What Codzee reads
Codzee works through a GitHub App that you install on the repositories you choose. When a pull request is opened or updated, it reads the changes and the surrounding code needed to review them. You can change which repositories it can see, or uninstall it, at any time in GitHub.
What Codzee keeps, and what it doesn’t
- No copies of your repositories. Code is read to produce a review, not stored as a copy.
- Review history. We keep pull request titles, file paths and the reviews themselves, so your dashboard has history. Review comments can quote short code excerpts and suggested fixes.
- No Ask Codzee transcripts. We keep usage counts, not the questions or answers.
- No card details. Payments are handled entirely by Stripe.
Our Privacy Policy lists everything we collect and how long we keep it.
What Codzee never does
- Push code, merge pull requests, or change your repository settings.
- Let AI models be trained on your code.
- Sell your data or use it for advertising.
GitHub App permissions
These are the permissions the Codzee GitHub App requests, and why:
| Permission | Why Codzee needs it |
|---|---|
| Contents: read | To read the code in your pull requests |
| Pull requests: read & write | To post review comments and request reviewers |
| Checks and Commit statuses: read & write | To show the review result on the pull request |
| Administration: read | Only to read branch protection rules, so approval suggestions match what you already enforce |
The app has no access to GitHub Actions, secrets or organization settings.
Sign-in permissions
Signing in to the dashboard with GitHub is separate from the app. It asks for your profile and email, your organization memberships, and access to repositories, which GitHub describes as “full control of private repositories” because that is the narrowest option GitHub offers for private repositories. Codzee only reads with it, to show you the repositories and activity you have access to, and never writes. We are working on narrowing this.
AI processing
Code changes are sent to Anthropic’s API to produce reviews. Under Anthropic’s commercial terms, this data is not used to train its models. Anthropic may keep it for a limited period under its own policies, for example for trust and safety.
Infrastructure and encryption
- Hosted in the United States on Railway, Vercel and Neon.
- All traffic to and from Codzee is encrypted in transit with HTTPS/TLS.
- Our database provider encrypts stored data at rest.
- Integration tokens, such as a connected Slack workspace’s, are encrypted with AES-256-GCM before they are stored.
- Dashboard sessions are kept in encrypted cookies.
- Access to production systems and data is limited to the people at Codzee who need it.
Your controls
- Choose exactly which repositories Codzee can see, in GitHub.
- Pause reviews at any time in Settings.
- Delete a repository’s review data at any time from the dashboard.
- Uninstall the GitHub App at any time; to delete your whole account, email support@codzee.io.
Reporting a vulnerability
If you believe you have found a security issue, email support@codzee.io with “Security” in the subject. We will acknowledge your report and keep you updated. We will not take legal action against research done in good faith that avoids accessing other people’s data, respects their privacy, and does not disrupt the Service. Please give us reasonable time to fix an issue before disclosing it publicly.
Compliance
Codzee does not yet hold third-party certifications such as SOC 2. A Data Processing Agreement (DPA) is available on request: email support@codzee.io.