Communicate With You
- Send service-related notifications
- Respond to your inquiries
- Provide customer support
- Send important updates about our Service
- Inform you about new features (with your consent)
3. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
3.1 With Your Consent
We may share your information when you explicitly consent to such sharing.
3.2 Service Providers
We share information with third-party service providers who perform services on our behalf:
- Cloud hosting services (e.g., AWS, Google Cloud, Vercel)
- AI model providers (e.g., OpenAI, Anthropic)
- Analytics platforms (e.g., Google Analytics, Mixpanel)
- Email service providers
- Customer support platforms
4. Data Retention
We retain your information for as long as necessary to provide our Service, comply with legal obligations, resolve disputes, and enforce our agreements.
- Account Data: Retained while your account is active and for 90 days after account deletion
- Code and Repository Data: Retained for the duration of service usage. Deleted within 30 days of disconnecting a repository
- Analytics Data: Aggregated and anonymized data may be retained indefinitely
5. Data Security
We implement appropriate technical and organizational measures to protect your information:
Technical Measures:
- Encryption in transit (TLS/SSL)
- Encryption at rest
- Secure authentication (OAuth 2.0)
- Regular security audits
- Access controls and logging
6. Your Privacy Rights
Depending on your location, you may have the following rights:
- Access and Portability: Request a copy of your personal information
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your personal information
- Opt-Out: Opt out of marketing communications
To exercise your rights, contact us at: privacy@diffray.ai
7. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. When we transfer your information internationally, we ensure appropriate safeguards are in place.
8. Children's Privacy
Our Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
10. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
- Email: privacy@diffray.ai
- Data Protection Officer: dpo@diffray.ai
- General Inquiries: hello@diffray.ai
- Support: support@diffray.ai
© 2025 diffray, Inc. All rights reserved.