Privacy
What Truecount receives, what it keeps, and where your code goes when a model reads it.
Who we are
Truecount is operated by CONFIRM: legal entity name and address. Contact us through the contact form.
What we receive from GitHub
- Your account: login, numeric id, and whether it is a user or an organization.
- The repositories you install Truecount on: numeric id, name, and whether each is public or private.
- Events: notices that a pull request opened or was labelled, that someone commented on one, or that the installation changed.
- For a review: the pull request's diff, title and description, and the config and guidelines files from its base branch.
- For an agent running in your GitHub Actions: GitHub's signed statement of which repository, workflow run and trigger it is, and the file contents the agent sends us to commit.
What we store
| Record | Contents | Kept for |
|---|---|---|
| Installation | Account login, id and type; the plan it is on; when it was installed, suspended or removed | While installed, then 90 days after you uninstall |
| Repository | Id, name, public or private; when it was added or removed | While installed, then 90 days after it is removed |
| Job | Repository name, pull request number, commit ids, what triggered it, and whether it succeeded | 90 days after it finishes |
| Agent run | Repository id, workflow run id, agent, trigger, the commit it audited, whether it finished, and the link to any pull request it opened | 90 days |
| Top-up purchase | The GitHub account named at checkout, runs bought and left, Stripe's checkout id, and when it was bought and expires | 365 days after it expires |
| Event receipt | GitHub's delivery id and event type, so a resent event is not handled twice | 7 days |
CONFIRM: these are the windows the code enforces today. Confirm them before launch. Expired records are deleted every hour.
We do not store your source code, diffs, pull request text, or what a model wrote about them. They are read when a job runs and kept only as long as the job takes. The review itself is posted to GitHub and lives there.
Where your code goes when a model reads it
Reviews and agents send code to a language model. By default that model runs on hardware we own and operate, not on a cloud provider's. CONFIRM: the inference gateway is configured not to log prompts or responses.
On paid plans, when our own hardware is busy or unavailable, a job may instead go through OpenRouter to a third-party model provider. CONFIRM: name the providers allowed, and that the routing is restricted to providers that neither retain nor train on prompts. Free plans never leave our hardware: a job waits instead.
We do not use your code to train models, and we do not sell or share it.
Top-ups are paid through Stripe, which handles your name, email address and payment details under its own privacy policy. We receive the GitHub account you name, what you bought, and Stripe's checkout id; never your card details. CONFIRM: refund terms, and Stripe named as a processor.
This website
truecount.dev sets no cookies of its own and runs no analytics. It is served by Cloudflare, which processes your IP address to deliver the pages.
The contact form uses Cloudflare Turnstile to check that a person, not a bot, is sending it; Cloudflare processes your IP address and browser signals for that check. What you send is emailed to us and kept in that mailbox. CONFIRM: how long contact messages are kept.
Your choices
- Uninstalling Truecount stops all processing. Your records are marked removed and deleted 90 days later, so a reinstall within that time picks up where it left off.
- To have your records deleted sooner, send a request through the contact form as an owner of the account, and every record of that installation is deleted at once. CONFIRM: how ownership is verified, and how quickly requests are answered.
Changes
If this policy changes, the new version will be posted here with its date. CONFIRM: effective date.