Privacy Policy
Effective date: 14 July 2026 · Last updated: 14 July 2026
1. Introduction
Hypervex Code ("Hypervex", "we", "us", "our") is an AI-powered security code review GitHub App operated by Prasanth Kannan, India ("the Operator"). This Privacy Policy explains what information we collect when you use the Hypervex Code service at hypervex.ai, how we use it, who we share it with, and the rights you have over your data.
By installing or using Hypervex Code you agree to this Privacy Policy. If you do not agree, do not use the service.
2. Information We Collect
Account information. When you sign in via GitHub (through Clerk), we receive your GitHub username, display name, email address, and a GitHub user ID. We use this to identify your account.
Repository metadata. When you connect a repository, we store its name, owner, GitHub repository ID, default branch, and basic settings. We do not store full repository history.
Pull request diffs and code content. When a pull request event is received, we fetch the PR diff and — when codebase context is enabled — excerpts from relevant files in the repository. This code content leaves our systems in two ways: (a) it is sent to Anthropic's Claude API for AI-powered security analysis, and (b) it is sent to Google's Gemini API to be converted into vector embeddings, which are then stored in our Qdrant vector database to power future reviews. Both providers receive the code itself, not only the embeddings; see Section 4. The changed-file patches from the PR are also stored with the review so your dashboard can display each finding alongside the code it references; they are deleted with the review data under the retention schedule in Section 5.
Review findings. Structured security findings produced by Hypervex (severity, file, line, description, suggested fix) are stored in our database and displayed in your dashboard.
Usage data. We log feature interactions, review counts, error events, and performance metrics for the purpose of operating and improving the service.
Billing information. Subscription and payment data is managed by Polar, our billing processor. We receive subscription status, tier, and renewal dates. We do not store card numbers or bank details.
Support communications. If you contact us by email, we retain the correspondence to help resolve your request.
3. How We Use Your Information
We use the information we collect to:
• Perform AI security reviews of your pull requests. • Build and maintain a codebase context index (vector embeddings) that improves review accuracy over time. • Manage your account, enforce plan limits, and process billing. • Send transactional communications: sign-in and account emails are sent via Clerk, billing receipts via Polar, and we may email you directly about security incidents or material changes to the service. We do not send marketing email without your explicit opt-in. • Detect and prevent abuse of the service. • Improve Hypervex by analysing aggregated, de-identified usage patterns.
We do not sell your data to third parties. We do not use your code or findings to train AI models.
4. Third-Party Processors
We share data with the following sub-processors only to the extent necessary to operate the service:
Anthropic (anthropic.com) — AI model provider. PR diffs and code excerpts are sent to the Claude API for security analysis. Anthropic does not train its models on API inputs or outputs by default. See anthropic.com/privacy for their data practices.
Google (ai.google.dev) — Embedding model provider. Code excerpts from your indexed repositories are sent to the Gemini API to be converted into vector embeddings. Google receives the code content itself, not only the resulting embeddings. We use a paid Gemini API tier, under which Google does not use submitted content to improve its models. See ai.google.dev/terms and policies.google.com/privacy.
Polar (polar.sh) — Billing and subscription management. Your email address and subscription status are shared with Polar. Polar acts as the merchant of record for Pro tier transactions. Their terms and privacy policy apply to payment processing.
Clerk (clerk.com) — Authentication. GitHub OAuth tokens and identity information are managed by Clerk. See clerk.com/privacy.
Vercel (vercel.com) — Application hosting and edge delivery. Standard request logs (IP address, user agent, request path) are processed by Vercel. See vercel.com/legal/privacy-policy.
Qdrant (qdrant.tech) — Vector database. Code embeddings (mathematical vector representations of code) are stored in Qdrant. Embeddings cannot be directly reversed to source code.
Neon / PostgreSQL — Primary database hosting for account data, findings, and subscription records.
Liveblocks (liveblocks.io) — In-app notifications. To deliver the notification bell in your dashboard we share your user ID, display name, email address and avatar URL, together with notification contents: repository name, pull request or issue number and title, and a link back to GitHub. Liveblocks does not receive your source code, diffs or finding details. See liveblocks.io/privacy.
Inngest (inngest.com) — Background job orchestration. The review, indexing and deletion pipelines are queued through Inngest. Event payloads contain repository owner and name, pull request number, title and description, and commit SHAs. They do not contain your source code or diffs — the code is fetched from GitHub inside the job, after Inngest has dispatched it. See inngest.com/privacy.
Render (render.com) — Backend application hosting. The review pipeline runs on Render, so PR diffs, code excerpts, and findings pass through their infrastructure in transit and in process memory. Standard request and application logs are processed by Render. See render.com/privacy.
Sentry (sentry.io) — Error monitoring and performance tracing. Exception reports may incidentally include fragments of the code being processed at the time of an error, together with request metadata. See sentry.io/privacy.
All sub-processors are required to handle your data only for the purpose we specify, under confidentiality obligations.
5. Data Retention
Code content (PR diffs). The diff is processed in real time by the review pipeline. The changed-file patches are stored with the review to power the dashboard's diff view, and follow the same retention as review findings below.
Codebase embeddings. Stored in our vector database until you uninstall the Hypervex GitHub App or request deletion. Uninstalling the app, or emailing privacy@hypervex.ai, triggers deletion of all embeddings for your repositories within 30 days.
Review findings and dashboard data. Retained for the lifetime of your account plus 90 days after account deletion, or deleted earlier on request to privacy@hypervex.ai.
Account data. Retained until you delete your account. You may request account deletion by emailing privacy@hypervex.ai.
Billing records. Retained for as long as required by applicable law and our payment processor's policies (typically 7 years for tax/accounting purposes).
Support communications. Retained for 2 years after the issue is resolved.
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
• Access: request a copy of the personal data we hold about you. • Correction: request that inaccurate or incomplete data be corrected. • Deletion: request that we delete your personal data (subject to our retention obligations). • Portability: request your data in a structured, machine-readable format. • Objection: object to processing based on legitimate interests. • Restriction: request that we restrict processing of your data in certain circumstances.
To exercise any of these rights, email privacy@hypervex.ai. We will respond within 30 days. We may need to verify your identity before fulfilling the request.
Users in the European Economic Area have additional rights under the GDPR. Users in India have rights under the Digital Personal Data Protection Act, 2023 (DPDP Act). Users in California have rights under the CCPA.
7. Security
We implement reasonable technical and organisational measures to protect your data — including encrypted data at rest, TLS in transit, and access controls. No method of transmission over the internet is perfectly secure. We will notify affected users of any data breach as required by applicable law.
8. Children
Hypervex Code is not directed at children under 13 years of age. We do not knowingly collect personal data from minors. If we learn that a minor has provided us personal data, we will delete it promptly.
9. International Transfers
The Operator is based in India. Data you provide may be processed in countries where our sub-processors operate (United States, European Union, and others). Where required by law, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses for data transferred from the EEA.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the effective date and, where we have your email address, notify you directly. Continued use of the service after the effective date of an updated policy constitutes acceptance.
11. Contact
For privacy questions or to exercise your rights:
Email: privacy@hypervex.ai Operator: Prasanth Kannan, India