Legal
Privacy policy
This notice explains how DiffAtlas handles personal data on its website and code-analysis application.
Last updated: 9 August 2026
1. Data controller
DiffAtlas is the data controller for the processing described below. You can contact the controller, including to exercise your data-protection rights, at [email protected].
2. Data, sources, purposes, and legal bases
| Data and source | Purpose | Legal basis |
|---|---|---|
| GitHub name, email address, profile image, account identifier, and encrypted authorization credentials, provided by GitHub when you sign in. The GitHub App requests read-only account access to your email address and read-only repository access to pull requests and contents for repositories on which you install it. | Create and secure your account, authenticate you, and request the pull-request data you submit | Performance of the service contract (GDPR Art. 6(1)(b)) |
| Repository and pull-request information requested by you: repository name, pull-request number, title, URL, head commit identifier, changed-file names and statistics, available text patches, generated dependency graph, analysis status, and analysis timestamps | Process the pull-request changes, display file diffs, generate the dependency graph you request, and let you reopen recent analyses | Performance of the service contract (GDPR Art. 6(1)(b)) |
| Session identifier, expiry, IP address, user agent, request identifiers, and technical logs generated when you use the service | Maintain sessions, protect the service, prevent abuse, and diagnose failures | Legitimate interest in providing a reliable and secure service (GDPR Art. 6(1)(f)) |
| Your email address and message, supplied when you contact us | Answer your question or rights request | Legitimate interest, steps taken at your request, or compliance with a legal obligation, depending on the request |
The marketing website does not use analytics, advertising trackers, or contact forms.
3. Is the data required?
GitHub account, authorization, and pull-request data are required to provide DiffAtlas. If you do not authorize this access, you can browse the marketing website but cannot use the application’s analysis features. Contact messages are optional, although we need a reply address to answer by email.
4. Recipients and processors
Access is limited to the DiffAtlas operator and the providers needed to run the service:
- Railway Corporation, 548 Market St, Suite 68956, San Francisco, California 94104, United States, provides application and database infrastructure.
- Cloudflare, Inc., 101 Townsend St, San Francisco, California 94107, United States, provides domain registration, authoritative DNS, proxy, content-delivery, and network-security services.
- GitHub, Inc. provides OAuth authentication and repository data through its API.
We do not sell personal data or share it with advertisers.
5. Transfers outside the EEA
Railway, Cloudflare, and GitHub are established in the United States and may process data outside the European Economic Area. Where GDPR transfer rules apply, transfers rely on an applicable adequacy decision or appropriate safeguards such as the European Commission’s standard contractual clauses. Further details are available in Railway’s privacy policy, Cloudflare’s privacy policy, and GitHub’s privacy statement.
6. Limited use of repository data
We use repository and pull-request information only to provide or improve DiffAtlas’s disclosed diff and dependency-graph features, operate and secure the service, and comply with law. We use the GitHub token associated with your account to request pull-request metadata, changed files, and a temporary source archive for the pull-request link you submit. Private repositories are accessible only when you can access the repository and the GitHub App is installed for it. These requests are subject to GitHub’s access controls and API rate limits. DiffAtlas requests read-only access to pull requests and repository contents and does not request repository write, organization administration, workflow, or gist permissions. We do not use or transfer repository data for personalized advertising, creditworthiness, or lending purposes. We do not permit humans to read repository data unless you give specific consent for support, access is necessary for security or legal compliance, or the data has been aggregated and anonymized for internal operations.
7. Retention
- Account data and encrypted GitHub credentials are retained while your account remains active. They are deleted when you request account deletion, except for data that must be retained by law or temporarily remains in protected backups.
- For each analysis, we store the repository and pull-request metadata, changed-file metadata, any text patches GitHub provides, the generated dependency graph, analysis status, and timestamps. These analysis records are scheduled for deletion 30 days after creation; the deletion job runs daily. Full repository source is extracted only to a temporary working directory to generate the graph and is deleted when that analysis job finishes or fails.
- Sessions are retained until they expire or are revoked.
- Technical and security logs are retained only as long as needed to investigate incidents, maintain security, and meet legal obligations. The period is determined by the nature and severity of the event.
- Contact messages are retained for up to three years after the last exchange, unless the request requires a different legal retention period.
You may request deletion of a stored analysis record, including its stored patches and graph, at any time by emailing [email protected]. We process deletion requests without undue delay and normally within one month. That period may be extended where permitted by law for a complex or numerous request, and we will inform you if an extension is needed.
8. Cookies
The website does not place non-essential cookies. The application uses a strictly necessary authentication cookie to keep you signed in. It is not used for advertising or audience measurement.
9. Your rights
Depending on the legal basis and circumstances, you may request access to, correction or deletion of your data, restriction of processing, or data portability. You may object to processing based on legitimate interests.
Send your request to [email protected]. We normally respond within one month. We may request only the additional information needed to verify your identity.
You may lodge a complaint with your local supervisory authority. In France, this is the Commission nationale de l’informatique et des libertés (CNIL).
10. Security and automated decisions
GitHub authorization tokens are encrypted before storage and are never returned to browser code. Repository source is parsed for analysis but is not installed or executed. DiffAtlas does not use personal data for automated decisions that produce legal or similarly significant effects.
11. Changes
We may update this notice when the product, providers, or data practices change. Material changes will be highlighted before they take effect where appropriate. The date above identifies the latest version.