# Privacy Policy

Effective date: October 3, 2026

This policy covers the Upseam GitHub App, the setup and settings pages at
app.upseam.dev, the website upseam.dev with its documentation, and the
`upseam` command-line tool. Upseam is a free beta.

## Who is responsible

Upseam is run by Vladislav, an individual based in Russia, who
is the controller of the personal data described here. There is no company
behind Upseam yet. Contact: contact@upseam.dev.

## What Upseam processes

### When you install the GitHub App

Upseam reads, through GitHub and only for the repositories you select: code,
lockfiles and manifests, `.github/upseam.yml`, Upseam's own pull requests and
dashboard issue, Dependabot and Renovate pull requests, and your CI results.
To find affected code it downloads a repository archive into a temporary
directory; the archive is deleted when that step ends. Upseam does not store
your code, diffs, or pull request and issue bodies.

Upseam stores in its database:

- the installation: its id, the GitHub account or organization login and
  type, and your settings;
- the selected repositories: ids, names and default branches;
- what it found: SDKs, versions and API pins with file and line, matched
  places as path, line and symbol, and changes in your internal API contracts;
- its proposals: branch, commit, pull request number and CI status;
- approvals: the decision, the channel, and who decided, as a GitHub user id
  or, once Slack is available, a Slack workspace and user id;
- who connected a model: a GitHub login;
- if you connect them: your model vendor, model name, base URL and API key,
  and, if you connect Slack (not available yet), the Slack workspace and
  channel (ids and names) and bot token. The API key and the bot token are
  encrypted; for keys of 20 characters or more, the last four characters are
  kept in plain text as a hint;
- technical records: queued work, received GitHub webhook deliveries (their
  id, type and a hash of the body, not the body itself), and hashes of revoked
  sign-in sessions. Queued work made from a GitHub notice keeps what that work
  needs, which can include the account login, repository names, and the
  GitHub user id and login of the person who edited the dashboard issue.

Upseam writes to your repositories only what the App is for: commits to
branches named `upseam/*`, its own pull requests, comments that close its own
pull requests, comments on Dependabot and Renovate pull requests, the
dashboard issue, and, when you generate fixes in your GitHub Actions, a
`repository_dispatch` event. It never pushes to your default branch.

### When you sign in

The setup and settings pages use Sign in with GitHub. Your session is an
encrypted, `HttpOnly`, `Secure` cookie that holds your GitHub user id and
login and GitHub access and refresh tokens, for up to seven days. Upseam uses the token
to ask GitHub which installations you may see and change. While you sign in, a
second encrypted cookie, `__Host-upseam_github_oauth`, protects the sign-in
for up to ten minutes. Signing out ends the session and asks GitHub to revoke
the token.

### When you connect a model

Upseam writes fixes with the model vendor and the key you choose; it has no
model of its own. To write a fix, it sends your vendor the change data, the
paths and line numbers of the matched places and the complete content of the
files where the change was found. For a change in one of your internal API
contracts, the change data comes from your own OpenAPI or GraphQL contract.
With a stored key, it also sends style instructions taken from your
`.editorconfig` and Prettier settings (indentation, quotes, semicolons), not
the files themselves. Your vendor
processes that data under its own terms. If you generate fixes in your own
GitHub Actions, Upseam never sees your key and does not call the model.

### When you connect Slack

Slack is not available yet. If you connect Slack once it is, Upseam posts
messages about findings to the channel you pick. Messages name files and line
numbers, never code. Upseam does not read channel history. When someone
presses a button, Upseam checks with Slack that the person is a full member of
the workspace.

### Product analytics

Upseam records product events in its database, such as "installed", "change
ingested", "pull request opened" or "merged". They carry only ids, flags and
fixed values, never code, repository names or user logins. When this export is
enabled (it is off today), they are exported to PostHog with the installation
id replaced by a keyed hash and with IP geolocation switched off. Upseam keeps
them for 13 months; how long PostHog keeps them is set in PostHog.

### The website

The website sets no analytics or advertising cookies. It sets one cookie,
`upseam_privacy`, for six months, only if you press **Remember my choice** in
the privacy notice. If you switch the page sound on or off, the choice is
kept in your browser's local storage; it is not sent to us. The home page
has no forms. The documentation search box runs in your browser against a
local index; what you type in it is never sent to us.

The website and its documentation send pseudonymous usage events to PostHog
in PostHog's cookieless mode: website analytics set no cookies, use no local
or session storage and create no visitor profile. The events go to
upseam.dev/ingest, which forwards them to PostHog in the United States. They
record page views and page exits, Web Vitals, which sections of the home page
come into view, and clicks on links and buttons, such as calls to action,
the install link, code copy buttons, agent tabs, the sound switch, and links
to other sites, which record only the destination domain. Text and
attributes of the clicked elements are masked, so events never carry code or
anything you type. PostHog adds its standard properties, such as the page
address and title, referrer, browser and screen size. Clicks
also feed heatmaps and dead-click reports. Every event asks PostHog to skip
IP geolocation. PostHog uses your IP address to compute a daily cookieless
identifier; the PostHog project is set to discard client IP addresses, so the
address is not stored with the event. Session recording and
surveys are off. If your browser sends Do Not Track or Global Privacy Control,
the analytics code does not load and no event is sent.

### Hosting logs

Our hosting provider, Vercel, processes request data such as IP addresses,
user agents and requested URLs, for the website and for app.upseam.dev: the
sign-in and settings pages, whose URLs contain the installation id, and the
GitHub notices, and Slack notices once Slack is available, sent to Upseam. How
long these logs are kept is set by the host.

### Email

If you write to contact@upseam.dev, we keep your message and address to
answer you.

### The command-line tool

The `upseam` CLI runs on your machine or in your CI. It sends nothing to
Upseam. Some commands contact GitHub, your model vendor or TypeSafe with your
own credentials; which ones is listed in [The CLI](trust.md#the-cli).

## Why Upseam processes it

- To provide the service you installed: finding API changes that affect your
  code and proposing fixes. This is necessary to perform our agreement with
  you ([Terms of Service](terms.md)).
- To keep the service secure and working: sessions, webhook checks, queued
  work. This is our legitimate interest in running a reliable service.
- To understand how the product and the website are used, with pseudonymous
  product and website events. This is our legitimate interest in improving
  Upseam.
- To answer your email.

Upseam does not sell personal data, show ads or use your code to train
models.

## Who receives it

- **GitHub**, where your code and the App live.
- **Vercel**, which hosts Upseam and the website. The App runs in the United
  States (Washington, D.C. region); the website is served from Vercel's
  global edge network.
- **Neon**, which hosts Upseam's database on AWS in the United States
  (us-east-1).
- **The model vendor you choose**, as described above.
- **Slack**, if you connect Slack (not available yet).
- **PostHog**, for the pseudonymous website events and, when the product
  event export is enabled (it is off today), product events, in the United
  States.
- **Spacemail**, which hosts the contact@upseam.dev mailbox.

TypeSafe labels vendor changelog entries when Upseam collects them; none of
your data is sent to TypeSafe by the App.

We may also disclose data if the law requires it.

## International transfers

Upseam's services and the providers above are mainly in the United States. If
you are outside the United States, your data is transferred there. Where the
law requires it, we rely on the providers' standard contractual clauses or
equivalent safeguards.

## How long it is kept

- Installation data stays while the App is installed.
- Product events: 13 months in Upseam's database; once the export is enabled
  (it is off today), PostHog's retention is set in PostHog.
- Website events: as set in PostHog; Upseam does not store them.
- Records of finished or abandoned work: 30 days.
- Records of received webhook deliveries: 14 days.
- Hosting logs: as set by the host.
- Hashes of revoked sessions: until the session would have expired.
- Repository archives: only during a processing step.

When GitHub tells Upseam the App was uninstalled, Upseam deletes the
installation with its repositories, findings, settings, stored model key and
Slack link, deletes its product events and, when the export is enabled (it is
off today), asks PostHog to delete them too.
It keeps the installation id with the time of removal indefinitely, so that
late GitHub notices do not bring the installation back, and a marker with the
installation id for 13 months, so that late product events are not exported.
Records of queued work and received webhook deliveries are not part of that
deletion; they follow the periods above.
If you connected Slack (not available yet), uninstalling does not revoke the
Slack bot token with Slack: press **Disconnect Slack** first, or remove the
app from your Slack workspace.

## Your rights

Depending on where you live, you may ask to access, correct, delete or
receive a copy of your personal data, to restrict or object to its
processing, and to withdraw consent. Write to contact@upseam.dev from the
email address linked to your GitHub account, or name the installation, and we
will answer within 30 days. The fastest way to delete an installation's data
is to uninstall the App. You may also complain to your data protection
authority.

## Security

Keys and tokens are encrypted in the database, every installation's rows are
separated by the database itself, and GitHub installation tokens are kept only
in memory. Details: [Security model](security.md).

## Children

Upseam is a tool for software developers and is not meant for anyone under
16. We do not knowingly collect data from children.

## Changes

We will post changes on this page and update the effective date. For
significant changes we will announce them on the website before they apply.
