Privacy Policy
quellbot is a GitHub App that reads issues and pull requests you point it at and uses a model you choose (Claude from Anthropic, or Codex from OpenAI) to fix bugs, review PRs, and triage failed CI. This policy explains what data passes through the service and how it is handled. It applies to the service at console.quellbot.dev.
1. What we process
| Data | Why | Kept |
|---|---|---|
| GitHub identity (login, id, avatar) | To sign you in and map you to your installation | While your account exists |
| Repository content (issue text, PR diffs, CI logs, file contents needed for a change) | Read at run time to perform the fix, review, or triage you requested | Not stored after the run; only sent to the model to produce the result |
| Your model credential (Anthropic or OpenAI API key, or a Claude / ChatGPT subscription token) | To call the model on your behalf, from a machine in your own cloud | Encrypted at rest until you disconnect it; decrypted only to start a run |
| Your Fly.io API token | To start the ephemeral machines in your Fly account that run your fixes, reviews, CI triage and replies | Encrypted at rest until you disconnect it |
| Run metadata (repo, status, model, token counts, cost, timestamps) | To show your dashboard, enforce budgets, and debug | Retained for your history until you delete the account |
| Email (optional) | To send you health alerts (dead token, budget cap) | Until you remove it |
| Subscription state (plan status, renewal date, and the Dodo customer and subscription ids) | To know whether your account has an active plan. Paid accounts only | While the account exists |
quellbot does not store your source code, execute it on the control plane, or use your code or prompts to train any model.
quellbot also never sees or stores your card details, billing address, or tax identifiers. Checkout happens on Dodo Payments' own pages; all we receive back is whether a subscription is active and an opaque customer id.
2. Who we share it with (sub-processors)
To run the service, data passes through these providers. Each is used only for the function listed.
- Anthropic or OpenAI, whichever lane you connect - runs the model that produces fixes, reviews, and triage. Your prompts and the code they include are processed here, under your own account with that provider, so their terms and retention apply to you directly.
- GitHub - the source of your repositories and the destination for the PRs and comments quellbot creates.
- Fly.io - hosts our control plane, and separately hosts the ephemeral machines started in your own Fly account, on your token, where every model run happens.
- Neon / PostgreSQL - stores account state, run metadata, and encrypted credentials.
- Dodo Payments - our Merchant of Record for quellbot Pro. They are the legal seller on the transaction and handle checkout, card processing, sales tax and VAT, invoices, refunds, and disputes. Your name, email, billing address and card details are provided to and held by them, not by us. Free-tier accounts never reach them at all.
- Resend - sends alert emails, only if you provide an email.
- Vercel - hosts this documentation site (static, no account data).
3. How your credentials are protected
- Model and Fly credentials are encrypted at rest and only decrypted in memory when a run needs them.
- Runs happen on your own infrastructure: every model call executes in an ephemeral machine in your own Fly account, which is destroyed when the run ends. Your credential is decrypted only to be handed to that machine. It is not a credential-free sandbox: what protects your credential there is deny-by-default egress (nothing can send it anywhere) and the machine being thrown away, rather than the credential being absent.
- Our control plane runs no model or agent compute. It orchestrates runs, talks to GitHub, serves the dashboard, and stores your data.
- Every push a run produces passes a deterministic policy gate before it reaches your repository. quellbot never merges, never touches your default branch, and never edits your CI.
3a. Cookies and local storage
The console sets one cookie, a signed session cookie that keeps you logged in for up to seven days, plus short-lived cookies for the sign-in handshake. The website stores your light or dark theme choice in your browser's local storage. There are no advertising or cross-site tracking cookies.
4. Your choices and rights
- Disconnect anytime - remove your model or Fly credential in Connections, or uninstall the GitHub App to revoke repository access immediately.
- Delete your data - use Delete account at the bottom of Profile & billing in the console. Credentials and runners are removed immediately; the account, run history, and activity are purged on a schedule afterwards. A paid subscription is cancelled at the same time, so nothing renews. Signing in again before the purge cancels the deletion.
- Access and export - request a copy of the run metadata we hold for you.
- Depending on where you live (for example the EU/UK under GDPR, or California under CCPA), you may have additional rights to access, correct, or erase your data. Contact us to exercise them.
5. Data location and retention
The control plane and database run in the United States. Run metadata is kept for your dashboard history until you delete your account; credentials are kept until you disconnect them; repository content is not retained beyond the run that used it.
6. Children
quellbot is a developer tool and is not directed to anyone under 16. Do not use it if you are under the age required to hold a GitHub account in your country.
7. Changes
If this policy changes materially, we will update the date above and, where appropriate, notify account holders by email.
8. Contact
The data controller is Quellbot, established in the United Arab Emirates. Questions, data access requests, and deletion requests: support@quellbot.dev. We aim to reply within two business days.