Privacy Policy
Last updated: August 2026
This policy explains what data Pullora collects, why, and how it is handled.
Data we collect
- Account data: your name, email address and avatar from Google when you sign in with Google OAuth.
- Repository data: Pull Request metadata, diffs and limited surrounding code context fetched on demand to perform a review you or your webhook configuration requested.
- Review data: the findings, summaries, statuses and usage records the Service produces.
- Billing data: subscription state and payment records from Razorpay. We never receive or store card numbers.
- Operational data: logs and metrics needed to run and secure the Service. Secrets and tokens are excluded from logs.
How code is processed
Code is fetched from your Git provider only to perform reviews. Relevant portions are sent to our AI providers under API terms that do not permit training on your data. We store review findings and metadata, not full repository copies.
Sharing
We share data only with the processors needed to operate the Service (cloud hosting, AI providers, Razorpay for payments, GitHub as your Git provider). We do not sell personal data.
Retention and deletion
Review data is retained while your workspace exists so you can browse history. Deleting your workspace deletes its data, subject to short backup retention windows and records we must keep for legal or accounting reasons.
Your rights
You may request access to, correction of, or deletion of your personal data by emailing privacy@pullora.ai. Depending on your jurisdiction you may have additional rights, which we will honor as required by applicable law.
Changes
We will post updates to this policy here and note the revision date above.