Legal

Privacy Policy

Last updated: August 29, 2026. How OnPair handles your code, identity, and analysis data.

  1. Overview

    At OnPair (“we”, “us”, or “our”), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our documentation analysis service and GitHub App.

  2. Information We Collect

    We collect information to operate, provide, and improve our services:

    • Account Information: Your email address, full name, and display name when you sign in or update your profile.
    • GitHub Installation Data: GitHub account login, account type, installation ID, and metadata of repositories you configure OnPair to watch.
    • Pull Request Diffs & Documentation: When a pull request opens or updates, OnPair reads commit diffs and associated documentation files in the repository to perform contract and impact analysis.
    • Billing & Payment Details: Transaction IDs, plan identifiers, and subscription status provided by our merchant of record payment processor. We do not store full credit card numbers on our servers.
  3. How We Use Your Information

    We use the information we collect to:

    • Authenticate your access passwordlessly via single-use email tokens.
    • Run deterministic contract checks and AI-powered documentation drift analyses.
    • Publish check runs and findings back to your GitHub pull requests.
    • Manage subscriptions, enforce quota allowances, and process billing.
    • Send essential transactional updates, receipts, and security notices.
  4. AI Processing & Data Privacy

    During AI analysis, relevant diff hunks and doc excerpts are passed to inference models (such as OpenAI) solely to evaluate documentation accuracy.

    Your proprietary source code and pull request data are never used to train foundational models. Data sent to inference providers is encrypted in transit and subject to strict zero-data-retention agreements where applicable.

  5. Data Sharing & Third Parties

    We do not sell, rent, or trade your personal data. We only share data with trusted service providers:

    • GitHub: For OAuth installation webhooks, repository file retrieval, and check run status reporting.
    • Payment Processors / Merchant of Record: For secure payment handling, tax compliance, and subscription management.
    • AI & Infrastructure Providers: For hosted cloud computing, database storage, and LLM inference.
  6. Data Retention & Security

    We implement industry-standard encryption, token hashing (SHA-256 for sign-in tokens), and access controls. We retain pull request analysis summaries and findings to display them in your dashboard. When you disconnect a repository or close your account, you can request permanent deletion of your stored records.

  7. Your Rights (GDPR & CCPA)

    Depending on your location, you have rights regarding your personal data, including the right to access, correct, export, or delete your personal information.

    To exercise any of these rights, please contact our privacy and support team at [email protected].

  8. Contact Us

    If you have any questions or concerns about this Privacy Policy, please contact us at:

    OnPair Privacy Team

    Email: [email protected]