Privacy

Privacy policy.

Last updated 2026-05-27. We process the minimum needed to make the product work, and we tell you exactly what that is. This policy is written to be read end-to-end.

Data controller

The controller for personal data processed in the context of the Acuvis service is Paweł Lisowski, ul. Słoneczna 12, 76-200 Bierkowo, Polska, NIP 8393198485, REGON 368330844. Contact: privacy@acuvis.dev. Full operator details are on the imprint page.

Categories of data we process

  • Account data — your GitHub or Google identifier, display name, email, avatar URL, and the organisations and teams you belong to inside Acuvis.
  • Repository metadata — the repositories you grant access to, branch names, pull request titles, descriptions, head/base SHAs, file paths, and the diff hunks of the changes under review.
  • Collaboration data — comments and reactions you author inside Acuvis, draft state, seen-state, navigation events that drive the resolution continuum.
  • Audit and security data — the hash-chained audit log, sign-in events, IP address and user-agent at sign-in time, webhook delivery records.
  • Billing data — when applicable, the Stripe customer identifier, plan, invoice history, and the country of the billing address used for VAT determination. Card numbers are held by Stripe; we never see them.
  • Operational data — request logs, error events captured by our in-house tracker, and aggregated usage metrics.

Source code handling

Source code is never persisted in any database. Diff content lives in the analysis sandbox's volatile memory for the duration of the analysis and is destroyed when the Firecracker microVM is torn down. The review document stored in our database holds the structural summary (clusters, files, hunks as references) and the diff text needed to re-render the review in the IDE — scoped to your organisation, never replicated to analytics, archives, or anywhere else.

Legal basis for processing

  • Performance of a contract (Art. 6(1)(b) GDPR) — account data, repository metadata, collaboration data, billing data. We need these to deliver the service you signed up for.
  • Legitimate interest (Art. 6(1)(f) GDPR) — audit log, security data, error tracking, fraud prevention, basic aggregate analytics. The interest is keeping the service secure and operable; the processing is the minimum needed for that.
  • Legal obligation (Art. 6(1)(c) GDPR) — invoice and tax records retained per Polish accounting law, breach notifications, lawful authority requests.
  • Consent (Art. 6(1)(a) GDPR) — only where we ask for it, e.g. optional marketing emails. You can withdraw consent at any time.

Retention

  • Account data — for the life of the account, deleted within 30 days of account closure.
  • Review documents — for the life of the org, or 12 months from the last access if the org becomes inactive. Earlier deletion on request.
  • Audit log — retention by plan: 90 days on Free, 12 months on Team, 10 years on Scale (for customers under SOX/HIPAA/PCI obligations).
  • Error events — 30 days, then automatically purged. Issue records (dedup keys with counts) are kept while the issue is open and 90 days after resolution.
  • Backups — encrypted database snapshots are retained for 30 days, then automatically deleted.
  • Invoices and tax records — 5 years from the end of the relevant tax year (Polish statutory minimum).

Sub-processors and international transfers

We use a small number of sub-processors to deliver the service. The complete list, including each sub-processor's jurisdiction and the legal mechanism for any transfer outside the EEA, is published at /sub-processors. For transfers to the United States we rely on the EU Standard Contractual Clauses (Commission Decision 2021/914) with supplementary measures where appropriate. We notify customers at least 30 days before adding or replacing a sub-processor.

AI inference provider

Prompts to the language model include diff hunks and the structural metadata the model needs to reason about the change. We route through Fireworks AI under a signed Data Processing Addendum: zero retention by default, no training on customer prompts, SOC 2 Type II and HIPAA-compliant. The review you see is the model's constrained output validated against our JSON schemas before display. Because the model output materially influences which issues you triage first, this constitutes automated processing within the meaning of Art. 22 GDPR; however the output is advisory — a human always merges or rejects the pull request, and we do not take any decision producing legal effects without human involvement.

Cookies and similar technologies

The marketing site at acuvis.dev sets a small number of strictly-necessary cookies only (preference for theme, anti-CSRF). The application at app.acuvis.dev sets a session cookie (HttpOnly, SameSite=Strict) for authentication and a state cookie during OAuth sign-in. We use Cloudflare Web Analytics, which counts page views via HTTP-only sampling and does not set any cookie or fingerprint identifier. We do not embed third-party advertising, marketing pixels, or session replay tooling.

Your rights under GDPR

You have the right to access your personal data, to have inaccurate data corrected, to have data erased, to have processing restricted, to data portability, and to object to processing based on legitimate interest. You can exercise most of these directly inside the product (export, delete); for anything else, mail privacy@acuvis.dev and we will respond within 7 days, at most 30 days as permitted by Art. 12(3) GDPR.

You also have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych — UODO), at ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl, or with the supervisory authority of the EU member state where you live or work.

Security and breach notification

Technical and organisational measures are summarised on the security page. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify UODO within 72 hours and notify affected users without undue delay, in line with Art. 33 and 34 GDPR.

Changes to this policy

We publish the date at the top of the page each time the policy changes. Material changes — new data categories, new sub-processors, new processing purposes — are announced by email to organisation owners at least 30 days in advance. Trivial corrections (typos, clearer wording) take effect immediately on publication.

Contact

privacy@acuvis.dev for privacy questions, data subject requests, or DPA negotiations. Operator details, including registration numbers, are on the imprint page.