The formal policy is being written. What we actually hold is below: a plain summary, not the document.
We would rather leave this page empty than fill it with something adapted from a template. This product lets software merge itself while nobody is watching, and the terms that govern that are not boilerplate: they are being written properly, with advice.
What is stored today
Three parties see anything: SendGrid receives an email address to deliver a sign-in code, GitHub receives what the App does on your repository, and the model provider sees the prompts. On a bring-your-own key, that last one is your contract and not ours , which changes who is responsible for it, and is one of the things the finished document has to be precise about.
On a self-hosted runner your source never reaches us at all. It is cloned on your machine with a token scoped to one repository, and what comes back is a branch name and a list of changed files.
Until then, ask us directly and you will get a straight answer: [email protected].