Privacy
How DeltaLabs handles account, repository, and service data.
Information we receive
- Account data. GitHub may provide your username, name, email address, avatar, and authentication identifiers.
- Repository data. The GitHub App provides access to repositories you select, including source code, metadata, commits, and pull request context.
- Service data. We store repository metadata, runs, candidates, invariants, gate results, settings, and related usage records.
- Integration data. If you connect Slack or another integration, we receive the identifiers and settings needed to operate it.
- Operational data. We receive logs, diagnostics, request details, and security events needed to run and protect the service.
How we use information
We use this information to authenticate users, analyze selected repositories, produce and enforce invariants, deliver notifications, support users, diagnose failures, prevent abuse, and secure DeltaLabs.
Repository and model processing
Workers create a scoped, temporary working copy of repository code for each run. These copies are not used as long term storage. Selected code context may be sent to commercial model and embedding providers to generate and compare invariant candidates. DeltaLabs does not opt customer code into model training.
How we share information
We share information with infrastructure, authentication, model, and integration providers only as needed to operate DeltaLabs. This includes services such as GitHub, Supabase, Vercel, Anthropic, embedding providers, and Slack when connected. We may also disclose information when required by law or needed to protect users and the service.
We do not sell personal information or use customer code for advertising.
Retention
We keep account and service records while needed to provide, secure, and support the service. Repository working copies are transient. Derived records such as invariants, run results, and logs may remain until account closure, a verified deletion request, or a longer period required for security or legal reasons.
Cookies
DeltaLabs uses session cookies for sign in and a preference cookie for organization selection. We do not use advertising cookies or cross site advertising trackers.
Your choices
You can revoke repository access through GitHub and disconnect optional integrations in DeltaLabs. Depending on where you live, you may also have rights to access, correct, export, or delete personal information. During private beta, make a request through the private channel used for your access.
Security and changes
We use technical and organizational safeguards appropriate to the service, but no system is perfectly secure. We may update this policy as DeltaLabs changes and will revise the date above when we do.