Legal

Privacy Policy

Effective date: 25 June 2026

This Privacy Policy explains how personal data is collected, used, and shared when you use Reviewsaur(the “Service”), available at www.reviewsaur.com. Reviewsaur generates interactive quizzes from GitHub pull requests so that reviewers demonstrate they understand a change before approving or merging it.

Reviewsaur is operated by Rafał Graniczny, a sole proprietor based in Poland (the “Operator”, “we”, “us”). For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), the Operator is the data controller of the personal data described below. You can reach us at any time at [email protected].

When your employer or team connects Reviewsaur to its GitHub organization, that team is the controller of the code and pull-request content it processes through the Service, and we act as a data processor on its behalf for that content. This policy describes both roles.

1. What data we collect

Account & identity data

When you sign in with GitHub, we receive and store the following from your GitHub profile and organization membership:

  • your GitHub user ID and username;
  • your name and email address;
  • your avatar URL;
  • your membership of, and role within, the teams (organizations) you belong to inside Reviewsaur.

Pull request & code data

To generate and grade quizzes, the Service processes data about the pull requests in the repositories your team connects, including:

  • pull request titles, numbers, and commit SHAs;
  • the author and approvers’ GitHub usernames;
  • the code diff and changed file list for the pull request, which is sent to our AI provider to produce questions;
  • the generated quiz questions, your submitted answers, scores, attempts, and grader feedback, attributed to the GitHub user who took the quiz.

Code diffs are sent to the AI provider only for the moment of quiz generation. We retain the resulting questions, a short PR summary, and the list of changed file names — not full copies of your source code.

Billing data

If your team subscribes to a paid plan, payments are handled by Stripe. We store your Stripe customer and subscription identifiers and your plan tier. We do not store full card numbers; card data is handled directly by Stripe.

Usage & analytics data

We use PostHog for product analytics to understand how the Service is used and to improve it. This includes pages viewed, features used, device and browser information, approximate location derived from your IP address, and an identifier associated with your account once you are signed in. We use cookies and similar technologies for this — see Section 7.

2. How we use your data

We use personal data to:

  • provide, operate, and secure the Service;
  • authenticate you and verify your team membership before you can take a quiz;
  • generate quizzes from pull requests and grade your answers;
  • attribute quiz results to a person so your team can rely on the GitHub status check;
  • process payments and manage subscriptions;
  • communicate with you about the Service, including transactional messages such as receipts and important changes;
  • analyze and improve the Service, and diagnose and fix problems;
  • comply with our legal obligations and enforce our terms.

3. Legal bases for processing (GDPR)

Where the GDPR applies, we rely on the following legal bases under Article 6(1):

  • Performance of a contract — to provide the Service to you and your team, including authentication, quiz generation and grading, and billing.
  • Legitimate interests — to secure, maintain, and improve the Service and to understand how it is used, balanced against your rights and freedoms.
  • Consent — for non-essential analytics cookies, where required. You can withdraw consent at any time.
  • Legal obligation — to comply with applicable law, such as tax and accounting requirements.

4. How we share data & sub-processors

We do not sell your personal data. We share it only with the service providers below, who process it on our behalf to operate the Service. Each is bound by a data processing agreement and processes data only for the purposes we specify.

ProviderPurposeData involved
GitHub (Microsoft)Sign-in, org membership, pull request and code accessIdentity, repository & PR data
StytchAuthentication and team/organization managementIdentity, team membership
StripePayment processing and subscription managementBilling data
xAI (Grok)AI generation of quiz questions and grading of answersPR diffs, generated questions, answers
InngestDurable background job processing (generation, grading)PR & quiz data
NeonManaged PostgreSQL database hostingAll stored application data
VercelApplication hosting and content deliveryRequest and log data
PostHogProduct analyticsUsage and device data

We may also disclose data where required by law, to enforce our agreements, or in connection with a merger, acquisition, or sale of assets, in which case we will notify you.

We do not use your code or quiz data to train our own models. Our AI provider’s use of data submitted through its API is governed by its own terms. We may update this list of sub-processors as the Service evolves; material changes will be reflected here.

5. International transfers

Some of our providers are located outside the European Economic Area (notably in the United States). Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision, so that your data continues to receive a level of protection comparable to that under EU law.

6. Data retention

We keep personal data only for as long as necessary for the purposes set out in this policy:

  • Account data is retained while your account or team membership is active.
  • Quiz and pull-request data is retained while the relevant repository is connected, so your team has a record of who passed which quiz.
  • Billing records are retained as long as required by tax and accounting law.
  • When a team disconnects a repository or closes its account, we delete or anonymize the associated data within a reasonable period, unless we are required to retain it by law.

7. Cookies & similar technologies

We use two categories of cookies and local storage:

  • Strictly necessary — to keep you signed in and to operate the Service securely. These cannot be switched off.
  • Analytics — set by PostHog to measure usage and improve the product. Where required by law, we ask for your consent before setting these, and you can withdraw it at any time.

You can also control cookies through your browser settings. Blocking strictly necessary cookies may prevent parts of the Service from working.

8. Your rights

Subject to applicable law, and in particular under the GDPR, you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • request erasure of your data (“right to be forgotten”);
  • restrict or object to certain processing;
  • receive your data in a portable, machine-readable format (data portability);
  • withdraw consent at any time, where processing is based on consent.

To exercise any of these rights, email [email protected]. Where the data relates to your team’s repositories, we may direct your request to your team administrator, who is the controller of that content. You also have the right to lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO).

9. Security

We take reasonable technical and organizational measures to protect personal data, including encryption in transit, access controls, and the use of reputable infrastructure providers. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

10. Children

The Service is intended for use by businesses and professionals and is not directed to anyone under 16. We do not knowingly collect personal data from children.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the effective date above and, for material changes, take reasonable steps to notify you. Your continued use of the Service after an update means you accept the revised policy.

12. Contact

For any questions about this policy or how we handle your data, contact us at [email protected].