Updated 20 September 2026
Privacy notice
How AntiCode uses account information, repository data, and review content, and how to contact us about your data.
Who is responsible
AntiCode is operated by Rashad Elkersawy, Friedrich-Naumann-Str. 66, 26125 Oldenburg, Germany. For privacy questions and requests, contact privacy@anticode.app. This notice covers the website, authenticated workspace, and the distinction between hosted review and local Mac checks. It also explains where further provider information remains to be confirmed.
Information you provide and information from GitHub
GitHub sign-in supplies account information such as your identifier, name, email address, and avatar. We store account-linked workspace preferences, repository connections, review history, and your personal decisions about findings. Messages you send us include the information you choose to provide and the address needed to reply.
Connecting and syncing a repository retrieves repository details and pull-request titles, descriptions, author identifiers, status, and revision information from GitHub. These records can identify contributors other than the customer using AntiCode. Contributor information comes from the connected repository and is not necessarily supplied directly by that contributor.
What happens during a review
Website checks retrieve the selected pull-request diff on our server. When you choose managed AI review, that diff, including its code and any personal information within it, is sent to OpenAI for analysis. Personal ignored-path and severity preferences filter displayed findings; they do not remove code from the submitted diff.
We save findings, paths, line numbers, suggestions, and review-run records. Requested repository scans also save a file inventory and coverage at a specific commit. Opt-in GitHub App automation keeps event identifiers, task states, and pending review or reply content so interrupted publication can be reconciled. AI scans, conversations, and suggested fixes send their bounded source context to OpenAI; recorded model usage supports service spending limits. Findings may include code excerpts. Separate exact quotes used to validate AI citations are discarded before storage. Results assist human review; AntiCode does not automatically approve or merge your code. Native local checks inspect code on the device. Native builds can also send repository names and review counts to a configured telemetry endpoint, so local analysis is not a promise of no network communication.
Optional Human Review
When you submit a Human Review request, you explicitly authorize sharing a bounded package from a saved review you can access. It contains the repository and pull-request reference, head and base commits, target branch, review coverage, file references and credential-redacted finding explanations, together with your focus, question and subsequent messages. The package excludes source files, GitHub access tokens and suggested patches. Automated masking cannot guarantee detection of every sensitive value; do not include credentials or unnecessary personal data.
Authorized Human Review operators can see only requests submitted to that service; their role does not grant general access to customer repositories. We store the agreed scope and quote, assignments, messages, activity, and published assessments with the human reviewer identity, time and exact reviewed revision. Internal operator notes are separate from customer-visible conversations. An automated result is not a human assessment: an assigned person must write and publish the assessment after scope acceptance. Submission requests a separate quote, makes no charge and does not change your software plan.
Why we process information
We process information necessary to provide the account, requested reviews, saved results, and exports on the basis of providing the service you request under Article 6(1)(b) GDPR. Security and misuse prevention rely on our legitimate interest in protecting the service and its users under Article 6(1)(f), subject to individuals' rights. We process information under Article 6(1)(c) where an applicable legal obligation requires it.
Signing into GitHub or requesting a review is not blanket consent to unrelated processing. Repository information about other people requires a separate assessment of our role and the customer's authority; an account contract does not automatically establish a legal basis for every contributor's data. Contact us before relying on a particular data-processing arrangement for your organisation.
Who can receive information
GitHub supplies identity and repository access. Supabase provides authentication and database services. The website's hosting platform and Cloudflare infrastructure handle application traffic. OpenAI processes the diff when you request AI review. These providers may also handle operational connection information under their applicable arrangements.
Customers with verified access to the same repository can see its canonical review findings. Personal settings and triage are scoped to your account. Saved GitHub tokens are encrypted and are not included in dashboard responses. Our service-provider page explains these roles; it is not a claim that every provider acts in the same contractual capacity.
Resend processes Human Review notification email when sending is enabled. Customer notices use the verified email address from the AntiCode authentication account; review-team notices go to admin@rtwochain.com. The notification contains a request ID, a generic update message and an authenticated portal link. Source code, OAuth tokens, finding explanations and request messages are not included in these notifications. The delivery record tracks sending attempts and provider acceptance, which does not prove inbox delivery. Inbound mail to human-review@anticode.app is forwarded by Cloudflare Email Routing to admin@rtwochain.com; information you choose to send in email also reaches that inbox.
Retention, deletion, and processing locations
Stored workspace records remain available unless removed. There is currently no verified fixed deletion schedule covering every account record, review, operational log, telemetry record, or provider backup. You can request deletion or retention information at privacy@anticode.app. Disconnecting a repository removes your workspace access; it does not delete every stored record or revoke your GitHub authorisation.
Withdrawing Human Review consent deletes the copied evidence package, removes operator access to the request and blocks pending notifications. It does not recall messages already submitted to the email provider. The request, messages, activity and prior assessments remain in account records until the account is deleted; deleting the account removes these linked application records. Account deletion currently requires a request to privacy@anticode.app. This describes application records, not a promise that delivered email, provider logs or backups are immediately erased.
The Resend sending domain notify.anticode.app is verified and configured in the EU (Ireland) region. This identifies the sending-domain configuration, not the location of all AntiCode processing. Other provider regions, contracting entities and applicable international-transfer safeguards remain to be confirmed for this notice. We do not promise EU-only processing or zero retention. OpenAI's API data controls distinguish response storage from other retention, including abuse monitoring; a storage-disabled request alone does not establish zero retention.
Your choices and rights
You can change workspace preferences, disconnect repositories, and stop requesting hosted reviews. Providing account and repository information is necessary for the corresponding features. Browser storage supports sign-in and interface preferences as described in our cookies notice.
Subject to the GDPR's conditions, you may request access, correction, deletion, restriction, or portability and object to processing based on legitimate interests. Where consent applies, you may withdraw it. Contact privacy@anticode.app; we may request proportionate information to verify your identity. Dashboard exports are not a complete legal access response, and account deletion is not currently self-service. You may complain to a competent supervisory authority; the EDPB directory lists the authorities.
Contact fallback
If you cannot reach privacy@anticode.app, email admin@rtwochain.com and identify AntiCode in the subject.