Last updated: June 30, 2026
Vydyra (“Vydyra”, “we”, “us”) is an autonomous software-engineering service that connects to your GitHub repositories and turns issues into pull requests. This policy explains what data we process, why, and the choices you have. It applies to the Vydyra web application and API.
We do not retain your source code. Vydyra reads your repository directly from GitHub only while a run is in progress, generates the proposed changes in memory, and writes them back to GitHub as a branch and pull request. We keep only operational metadata — such as the paths of files changed, commit SHAs, and pull-request references — never the contents of your files, and we do not copy your repository into our own storage. We also never store your email login code in readable form; only a one-way hash is kept so it can be verified once and then discarded.
We use your data solely to provide the service: authenticating you, processing the repositories and issues you direct us to, generating and reviewing code changes, and operating and securing the platform. We do not sell your data, and we do not use your private source code to train our own models.
Where the GDPR or similar laws apply, we process your data on these legal bases: to perform our contract with you (providing the Service you request); our legitimate interests in operating, securing, and improving the Service; your consent where required (which you may withdraw); and to comply with legal obligations. For your repository content, you act as the data controller and Vydyra processes that content as your processor, on your instructions; for your account data, Vydyra is the controller.
We use browser local storage to keep you signed in (your session and refresh tokens). We do not use third-party advertising or cross-site tracking cookies. Clearing your browser storage will sign you out.
To deliver the service we share data with:
Our infrastructure is hosted on AWS in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the U.S. Where required for transfers from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
The Service uses AI models to assess issues and generate code. These produce proposals (pull requests) only; they do not make decisions that produce legal or similarly significant effects on you without your involvement — you decide what to review, accept, and merge.
Data is stored on AWS in the United States in an access-controlled database that is encrypted at rest, and all traffic to the Service is encrypted in transit with TLS. We restrict access to production data to what is necessary to operate the Service, and we do not use your private source code to train our own models. No method of transmission or storage is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
We retain account and operational data for as long as your account is active. When you delete your account or disconnect a repository, we delete or de-identify the associated data (including stored AI provider credentials) within a reasonable period, except where we must retain it to comply with legal obligations. You can request deletion at any time (see Contact).
Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing or withdraw consent. To exercise any of these rights, contact us at the address below and we will respond as required by applicable law (including the GDPR and CCPA where they apply). If you are in the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local data-protection supervisory authority.
The Service is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
We may update this policy from time to time. Material changes will be reflected by an updated “Last updated” date, and where appropriate we will notify you.
Questions or requests regarding this policy or your data: privacy@vydyra.com.
See also our Terms of Service.