Privacy Policy.Your code stays yours.
Last updated 11 October 2026
The short version
- We only analyze pull request diffs. Your full codebase stays on GitHub.
- Diffs are sent to Anthropic for review and are not stored afterwards.
- We never sell your data or use your code to train AI models.
- No advertising or analytics trackers, just one sign-in cookie.
- Waitlist emails are used only to invite you and share launch news.
- You can ask us to export or delete your data at any time.
01Who we are and what this covers
Scrutio ("we", "us") provides AI code review for GitHub pull requests. This policy explains what personal data we collect through our website, our waitlist, and the Scrutio service, how we use it, and the choices you have.
By joining the waitlist or using the service, you acknowledge the practices described here.
02Information we collect
If you join the waitlist
- Your email address.
- Optionally, your role and team size, if you choose to tell us.
- How you found us: a campaign tag (such as
utm_source) or the referring website's domain.
If you sign in with GitHub
- Your GitHub user ID, username, display name, avatar, and email address (if GitHub shares it).
- We do not store GitHub access tokens. Scrutio is a GitHub App. When it needs to read a repository, it requests a short-lived installation token from GitHub and does not save it.
Repositories you grant access to
- Repository names and IDs, and the installation ID GitHub assigns.
- Your settings for each repository: review mode, branch filter, schedule, ignore patterns, and custom review rules.
Pull requests we review
- PR metadata: number, title, URL, author username, branch names, commit SHA, and the size of the change.
- The diff itself is fetched from GitHub when a review runs, sent for analysis, and not stored.
- The resulting findings: title, explanation, file path, line numbers, severity, suggested fix, and your decision on each.
- When you open a file in the Scrutio code viewer, its contents are fetched live from GitHub and not stored.
Billing and notifications
- Your plan, credit usage, and subscription and payment references from Razorpay. We never see or store your card or bank details.
- If you set them up: a Slack webhook URL (stored encrypted) and a notification email address.
Technical logs
- Request logs (method, path, status, timing, and your user ID when signed in), kept for security and debugging.
03How we use it
- To invite waitlist members and, occasionally, share launch updates (you can opt out at any time).
- To understand demand, for example which roles and team sizes are interested, using aggregate counts.
- To sign you in, run reviews, and show findings in your dashboard and on your pull requests.
- To track credits, process subscriptions, and send account-related messages.
- To keep the service secure, prevent abuse, and fix problems.
04AI processing
Reviews are generated by Anthropic's Claude models. For each review, Anthropic receives the pull request diff, the PR title and author username, the repository name, and any custom review rules you have written. It does not receive your account details or billing information.
Under Anthropic's commercial API terms, this data is not used to train their models. We do not use your code to train any model either.
05Service providers we rely on
We share data only with the providers needed to run Scrutio, and only for that purpose:
- GitHub: sign-in, repository access, and posting review summaries to your pull requests.
- Anthropic: AI analysis of pull request diffs.
- Razorpay: subscriptions and payments.
- Vercel and Render: hosting for our website and API.
- Our database and job-queue providers: storing account data and running reviews in the background.
- Slack: only if you connect it for notifications.
We do not sell personal data, and we do not share it with advertisers.
07How long we keep it
- Waitlist entries: until you are invited and for up to 12 months after launch, or until you ask us to remove you.
- Account data, reviews and findings: for as long as your account is active, so you keep your review history.
- Pull request diffs and file contents: never stored.
- When you ask us to delete your account, we remove your personal data within 30 days, unless the law requires us to keep it (for example, payment records).
08Security
All traffic is encrypted with HTTPS. Sensitive settings such as Slack webhook URLs are encrypted at rest. GitHub webhooks are verified by signature, access to repositories is limited to what you grant the GitHub App, and our API is rate limited.
No system is perfectly secure. We encourage you to protect your GitHub account with two-factor authentication. If you believe you have found a vulnerability, please email privacy@scrutio.dev.
09Your rights and choices
Depending on where you live, including under India's Digital Personal Data Protection Act, 2023 and the GDPR, you can ask us to:
- Show you the personal data we hold about you, and give you a copy.
- Correct anything inaccurate.
- Delete your data, or remove you from the waitlist.
- Stop using your data for launch updates, or withdraw consent you have given.
Email privacy@scrutio.dev from the address you used with us and we will respond within 30 days. You can also uninstall the Scrutio GitHub App at any time, which immediately ends our access to your repositories.
10International transfers
Some of our providers, including Anthropic and GitHub, process data outside India, mainly in the United States. We rely on providers that offer appropriate contractual safeguards for this.
11Children
Scrutio is a tool for professional developers and is not directed at anyone under 18. We do not knowingly collect data from children.
12Changes to this policy
If we make material changes, we will update the date above and let you know by email or in the product before they take effect.
13Contact
Questions or requests about your privacy: privacy@scrutio.dev.