PatchPilot

Privacy Policy

What we store about you

When you sign in with GitHub OAuth, we store your GitHub user ID, login (username), and avatar URL, plus a signed session cookie used to keep you logged in. We do not receive or store your GitHub password.

What the GitHub App can access

The PatchPilot GitHub App only accesses repositories it has been explicitly installed on and granted access to -- installing it on one repository does not give it access to any others. Its permissions are scoped to what it needs to do its job: read issues, read repository metadata, write repository contents (to push a fix branch), and write pull requests (to open a draft PR).

What gets sent to a third-party LLM provider

To analyze an issue and propose a fix, PatchPilot sends relevant repository content (file contents, issue text, diffs, command output) to a third-party large language model provider -- OpenAI or Anthropic, depending on which model is configured -- for processing. That provider's own privacy policy and data-handling terms apply to what happens to that data on their side.

How long we keep run and log data

Run records (status, commands executed, test results, token usage, patches produced) and log/artifact files are retained so runs stay debuggable and auditable. As of this writing there is no automated expiry -- data is kept indefinitely unless manually deleted. If that changes, this page will be updated.

Billing

If billing is enabled, Stripe processes payments and handles your payment details directly -- PatchPilot does not receive or store your card number. We store the minimum billing metadata needed to associate your workspace with a Stripe customer and subscription (e.g. plan tier, subscription status).

Questions

This is an early private beta. If you have questions about data handling, contact the person who invited you.