Skip to content
Data policy · Private beta

Clear boundaries for your source context.

What DiffDispatch reads, what it retains, and what is sent to AI providers.

Data we collect

DiffDispatch reads repository metadata, selected repository contents, commit and pull request history, review activity, and organization membership for repositories an administrator enables. Slack access is limited to user identity mapping, direct messages, and the digest channel you select.

We retain derived code-area summaries, expertise evidence, reviewer decisions, operational events, and embeddings. DiffDispatch does not persist the raw source snippets sent in an AI request.

OpenAI processing

When an administrator enables AI analysis and accepts the consent disclosure, DiffDispatch sends changed hunks, file paths, and minimal module context to OpenAI. Requests use store: false.

Important. OpenAI may retain API inputs and outputs for abuse monitoring for up to 30 days unless Zero Data Retention is approved for the relevant account. DiffDispatch does not claim end-to-end zero retention.

Repository content is treated as untrusted input. The model receives no tools, output is constrained by strict schemas and size limits, and a deterministic ownership method is used if analysis fails or is refused.

Security

GitHub installation tokens are ephemeral. Slack bot tokens and OAuth credentials are encrypted with AES-GCM using a versioned application secret. Tenant-owned records include an organization identifier and API access is scoped to the authenticated membership.

Deletion and uninstall

Uninstalling the GitHub App immediately deletes stored credentials and stops pending processing. Tenant-derived code data is purged within 24 hours. Operational records may be retained only where required to investigate security or reliability incidents.

Contact

For privacy questions or deletion requests, email privacy@diffdispatch.com.