Privacy
Privacy Policy. In plain language.
This page explains how Sigilix handles your code, your account, and the data that flows through our code review, coding agent, and research chat. It is the controlling reference for our privacy commitments. The full architectural detail — including data-flow diagrams and retention rules — lives at /security.
Effective
July 2, 2026
Scope
Code, account, app data
Requests
privacy@sigilix.ai
01
Effective
Last updated: July 2, 2026.
Sigilix is operated by Sigilix, Inc. ("Sigilix", "we", "our"). We provide an AI code-review service that runs on your pull requests, a coding agent available through our CLI and issue-tracker integrations, and a research chat. This policy explains what data we collect, how we use it, who we share it with, and the rights you have.
02
What we collect
The data we process.
Account & identity
Email address, GitHub user ID, organization membership, billing contact, and the metadata GitHub returns when you authorize the Sigilix App. We do not collect passwords; auth is delegated to GitHub.
Repository & review data
For each review or agent task: the diff hunks, surrounding files, lockfiles, and PR metadata of the pull request under review, plus the findings we produce. Raw file contents are processed for inference; what is retained afterwards is governed by your learning settings (Section 03) and is redacted before storage.
Issue-tracker data
If you connect Linear or another issue tracker, we process the issues, comments, and metadata needed to triage tickets and run agent sessions you assign to Sigilix.
CLI & chat sessions
Prompts, responses, and tool activity from your Sigilix CLI and research-chat sessions. Retention of this content for learning is controlled per user (Section 03).
Connected apps (MCP)
If you connect third-party apps via MCP, we store the OAuth tokens and connection metadata needed to call those apps on your behalf. We only call them when your session uses them, and you can disconnect at any time.
Usage & billing
Aggregate usage metrics (review counts, latency, error rates, rate-limit usage), marketing-page analytics (page views, referrers), and billing records. Payments are processed by Stripe — we never store your card numbers.
03
Model learning
Learning scope depends on your plan.
Sigilix uses learning to improve review quality, user experience, and safety. Whether retained learning improves Sigilix-managed models or stays internal to your organization depends on your plan.
Defaults depend on your plan:
- ·Free, Pro, Max, and Ultra plans: learning is ON by default. Retained, redacted review, CLI, and chat signals are included in that default and are used to improve Sigilix-managed models, user experience, review quality, and safety. You can opt out at any time.
- ·Team and Enterprise plans: learning is OFF by default. If your organization admin opts in, retained, redacted learning stays internal to your organization and is not used to train models outside your organization.
Before anything is retained for learning, secrets and personally identifiable information are redacted. The retained corpus is stored durably (on Cloudflare infrastructure and object storage) according to the plan-specific learning scope above.
Turning learning off stops new retention immediately. Deleting your account permanently deletes your personal data and any user-scope retained learning data tied to that account. If your organization requests deletion of its retained learning corpus, that corpus is permanently deleted from Sigilix learning systems.
04
Boundaries
Plan-specific boundaries.
- ·Team and Enterprise learning is off by default and, if enabled, stays org-internal. We do not train models outside your organization on that retained learning data.
- ·We do not share one organization's raw repository data or retained learning corpus with any other organization.
- ·We do not vectorize or index your repositories into any shared embedding store.
- ·We do not retain secrets or PII — both are redacted before anything is stored for learning.
- ·We do not sell or rent your data.
05
Sub-processors
Where your data lives and runs.
Sigilix keeps a deliberately small footprint. Your code already lives in GitHub; our own infrastructure runs on Cloudflare; and model inference runs through partners bound by terms that prohibit them from training on your data. This list may change as the product evolves — material changes will be announced with notice (Section 09), and a current subprocessor list is always available on request.
Optional CLI BYOK (Bring Your Own Key) routes your local CLI session through the provider account you choose. Sigilix still supplies the context layer, but provider data handling is governed by that provider's terms and privacy policy. Sigilix does not control provider retention, privacy practices, or model behavior outside the Sigilix service. The Terms of Service describe the related BYOK model-behavior limitations.
Where your code already lives. We read pull requests through a scoped, short-lived token and post reviews back — we don't move your code anywhere new.
Our infrastructure — the API, workers, databases, object storage, and Durable Objects that run reviews, agent sessions, and (where enabled) store your org's learned corpus. TLS in transit, encryption at rest, isolated per tenant.
Prompts are sent for inference only, under zero-retention terms that prohibit training on your content. A current provider list is available on request.
Payment processing. Card numbers go directly to Stripe; we store only billing metadata (plan, invoices, billing contact).
If you connect it: issue and comment data needed for triage and agent sessions you assign to Sigilix.
Third-party apps you explicitly connect (via MCP) are called on your behalf with the OAuth grant you approve. Each is governed by its own terms.
06
Your rights
What you can ask us to do.
- ·Access — ask what data we hold about you or your organization.
- ·Export — request a copy of your account data and, where applicable, your org's learned corpus.
- ·Deletion — request deletion of your account data and retained learning data within your control. We will permanently delete retained learning data from Sigilix learning systems.
- ·Opt out of learning — Free, Pro, Max, and Ultra users can turn learning off in settings. Team and Enterprise org admins control whether org-internal learning is enabled.
We aim to honor these rights for all customers regardless of region, in line with GDPR and CCPA principles. Send requests to privacy@sigilix.ai and we will respond within 30 days.
07
Security
How your data is protected.
- ·Encryption in transit (TLS) and at rest across our stack.
- ·Per-tenant isolation: each organization's data, memory, and learned corpus are partitioned per organization and never mixed.
- ·OAuth tokens for GitHub, Linear, and MCP-connected apps are stored encrypted, scoped to the minimum permissions needed, and revocable by you at any time.
- ·Secrets and PII are redacted before any content is retained for learning.
Architectural detail lives at /security. Report vulnerabilities to security@sigilix.ai.
08
Enterprise
Data Processing Agreements.
A Data Processing Agreement (DPA) is available on request for enterprise customers. Contact legal@sigilix.ai.
09
Changes
How updates work.
We will revise this policy as we add features and sub-processors. Material changes will be announced by email to the billing contact and posted at sigilix.ai/privacy with the new effective date. Continued use of the service after a change constitutes acceptance.
10
Contact
Reach a human.
Privacy questions: privacy@sigilix.ai. Security disclosures: security@sigilix.ai. Anything else: support@sigilix.ai.