Privacy Policy

Last updated: May 2026

1. What We Collect

When you sign in with GitHub, we receive your public profile information (name, email, avatar) and an access token scoped to the repositories you authorize. We store your user profile and the list of repositories you enable for review.

2. How We Use Your Code

MicroReview only reads the changed lines (diff hunks) from your pull requests — never your entire codebase, commit history, or branches. Diff data is sent to our AI provider (OpenAI) for analysis. Your code is not used to train AI models, is retained by the provider for at most 30 days for abuse monitoring and then deleted, and is encrypted in transit.

3. Data Storage

Review metadata (risk scores, finding counts, rule names) is stored in our database to power your dashboard and analytics. The actual source code from your diffs is not persisted after the review is complete.

4. Third-Party Services

We use GitHub OAuth for authentication, OpenAI for AI analysis (diffs only — not used for training), and Google Analytics for anonymous website usage statistics. We do not sell your data to any third party.

5. Data Security

All data is encrypted in transit using TLS/HTTPS. Our GitHub App requests only the minimum permissions needed: read access for PR diffs and write access for posting review comments and check runs.

6. Your Rights

You can revoke MicroReview's access to your repositories at any time via your GitHub settings. To request deletion of your account and all associated data, email us at hello@microreview.dev.

7. Contact

For privacy-related questions, reach out to hello@microreview.dev.