Privacy
last updated 2026-07-24
Short version: we store your account, the documentation we generated, and counters. We do not store your source code, we do not train on it, and there are no advertising or analytics trackers anywhere on this site. Deleting your account deletes your data.
What we store
- Account — your email, your name if Google gave us one, and a password hash if you set one.
- Projects — the repository URL, the generated overview and its previous versions, your steering notes, and the statements you have hidden.
- Dependencies — the package and version list read from your lockfiles, so we can check it against public vulnerability and end-of-life data.
- Credentials — your AI provider key, encrypted at rest; agent tokens, stored as hashes we cannot reverse; GitHub App installation ids.
- Counters — token usage and cost per generation, and view counts on your share pages.
What we do not store
Your source code. To write an overview we read files from your repository, assemble them in memory, send them to the AI provider you chose, and keep the answer. The file contents themselves are never written to our database or our logs. What persists is the description, the commit SHA it was written from, and the dependency list.
We also do not store payment details — there is nothing to pay for yet — and we run no advertising, analytics, or fingerprinting scripts. The only cookie we set is the session cookie that keeps you logged in, plus the CSRF token that stops other sites posting forms as you. Neither is used to track you anywhere.
Training
We do not train models. We do not have any. Your code and your documentation are never used to improve any model of ours, and are never sold or shared for anyone else's training. What the AI provider you selected does with the requests you send through your own key is governed by your agreement with them — if that matters to you, read their terms, because you chose them and you are their customer, not us.
Who else sees data
We use a small number of processors, each for one job:
- The AI provider you pick (Anthropic, OpenAI, Google, xAI or DeepSeek) — receives repository content in order to write your overview, under your own key.
- GitHub — where your repositories already live; we read them through an App you install.
- Resend — sends the few transactional emails we send.
- Sentry — receives error reports when something breaks, which can include the URL and your account id.
- Cloudflare — DNS and network in front of the site, and encrypted off-site backup storage.
- Google — only if you choose to sign in with Google, which tells us your email and name.
Nobody else. We do not sell data, and there is no third party receiving it for their own purposes.
Where it lives
Application servers and the database are in Germany (EU). Backups are encrypted before they leave the machine and stored with Cloudflare R2. Where a processor operates outside the EU, transfers rely on standard contractual clauses or an adequacy decision.
How long we keep it
- Account and project data — until you delete them.
- Deleted projects — 30 days in trash, then permanently purged.
- Overview history — the last 20 versions of each project.
- Backups — daily copies for two weeks, weekly copies for two months, then gone.
Deleting your account removes your projects, your steering notes, your stored provider keys and your agent tokens immediately. Backups already taken expire on the schedule above.
Your rights
Under the GDPR you can ask for a copy of your data, ask us to correct or delete it, object to processing, or ask us to hand it to someone else. Deletion you can do yourself in settings, instantly. For anything else, email hello@donotedit.io and you will get a real answer from a person within a month. If you think we have handled your data badly, you can complain to your national data protection authority.
Security
Provider keys are encrypted at rest, agent tokens are stored only as hashes, and share pages can be locked behind a passphrase. Backups are encrypted, taken nightly, and a restore is actually performed and verified every week rather than assumed to work. None of this makes us unbreakable; if we ever do suffer a breach affecting your data, we will tell you.
Who is responsible
The data controller is MB Nexus consulting, Leičių g. 17-20, LT-12109 Vilnius, Lithuania. Contact: hello@donotedit.io.