← Back to home

Privacy Policy

Last updated: June 30, 2026

1. Overview

Vydyra (“Vydyra”, “we”, “us”) is an autonomous software-engineering service that connects to your GitHub repositories and turns issues into pull requests. This policy explains what data we process, why, and the choices you have. It applies to the Vydyra web application and API.

2. Data we collect

  • Account data: your email address (used for passwordless sign-in) and, if you sign in with GitHub, your GitHub account identifier and verified email.
  • Repository content: when you connect a repository, we read issues, code, and related metadata during a run to plan and implement changes, and we write branches and pull requests on your behalf. We do not retain your source code — see “What we do not store” below.
  • AI provider credentials: if you bring your own AI model, the API key and base URL you configure are stored so the service can call your chosen provider on your behalf.
  • Operational data: run history, logs, and metrics generated while processing your issues.

What we do not store

We do not retain your source code. Vydyra reads your repository directly from GitHub only while a run is in progress, generates the proposed changes in memory, and writes them back to GitHub as a branch and pull request. We keep only operational metadata — such as the paths of files changed, commit SHAs, and pull-request references — never the contents of your files, and we do not copy your repository into our own storage. We also never store your email login code in readable form; only a one-way hash is kept so it can be verified once and then discarded.

3. How we use your data

We use your data solely to provide the service: authenticating you, processing the repositories and issues you direct us to, generating and reviewing code changes, and operating and securing the platform. We do not sell your data, and we do not use your private source code to train our own models.

4. Legal bases for processing

Where the GDPR or similar laws apply, we process your data on these legal bases: to perform our contract with you (providing the Service you request); our legitimate interests in operating, securing, and improving the Service; your consent where required (which you may withdraw); and to comply with legal obligations. For your repository content, you act as the data controller and Vydyra processes that content as your processor, on your instructions; for your account data, Vydyra is the controller.

5. Cookies and local storage

We use browser local storage to keep you signed in (your session and refresh tokens). We do not use third-party advertising or cross-site tracking cookies. Clearing your browser storage will sign you out.

6. Sub-processors and third parties

To deliver the service we share data with:

  • Your chosen AI provider (e.g. Google AI, Groq, OpenAI): issue text and relevant repository context are sent to the provider you configure so it can generate or review code. Your use of that provider is also governed by their terms and privacy policy.
  • GitHub: to read issues/code and open pull requests in your repositories.
  • Amazon Web Services (AWS): our cloud infrastructure and data storage (United States region).
  • Amazon SES: to deliver login-code emails.

7. International data transfers

Our infrastructure is hosted on AWS in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the U.S. Where required for transfers from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.

8. Automated processing

The Service uses AI models to assess issues and generate code. These produce proposals (pull requests) only; they do not make decisions that produce legal or similarly significant effects on you without your involvement — you decide what to review, accept, and merge.

9. Storage and security

Data is stored on AWS in the United States in an access-controlled database that is encrypted at rest, and all traffic to the Service is encrypted in transit with TLS. We restrict access to production data to what is necessary to operate the Service, and we do not use your private source code to train our own models. No method of transmission or storage is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.

10. Retention

We retain account and operational data for as long as your account is active. When you delete your account or disconnect a repository, we delete or de-identify the associated data (including stored AI provider credentials) within a reasonable period, except where we must retain it to comply with legal obligations. You can request deletion at any time (see Contact).

11. Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing or withdraw consent. To exercise any of these rights, contact us at the address below and we will respond as required by applicable law (including the GDPR and CCPA where they apply). If you are in the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local data-protection supervisory authority.

12. Children’s privacy

The Service is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

13. Changes

We may update this policy from time to time. Material changes will be reflected by an updated “Last updated” date, and where appropriate we will notify you.

14. Contact

Questions or requests regarding this policy or your data: privacy@vydyra.com.

See also our Terms of Service.