Privacy Policy
How ComplyLoop handles account, repository, and compliance data during early access.
Last updated: 2026-09-10
What we store
- GitHub account identity (user id, login) when you sign in
- Encrypted GitHub tokens (user OAuth or App installation tokens) for clone, PR, and Checks
- Ephemeral clones of connected repositories during assessment, remediation, and PR jobs (deleted after each job)
- Assessments, findings, remediations, exceptions, and append-only evidence for connected projects
Retention
Evidence is append-only and retained for audit history. Disconnecting a GitHub project removes project-scoped mutable records (requirements, assessments, findings, remediations, alerts) while its evidence rows remain. Deleting an organization erases everything, including its evidence history.
Export and deletion
Organization owners can download a machine-readable JSON export of org-scoped product data and delete the organization from the Organization page. Sign-out clears stored encrypted GitHub tokens for that user. Support-assisted deletion requests are handled within 30 days for early-access pilots — contact your pilot operator.
Subprocessors
Optional AI features send finding context to the configured AI gateway when AI_GATEWAY_API_KEY is set. Error reporting may send diagnostics to Sentry when a Sentry DSN is configured (SENTRY_DSN on the server, optionally NEXT_PUBLIC_SENTRY_DSN in the browser). Hosting and Postgres providers hold application data when you deploy with those services.