Privacy Policy
Last updated 2026-08-02
Draft, not legal advice. This page is a first draft written to be plain and accurate about what PatchPilot actually does today. It has not been reviewed by a lawyer. Have it checked before relying on it with real users.
What we store about you
When you sign in with GitHub OAuth, we store your GitHub user ID, login (username), and avatar URL, plus a signed session cookie used to keep you logged in. We do not receive or store your GitHub password.
What the GitHub App can access
The PatchPilot GitHub App only accesses repositories it has been explicitly installed on and granted access to -- installing it on one repository does not give it access to any others. Its permissions are scoped to what it needs to do its job: read issues, read repository metadata, write repository contents (to push a fix branch), and write pull requests (to open a draft PR).
What gets sent to a third-party LLM provider
To analyze an issue and propose a fix, PatchPilot sends relevant repository content (file contents, issue text, diffs, command output) to a third-party large language model provider -- OpenAI or Anthropic, depending on which model is configured -- for processing. That provider's own privacy policy and data-handling terms apply to what happens to that data on their side.
How long we keep run and log data
Run records (status, commands executed, test results, token usage, patches produced) and log/artifact files are retained so runs stay debuggable and auditable. As of this writing there is no automated expiry -- data is kept indefinitely unless manually deleted. If that changes, this page will be updated.
Billing
If billing is enabled, Stripe processes payments and handles your payment details directly -- PatchPilot does not receive or store your card number. We store the minimum billing metadata needed to associate your workspace with a Stripe customer and subscription (e.g. plan tier, subscription status).
Questions
This is an early private beta. If you have questions about data handling, contact the person who invited you.