Privacy Policy

Effective: 2026-05-26

This Privacy Policy describes how QAOnFire ("we", "us") collects, uses, and shares information when you install the QAOnFire GitHub App or subscribe to a paid plan ("the Service").

1. What we collect

CategoryExamplesWhen collected
GitHub installation datainstallation ID, account login, account type (User/Organization), account IDWhen you install the App
Pull request contentPR title, description, file diffs, contents of small files, your qabot.mdWhen a PR triggers a QA report
Usage recordswhich PRs were processed, token counts, comment IDs, error messagesEach time we run a job
Billing dataStripe customer ID, subscription ID, plan, statusWhen you subscribe to a paid plan
Webhook metadataIP address, user agent of incoming GitHub/Stripe webhooksOn each webhook delivery (transient, not stored long-term)

We do not collect: payment card details (handled by Stripe directly), your full repository contents (only diffs and selected file contents at PR time), or any data unrelated to the PRs you submit for review.

2. How we use it

We do not sell your data, use it for advertising, or train any AI model on it.

3. Third-party processors

We send certain data to the following sub-processors to operate the Service:

ProcessorWhat it processesWhere
Anthropic (Claude API)PR content, qabot.md, system prompts (the data needed to generate the QA report)USA
StripeSubscription payment processingUSA / global
RailwayCompute, database, Redis (where all Service data is stored at rest)Europe / USA depending on region
GitHubWebhook delivery, PR comment posting (necessary to integrate with your repos)USA
CloudflareDNS for our domainGlobal

Anthropic's API terms state that data submitted via API is not used to train their models. See their Commercial Terms.

4. Data retention

5. Your rights

Depending on your jurisdiction (e.g., under GDPR if you are in the EU, or under CCPA if you are in California), you may have the right to:

To exercise any of these rights, email hello@qaonfire.dev. We'll respond within 30 days. Note that deleting your installation data will terminate the Service for your account.

6. Security

We follow standard practices to protect your data:

No system is perfectly secure. If you discover a vulnerability, please report it to hello@qaonfire.dev.

7. Children

QAOnFire is not directed at children under 16. We do not knowingly collect data from anyone under 16.

8. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced via email to active subscribers or by a notice in QAOnFire output. The "Effective" date at the top of this page reflects the latest version.

9. Contact

Questions about this policy or your data: hello@qaonfire.dev