<\!DOCTYPE html> Privacy Policy — PullLight

Privacy Policy

Last updated: June 25, 2026

Overview

PullLight is an AI-powered code review tool that analyzes pull request diffs to identify security vulnerabilities and bugs. We access your code only through the GitHub API at your direction, and we never store full source files or credentials.

What Data We Collect

When you install and use PullLight, we receive and process:

What We Do NOT Store

PullLight explicitly does NOT collect, store, or transmit:

How We Use Your Data

All diff data submitted to PullLight is used exclusively to run AI analysis and post review comments back to GitHub. We do not use your code to train, fine-tune, or improve our AI models. PullLight's AI analysis runs through Anthropic's Claude API — your code is processed by that service under their own privacy terms.

AI Data Processing

PullLight routes pull request diffs through Anthropic's Claude for analysis. This processing is governed by Anthropic's privacy policy. We do not retain the diff content after analysis completes — only the structured findings (severity, category, file, line) are stored to power the review queue and history.

Data Retention

Review findings (severity, category, file path, line number, and AI-generated description) are retained for 30 days after a review session completes, then automatically purged. Raw diff content is never stored. You can request immediate deletion of your organization's data at any time by emailing privacy@pulllight.io.

GitHub Permissions

PullLight requests only the permissions it needs to function:

We do not request write access except to post review comments on pull requests you have already opened. Uninstalling the PullLight GitHub App immediately revokes all access.

Cookies and Tracking

PullLight does not use tracking cookies. We log anonymized server metrics (request counts, error rates, response times) for operational purposes only. We do not use third-party advertising trackers.

Data Sharing

We do not sell, rent, or share your data with any third party outside of the services required to deliver the product (Anthropic for AI analysis, GitHub for API access). PullLight's public /caught feed shows sanitized, de-identified bug finding snippets with repository names — no personal data, no code content.

Security

All data in transit is encrypted via TLS. Stored findings are encrypted at rest. GitHub App credentials are stored encrypted and rotated automatically on uninstall/reinstall.

Children's Privacy

PullLight is not intended for use by anyone under the age of 13. We do not knowingly collect data from children.

Changes to This Policy

We will update this page if our data practices change. Changes will be posted here with an updated "Last updated" date. For significant changes, we will notify via the email associated with your installation.

Contact

For privacy concerns or data deletion requests:
privacy@pulllight.io