Last updated: 2026-08-20
This Privacy Policy describes how GitReviewed ("GitReviewed," "we," "our," or "us") collects, uses, and protects your personal information when you use our website and software services (the "Service"). By using the Service, you agree to the terms of this Privacy Policy.
Who we are. GitReviewed is operated by MIRIO Technologies Limited, a company registered in Hong Kong under Business Registration No. 76928444, with its registered office at Unit 2904-05, 29/F, Universal Trade Centre, No. 3 Arbuthnot Road, Central, Hong Kong. MIRIO Technologies Limited is the data controller for the personal data described in this policy. For any privacy question, or to exercise the rights described in Section 9, contact us at support@gitreviewed.com.
1. Information We Collect
1.1 Account Information
When you sign up, we collect your name, email address, and billing details (for paid plans).
1.2 OAuth Permissions
When you authorize GitReviewed via GitHub, GitLab, or similar platforms, we request access to repositories and pull request metadata strictly as required to operate the Service.
1.3 Personal Access Token (PAT) for GitHub
Providing a GitHub Personal Access Token (PAT) is optional. If you do not provide a PAT, you can only review public repositories in read-only mode. For organization repositories, you will need admin approval to post comments. If you choose to provide a PAT, it is used solely to retrieve your pull requests and to post review comments on your behalf. We store your PAT securely using strong AES-256 encryption and strict access controls, and you can revoke it at any time in your GitHub settings.
1.4 Usage Data
We collect usage metrics such as the number of reviews you run, which features you use, and timestamps. We use them to enforce plan limits, improve performance, and detect abuse. These metrics are stored against your account identifier, not your name or email. That makes them pseudonymous rather than anonymous: we can still link them back to your account. We do not share them with third parties in a personally identifiable way.
1.5 Payment Information
Payments are securely handled by Stripe. We never store your card details. For more on Stripe's data practices, see https://stripe.com/privacy.
1.6 Cookies
We use cookies for essential site functions and analytics.
- Clerk cookies are strictly necessary for authentication and login. These cookies are required for the Service to function and cannot be disabled if you wish to log in or use authenticated features. Clerk cookies do not store personally identifiable information by default. See Clerk's documentation for more details.
- PostHog cookies are used for analytics to help us understand how you use the product and improve it. These cookies are only set if you accept cookies via our cookie consent banner. If you decline, PostHog operates in cookieless mode (in-memory, no persistent ID, no cross-session tracking). See PostHog cookieless tracking and PostHog persistence docs.
- You can manage your cookie preferences at any time using the cookie consent banner.
- Withdrawing Consent: You may withdraw your consent for analytics cookies at any time by updating your preferences in the cookie consent banner.
2. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract: To provide and maintain the Service as agreed in our Terms of Service.
- Consent: For analytics cookies and marketing communications, where you have given explicit consent.
- Legitimate Interest: To improve and secure our Service, prevent abuse, and ensure proper billing and support.
3. How We Use Your Data
- To provide and maintain the Service
- To process payments and manage subscriptions
- To send essential notifications (e.g., billing, service updates)
- To improve and optimize the Service
- To prevent fraud or abuse
4. Code & Repository Data
- We never store your source code or diffs.
- Pull Request data is processed in-memory only and discarded after generating review comments.
- No code is used for training machine learning models.
5. Data Sharing
We do not sell your personal data. We share it with the service providers we need in order to run GitReviewed, and only to the extent each one requires:
- Clerk, for authentication and account management
- Stripe, for payments and subscriptions
- OpenRouter, which sends pull-request diffs to the language model that drafts your review comments. OpenRouter passes each request to a third-party model provider, and the model we use changes as better ones become available.
- Upstash, which stores your monthly review count in Redis
- PostHog, for product analytics
- Vercel, for hosting and delivery
We may also disclose your data when required by law or legal process, or to investigate abuse, fraud, or violations of our Terms of Service.
6. Data Retention
We retain account and billing data as long as your account is active or as needed to comply with legal obligations. You may request deletion of your account at any time.
7. Security
We use industry-standard security measures including HTTPS encryption, in-memory processing of sensitive data, and strict access controls. All tokens are stored using strong AES-256 encryption and are only accessible to our core systems.
8. Data Breach Notification
In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, in accordance with applicable law.
9. Your Rights (EU & International Users)
You may:
- Access the personal data we hold about you
- Request corrections or deletion
- Object to processing or request data portability
- Restrict processing of your data
- Withdraw consent at any time (for analytics/marketing cookies)
- Not be subject to automated decision-making or profiling
- File a complaint with your local data protection authority (find your authority here)
- Manage your cookie and analytics preferences at any time using the cookie consent banner
To exercise these rights, contact us at support@gitreviewed.com
10. Data Protection Officer / Contact
If you have questions about this policy or your data, or wish to exercise your rights, contact our Data Protection Officer (DPO) or privacy team at support@gitreviewed.com.
11. Automated Decision-Making and Profiling
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
12. Children's Privacy
Our Service is not intended for children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will take steps to delete such information.
13. International Data Transfers
We operate from Hong Kong, and the providers listed in Section 5 may store or process data outside your country, including in the United States and the European Union. Where a transfer involves personal data protected by EU or UK law, we rely on the transfer mechanisms our providers make available, such as the European Commission's Standard Contractual Clauses.
14. Changes to This Policy
We may update this Privacy Policy. Material changes will be notified via email or within the Service. Continued use after changes means acceptance.
15. Contact Us
Email us at support@gitreviewed.com for any questions or concerns.
Thanks for using GitReviewed!