1. Overview
This Privacy Policy explains how TeraCodeAI collects, uses, and protects information when you use the TeraCodeAI service — a bring-your-own-key multi-agent pull request review product (GitHub App and dashboard). By using the Service, you agree to the practices described here.
2. Information We Collect
Account information. When you sign in with GitHub we receive the identity GitHub shares for that OAuth flow — typically your GitHub user id, login, and email. We use that to create a session and to know which installations and repositories you may see.
Repository content. To review a pull request we receive the forge webhook, then — unless the project turns checkout off — shallow-clone the pull request head into an ephemeral sandbox so agents can read files, search, and list directories. We also receive the diff, metadata (title, author, SHAs), review comments, and check-run results. Nothing from the repository is executed in the sandbox: no install, no build, no tests.
Credentials you supply. Model provider API keys (Anthropic or OpenRouter) are stored encrypted at rest and used only to call that provider from the host process. The key does not enter the sandbox. GitLab project access tokens, if you connect a GitLab project, are stored the same way and used to read the project and post the review.
Review artifacts. We store review runs, agent findings, comments posted, check outcomes, and what became of each finding (resolved, deleted, or left open) so the dashboard can show a journal and a keep-rate.
Usage information. We record that a review ran, which agents ran, token counts or cost the provider reported, and similar operational events. We collect ordinary device information such as browser type and IP address on the dashboard.
3. How We Use Information
We use this information to run the reviewers you configured, post findings and status checks on the pull request, show the dashboard, enforce the repository meter, respond to support requests, send account notifications you asked for, and monitor for security and abuse. We do not build a knowledge graph of third-party business data sources, and we do not use your repositories to train a public model.
4. Data Sharing
We do not sell your data. Prompts and code excerpts needed for a review are sent to the model provider whose key you supplied, and are subject to that provider's terms. We may share information with infrastructure providers who host the dashboard, database, and sandboxes, under confidentiality obligations, or when required by law. GitHub or GitLab receive the comments and checks the Service posts because that is the product.
5. Sandboxes and keys
Repo-aware review boots a sandbox, clones the pull request head, and gives agents read-only file tools. Egress from the sandbox is allow-listed to the forge. The model is called from the host, not the sandbox, so your provider key never enters the VM. A sandbox that fails to start degrades that review to the diff only; it does not fail the review silently.
6. Data Security
We use industry-standard safeguards, including encryption in transit and at rest for stored keys and tokens. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Data Retention
We retain account, project, and review history for as long as the organization uses the Service. Disconnecting a repository is intended to stop new reviews; billing history is kept so an invoice can still be explained. Upon account cancellation, data is deleted from our systems within 30 days, except where retention is required by law.
8. Your Rights
Depending on your location, you may have the right to access, correct, export, or delete your personal information. To exercise these rights, contact us using the information below.
10. Children's Privacy
TeraCodeAI is not directed to individuals under the age of 16. We do not knowingly collect personal information from children.
11. International Transfers
Your information may be transferred to and processed in countries other than your own. We take steps to ensure appropriate safeguards are in place for such transfers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
13. Contact
Questions about this Privacy Policy can be sent to contact@teracodeai.com.