Privacy Policy
Last updated: August 4, 2026
CritGuard (“we”, “us”) is a GitHub App that reviews pull requests for production-impacting business-logic risks. This policy explains what we process when you install or use CritGuard.
Who this applies to
This policy applies to GitHub users and organizations that install CritGuard, and to people who open pull requests in repositories where CritGuard is installed or who use CritGuard feedback links.
Data we process
- GitHub App installation data — installation id, account/org identity, and selected repositories.
- Pull request data — PR metadata (numbers, titles, SHAs, authors), file paths, diffs, and related webhook payloads needed to run a review.
- Review outputs — findings (severity, problem, impact, suggestion), review comments posted to GitHub, and audit/operational logs.
- Feedback — Helpful / Incorrect votes submitted via signed feedback links.
- Usage limits — per-repository daily review counts for the free plan.
How we use data
- To analyze pull request changes and post review comments on GitHub.
- To enforce free-plan quotas and operate the service reliably.
- To improve review quality using aggregate feedback and operational signals.
- To secure the service, debug issues, and prevent abuse.
Third-party services
CritGuard sends pull request diffs and related review context to an OpenAI-compatible LLM provider (for example OpenAI or Freemodel) to generate findings. We also use hosting infrastructure (application servers and databases) to run CritGuard. GitHub processes data according to GitHub’s own terms and privacy policy when you use GitHub.
What we do not do
- We do not sell your personal data.
- We do not use pull request content to train public foundation models for unrelated products (provider terms may still allow limited processing needed to provide their API).
- We do not require a CritGuard account separate from GitHub for the core review flow.
Retention
We retain review records, feedback, and operational logs as long as needed to provide the service, enforce limits, debug issues, and meet legal obligations. You can uninstall the GitHub App at any time to stop new processing for your repositories.
Security
We use industry-standard measures appropriate to a small SaaS service, including secrets for webhook verification and signed feedback links. No method of transmission or storage is perfectly secure.
International transfers
Depending on where CritGuard and its LLM/hosting providers operate, data may be processed in countries other than your own. Those providers apply their own safeguards and terms.
Your choices
- Uninstall CritGuard from your GitHub account or organization.
- Limit repository access in the GitHub App installation settings.
- Contact us via the Support page for privacy questions or deletion requests we can reasonably fulfill for data we control.
Children
CritGuard is intended for professional software development use and is not directed at children.
Changes
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use after updates means you accept the revised policy.
Contact
Privacy questions: Support or open an issue at github.com/hossein25/critguard/issues.