Privacy Policy
Last Updated: April 17, 2026
1. Data Collection
We minimize data collection to the absolute essentials required for service delivery:
- GitHub Metadata: Repository names, PR numbers, commit hashes, and installation identifiers.
- Source Code: Ephemerally processed for verification (AST analysis, math validation, security scanning). It is never stored. Code is loaded into volatile memory, analyzed, and immediately discarded.
- Payment Info: Processed securely via GitHub Marketplace. We do not store or access credit card or billing details.
- Analytics: We use Google Analytics (via Google Tag Manager) to collect anonymized usage data including page views, session duration, and general browser/device type. No personally identifiable information is collected through analytics.
- Contact Form: If you submit the contact form, we collect your name, email, company, and message to respond to your inquiry.
2. Third-Party Services
QWED Security may optionally route verification requests through third-party AI providers when configured by the user. These include:
- OpenAI (optional) — used only when user-configured
- Anthropic (optional) — used only when user-configured
- Google Gemini (optional) — used only when user-configured
These providers are only invoked when explicitly enabled. Source code passed to these providers is subject to their respective privacy policies. We do not share data with these providers without user configuration.
We also use Google Tag Manager and Google Analytics on our website for anonymized usage analytics.
3. Data Usage
- Verification: To generate pass/fail reports on your Pull Requests and repositories.
- Audit Logs: Verification results (not source code) are retained for 30 days to support audit trails, then permanently deleted.
- Improvements: Aggregated, anonymized statistics (e.g., "errors blocked") may be used to improve our verification engines. No individual code or user data is used.
4. Data Protection
- Encryption: All data in transit is encrypted via TLS 1.3.
- Access Control: Strict internal access controls based on the principle of least privilege. All interactions pass through GitHub App authentication (JWT).
- PII Masking: Our PII Detection engine automatically masks sensitive data (emails, SSNs, credit card numbers) before logging.
- Retention: Verification metadata is retained for 30 days. Source code is never retained.
5. Your Rights (GDPR / CCPA)
You have the following rights regarding your data:
- Access: Request a copy of data we hold associated with your account.
- Deletion: Request deletion of all metadata associated with your GitHub installation.
- Opt-out: You may uninstall the GitHub App at any time to stop all data processing.
To exercise any of these rights, contact: support@qwedai.com
6. Cookies
Our website uses cookies solely for Google Analytics (anonymized, aggregated usage tracking). We do not use cookies for advertising or cross-site tracking. You may disable cookies in your browser settings at any time.
7. Policy Changes
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date above. Continued use of the service after changes constitutes acceptance of the revised policy. For significant changes, we will notify users via the GitHub App or email where possible.
8. Contact
For privacy-related inquiries: support@qwedai.com