How we handle your code
Repoclaw needs to understand your product, not to keep your code. These are the rules it follows.
Reading
- Access is read-only. Through GitHub, the Clawpy Repoclaw app asks only for read access to contents, issues and metadata, and only on the repositories you choose.
- Or use local mode: Repoclaw runs on your own machine and uploads only the capability list. Your code never leaves your computer.
- Repositories are treated as untrusted. Repoclaw never runs your code, your build scripts or your git hooks.
Processing
- Your code is read on our server in the EU, or on your machine in local mode.
- Source code is never sent to an AI model. The model sees a summary: folder and file names, your documentation and roadmap, dependency names, and TODO comments.
- Summaries go only to model providers whose terms exclude training on your data. Today that is Mistral AI, hosted in the EU, with training switched off.
Storage and deletion
- Clones are deleted at the end of every scan, including scans that fail.
- We keep your capability list, your weekly reports and the verdict history that makes week-to-week comparison possible.
- You can delete everything at any time from your dashboard or by emailing [email protected]. Backups roll off within 30 days.
What we never do
- Sell or share your code or reports.
- Use your code to train models.
- Publish a report about your repository without your permission.