SiftPulse SiftPulse
Try demos Compare Blog Changelog ROI Enterprise Pricing Autonomous AI Install on GitHub →
Legal

Privacy Policy

Last updated: July 12, 2026

Contents

  1. Information We Collect
  2. How We Use Your Information
  3. Model Providers & Data Processing
  4. Data Retention
  5. Your Rights
  6. Data Security
  7. Cookies
  8. Third-Party Services
  9. Children's Privacy
  10. Changes to This Policy
  11. Contact Us

1. Information We Collect

SiftPulse is an AI-powered code review tool that operates as a GitHub App. We collect the following categories of information:

  • GitHub App installation data: Your GitHub user info (login, display name, avatar URL, and numeric account ID), your organization or account name, and the repository IDs you select for review. This is required to post review comments on your pull requests and verify authorship.
  • Pull request metadata: PR titles, numbers, authors, branch names, and file paths changed.
  • Code diffs (unified patches): The actual unified patch content of each pull request is sent to our AI provider at review time to generate findings. Raw diffs are processed in memory during review, are not retained by our AI provider, and are not stored permanently in our database.
  • Review event data: AI-generated review findings (blocker/suggestion/nit classifications), verdict labels, and review summaries. These are stored in our database to power your dashboard and activity feed.
  • Account and billing information: Email address and Stripe customer ID for subscription management. We do not store payment card details — those are handled entirely by Stripe.
  • Dashboard usage data: Pages visited, feature settings configured, and navigation patterns within your SiftPulse dashboard. This helps us improve the product.
  • Email address: Used for magic-link authentication, onboarding emails, and optional weekly digest or Slack notification configuration.

2. How We Use Your Information

We use the information we collect to:

  • Run AI code reviews on your pull requests and post structured findings back as GitHub comments
  • Power the SiftPulse dashboard — showing review history, DORA metrics, and settings
  • Send email notifications (weekly digest, first-review alerts, trial reminders, long-running PR sign-off requests) only if you have configured them
  • Manage your subscription (billing, trial periods, plan upgrades)
  • Improve the product through aggregated usage patterns, review-quality feedback, and feature adoption metrics. We do not share raw customer data for this purpose.
  • Respond to support requests submitted via hello@siftpulse.polsia.app

We do not sell, rent, or share your personal information with third parties for marketing purposes.

3. Model Providers & Data Processing

SiftPulse processes pull request code through AI models hosted by third-party providers. This section describes what is sent, retained, and not retained.

What we send: When a PR is opened or updated, SiftPulse sends the diff (unified patch format), file path names, and PR metadata (title, body, changed file count) to our AI provider via an API. This data is used solely to generate the code review.

No training: Our AI provider does not use data submitted via our API to train or improve their models.

No retention by AI provider: Under our arrangement with the AI provider, input data is processed and not retained beyond the immediate request. This is verified in our provider agreements.

Our own retention: Review findings (structured JSON: category, severity, file location, comment text) are stored in our database. The raw diff is not stored after review completes.

Current AI provider: SiftPulse currently routes AI requests through a Polsia-managed proxy to model infrastructure. You can request details on the specific model by emailing hello@siftpulse.polsia.app.

4. Data Retention

We retain personal information for as long as your SiftPulse account is active, or as needed to provide you services. Specifically:

  • Review events: Stored indefinitely while your account is active. You can request deletion of specific review event records by contacting us.
  • Account data: Retained for 2 years after account closure for tax and accounting purposes, then deleted.
  • Billing records: Retained for 7 years per financial record-keeping requirements.
  • Email addresses: Removed from our mailing lists within 30 days of account closure.
  • Digest preference: If you unsubscribe from the weekly digest, you remain opted out indefinitely.

5. Your Rights

Depending on where you reside, you may have the following rights regarding your personal data:

  • Access: Request a copy of all personal data we hold about you.
  • Correction: Request correction of inaccurate personal data.
  • Deletion: Request deletion of your account and associated data. We will comply within 30 days.
  • Portability: Request your data in a machine-readable format.
  • Objection: Object to processing for direct marketing purposes.

To exercise any of these rights, email hello@siftpulse.polsia.app with your request. We will respond within 30 days.

GDPR (EU/EEA): SiftPulse offers a Data Processing Agreement (DPA) for customers subject to GDPR. Request the DPA by emailing hello@siftpulse.polsia.app.

CCPA (California): California residents have the right to know what data we collect, delete it, and opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at the email above.

6. Data Security

We implement the following technical and organizational measures to protect your data:

  • All data in transit is encrypted with TLS 1.2+
  • Database credentials are stored as environment variables and never committed to code
  • Access to production systems is restricted to authorized personnel and requires authentication
  • AI API requests are made over encrypted channels with token-based authentication
  • GitHub installation tokens are stored securely and rotated per GitHub's token lifetime
  • Dashboard sessions use signed HTTP-only cookies with a 30-day expiration

7. Cookies

SiftPulse uses the following cookies:

  • sp_session — HTTP-only signed session cookie. Stores a cryptographic session token. Expires after 30 days of inactivity. No tracking or advertising cookies are used.

You can disable cookies in your browser, but this will log you out of the dashboard on each visit.

8. Third-Party Services

SiftPulse uses the following third-party services:

  • GitHub: The SiftPulse GitHub App runs inside your GitHub account and receives the data you authorize at install time (repos, PRs, comments). GitHub's privacy policy applies. github.com/privacy ↗
  • OpenAI (via the Polsia proxy): PR review completions are routed through a Polsia-managed proxy to OpenAI's API. Only the unified diff, file paths, and PR metadata are sent. OpenAI does not retain or train on this data. openai.com/privacy ↗
  • Anthropic (via the Polsia proxy): Where used, review requests route through the same Polsia proxy to Anthropic's API under Claude API Terms. Anthropic does not retain or train on input data. anthropic.com/privacy ↗
  • Stripe: Payment processing and subscription management. Stripe's privacy policy applies to all payment data. stripe.com/privacy ↗
  • Neon (PostgreSQL): Cloud database hosting. neon.tech/privacy ↗
  • Render: Cloud hosting for the SiftPulse application. render.com/privacy ↗
  • Postmark: Transactional email delivery. postmarkapp.com/privacy ↗
  • Plausible Analytics: Privacy-first website analytics. No cookies, no tracking, GDPR-compliant. plausible.io/privacy ↗

9. Children's Privacy

SiftPulse is not directed at or intended for use by anyone under 16 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child under 16, we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email to the address associated with your account and by posting a notice on our website at least 14 days before the change takes effect. Continued use of SiftPulse after a policy update constitutes acceptance of the new policy.

11. Contact Us

SiftPulse is operated by Polsia, Inc. For any privacy-related questions or to exercise your data rights:

Privacy inquiries & general contact: support@siftpulse.polsia.app
Data deletion requests: privacy@siftpulse.polsia.app
Vulnerability reporting: security@siftpulse.polsia.app

Samples Compare Customers Benchmark Enterprise Pricing Changelog Blog Security Status Support FAQ How it works ROI Calculator Privacy Terms
GitHub X LinkedIn
SiftPulse AI-powered PR review and issue triage — built for developer teams that move fast.