Skip to content
compiler.dev

Privacy policy

Last updated

compiler.dev is run by Luxlogik ("we"). This page explains what we collect when you visit our website or use the product, why, and what you can do about it. Questions or requests: admin@luxlogik.com.

What we collect

  • Account data. When you sign in with GitHub we receive your GitHub user id, username, name, email address and avatar, and the organizations and repositories you install our GitHub App on.
  • CI and product events. Job queued, started and finished times, durations, cache hits, runner type, repository and job names, onboarding steps and page views. These never contain source code, secrets or email addresses; people are identified by an internal user id.
  • Billing data. Prepaid credit, invoices and payment status. Card details go directly to Stripe; we never see or store them.
  • Code you ask us to process. CI jobs run your repository's code on short-lived machines that are destroyed after the job. Dependency and git caches are kept to make later jobs faster and expire automatically. If you use Code review, the pull request's diff and related files are processed to write the review. If you use Code in a box, your box's disk holds whatever you put on it until you delete the box.
  • Keys you give us. Anthropic, OpenAI or other API keys are stored encrypted, sent only to the place they are needed (your box, or the review service), and never shown again.
  • Website analytics. Google Analytics, only if you accept cookies (see below).

Why we use it

To run the service you asked for (contract), to bill you (contract and legal obligation), to keep the service secure and working and to improve it (legitimate interest), and for website analytics only with your consent.

Cookies

CookiePurposeLasts
cd_sessionRemembers that you are signed in, so compiler.dev can send you to the appUntil you sign out
cd_consentRemembers your cookie choice6 months
_ga, _ga_*Google Analytics: which pages are visited and how people find usUp to 2 years, only if you click Accept

Visitors in the UK, EU, EEA and Switzerland get no analytics cookies unless they click Accept. We do not use advertising cookies and we do not sell data. You can change your choice at any time: cookie settings.

Who processes data for us

  • Supabase: sign-in and database.
  • Amazon Web Services: CI runners, Code in a box machines and storage.
  • Hetzner: our servers.
  • Stripe: payments.
  • Resend: emails such as receipts and notifications.
  • Google: website analytics, only with your consent.
  • Anthropic: writes code reviews and answers Insights questions, only when you turn those features on. If your organization adds its own Anthropic key, these requests run under your account with Anthropic.
  • TypeSafe: a decision model that helps decide how closely to review a pull request and which findings to post. It receives the pull request title and description, the list of changed files and short excerpts of the diff, only when Code review is on.

Some of these providers process data outside the UK and EU, under standard contractual clauses or an adequacy decision.

How long we keep it

CI and product events: two years. Account and billing data: while your account is open, and billing records for as long as tax law requires. Code in a box disks: until you delete the box.

Your rights

You can ask to see, correct, export or delete your data, or object to how we use it. Email admin@luxlogik.com and we will reply within 30 days. If you are unhappy with our answer you can complain to the UK Information Commissioner's Office (ico.org.uk) or your local data protection authority.

Changes

If we change this policy we will update the date at the top of this page.