\!DOCTYPE html>
Last updated: June 25, 2026
PullLight is an AI-powered code review tool that analyzes pull request diffs to identify security vulnerabilities and bugs. We access your code only through the GitHub API at your direction, and we never store full source files or credentials.
When you install and use PullLight, we receive and process:
PullLight explicitly does NOT collect, store, or transmit:
All diff data submitted to PullLight is used exclusively to run AI analysis and post review comments back to GitHub. We do not use your code to train, fine-tune, or improve our AI models. PullLight's AI analysis runs through Anthropic's Claude API — your code is processed by that service under their own privacy terms.
PullLight routes pull request diffs through Anthropic's Claude for analysis. This processing is governed by Anthropic's privacy policy. We do not retain the diff content after analysis completes — only the structured findings (severity, category, file, line) are stored to power the review queue and history.
Review findings (severity, category, file path, line number, and AI-generated description) are retained for 30 days after a review session completes, then automatically purged. Raw diff content is never stored. You can request immediate deletion of your organization's data at any time by emailing privacy@pulllight.io.
PullLight requests only the permissions it needs to function:
We do not request write access except to post review comments on pull requests you have already opened. Uninstalling the PullLight GitHub App immediately revokes all access.
PullLight does not use tracking cookies. We log anonymized server metrics (request counts, error rates, response times) for operational purposes only. We do not use third-party advertising trackers.
We do not sell, rent, or share your data with any third party outside of the services required to deliver the product (Anthropic for AI analysis, GitHub for API access). PullLight's public /caught feed shows sanitized, de-identified bug finding snippets with repository names — no personal data, no code content.
All data in transit is encrypted via TLS. Stored findings are encrypted at rest. GitHub App credentials are stored encrypted and rotated automatically on uninstall/reinstall.
PullLight is not intended for use by anyone under the age of 13. We do not knowingly collect data from children.
We will update this page if our data practices change. Changes will be posted here with an updated "Last updated" date. For significant changes, we will notify via the email associated with your installation.
For privacy concerns or data deletion requests:
privacy@pulllight.io