Data we collect
DiffDispatch reads repository metadata, selected repository contents, commit and pull request history, review activity, and organization membership for repositories an administrator enables. Slack access is limited to user identity mapping, direct messages, and the digest channel you select.
We retain derived code-area summaries, expertise evidence, reviewer decisions, operational events, and embeddings. DiffDispatch does not persist the raw source snippets sent in an AI request.
OpenAI processing
When an administrator enables AI analysis and accepts the consent disclosure, DiffDispatch sends changed hunks, file paths, and minimal module context to OpenAI. Requests use store: false.
Repository content is treated as untrusted input. The model receives no tools, output is constrained by strict schemas and size limits, and a deterministic ownership method is used if analysis fails or is refused.
Security
GitHub installation tokens are ephemeral. Slack bot tokens and OAuth credentials are encrypted with AES-GCM using a versioned application secret. Tenant-owned records include an organization identifier and API access is scoped to the authenticated membership.
Deletion and uninstall
Uninstalling the GitHub App immediately deletes stored credentials and stops pending processing. Tenant-derived code data is purged within 24 hours. Operational records may be retained only where required to investigate security or reliability incidents.
Contact
For privacy questions or deletion requests, email privacy@diffdispatch.com.