Your data,
plainly explained.
This policy describes what Rotwise collects when you use rotwise.io and the Rotwise application, why we collect it, who we share it with, and the choices you have. If anything here is unclear, email hello@rotwise.io.
What we collect
- Account details. Your name, email address, and either a password stored as a salted hash or the single-use tokens behind magic-link sign-in.
- Organization and billing. Your organization name, plan, trial dates, and the Stripe customer and subscription identifiers. Card details go directly to Stripe. We never see or store full card numbers.
- GitHub installation. The installation identifier, the GitHub account it belongs to, the repositories you selected, and an installation access token that we encrypt at rest.
- Scan results. File paths, code metrics, findings with short code excerpts, debt scores, proposed diffs, and links to the pull requests we open for you.
- Activity. An audit log of actions taken in your account, such as scans started, batches approved, and plan changes, with timestamps.
- Technical data. IP address, browser type, and server logs that we keep for security and debugging.
What happens to your source code
When you start a scan, Rotwise clones the selected repository into an isolated worker, analyzes it, and deletes the clone when the job finishes. We do not keep a copy of your repository. Short excerpts appear inside findings and proposed diffs so you can review them, and those stay in your account until you remove the repository or delete your account.
Relevant code is sent to Anthropic for AI analysis and fix generation under a zero-retention data processing agreement. It is not used to train models and is not retained after the request completes. We do not send your code to any other AI provider. The security page describes these boundaries in more detail.
How we use information
- To provide and operate the service, including running scans, generating fixes, and opening pull requests you approve.
- To send emails about your account and your scans, such as sign-in links, scan completion, and pull request updates.
- To bill you for paid plans and enforce plan limits.
- To keep the service secure, prevent abuse, and debug problems.
- To answer support requests.
- To understand how the product is used, in aggregate, so we can improve it.
We do not sell personal data, and we do not use it for advertising.
Who we share it with
We rely on a small number of service providers that process data only on our instructions:
- GitHub for repository access and pull requests.
- Anthropic for AI analysis under a zero-retention agreement.
- Stripe for payments and subscription management.
- Amazon Web Services for transactional email through Amazon SES.
- Our hosting provider for servers, databases, and short-lived scan workers.
We may also disclose information when required by law or to protect the rights and safety of Rotwise and its users.
Cookies
Rotwise sets only the cookies needed to keep you signed in and to protect forms against forgery. We do not use advertising cookies or cross-site tracking.
How long we keep data
Account and organization data is kept while your account is active. Scan results are kept until you remove the repository or delete your account. Audit logs and server logs are kept for up to twelve months. When you ask us to delete your account, we remove your data within thirty days, except where we are required to keep it for legal or accounting reasons.
Your rights
You can access, correct, export, or delete your personal data at any time by emailing hello@rotwise.io. If you are in the European Economic Area, the United Kingdom, or California, you have additional rights under local law, including the right to object to certain processing and to lodge a complaint with your supervisory authority.
International transfers
Our service providers may store and process data outside your country. Where that happens, we rely on standard contractual clauses or equivalent safeguards.
Children
Rotwise is a tool for software teams and is not directed at children under sixteen. We do not knowingly collect their data.
Changes to this policy
We will post any changes on this page and update the date at the top. If a change materially affects how we handle your data, we will email account owners before it takes effect.