Your data, your control
Last updated: September 4, 2026
This Privacy Policy explains how Yanib ("Yanib", "we", "us", "our") collects, uses, and protects information when you use the Yanib service available at yanib.dev (the "Service"). It applies to visitors, account holders, and anyone whose data is processed through the Service.
1. Who we are (Data Controller)
Yanib is the data controller for personal data processed about you when you use our Service. For privacy questions or data subject requests, email support@yanib.dev.
For paid subscriptions, Paddle.com Market Limited acts as Merchant of Record and is an independent data controller for the payment data it collects from you at checkout. Paddle's privacy notice is available at paddle.com/legal/privacy.
2. Information we collect
Account information: When you sign in with GitHub, GitLab, Google, or email, we receive your name, email address, and profile photo. For GitHub or GitLab sign in, we also receive your username and an OAuth access token to interact with your repositories on your behalf.
Repository data: When you connect a repository, we access repository metadata, commits, pull or merge requests, and release tags. Code-indexing, surface-detection, and pull-request review features also read source files, configuration, and diffs from repositories you authorize. We retain derived indexes, dependency references, bounded source excerpts, and review results to provide those features.
Content you submit: Edits to story drafts, integration configurations (Slack channels, Discord webhooks, custom webhook URLs), team names, and similar inputs.
Usage and device data: Pages visited, features used, browser type, device type, IP address (transient, used for rate limiting and security) and approximate timestamps. Collected via PostHog (product analytics) and Sentry (error reporting). Both are configured to scrub personally identifiable values from event payloads where reasonably possible.
Payment information: If you subscribe, Paddle collects your billing name, billing address, and payment details (card or alternative). We receive only a Paddle customer ID, subscription status, and the last four digits of your card from Paddle webhooks. We do not store full card numbers.
3. How we use your data and legal basis
We process your data for the following purposes:
- Provide the Service, analyze authorized code and dependencies, provide pull-request reviews, and write release stories and digests from your commit/PR data, deliver them to your configured integrations, host public story pages and developer profiles. Legal basis: performance of a contract.
- Account and billing, authenticate you, manage your subscription, send transactional emails (invoices, draft notifications, team invites). Legal basis: performance of a contract.
- Service improvement and security, debug issues, prevent abuse, monitor performance, enforce rate limits. Legal basis: legitimate interest in operating a reliable, secure Service.
- Legal compliance, meet tax, accounting, and regulatory obligations. Legal basis: legal obligation.
- Marketing emails, only with your separate consent or where permitted under soft opt in for similar products. You can unsubscribe at any time.
4. AI processing
Yanib uses Anthropic’s API or Amazon Web Services (AWS) Bedrock for enabled review and writing features, according to the service configuration. Inputs can include commit and pull-request metadata, draft content, source-code diffs, and bounded code excerpts with dependency evidence. Code processing is not limited to repository metadata. Cross-repository review uses the connected repositories explicitly selected for that source repository.
The configured provider processes these inputs under its applicable commercial terms. Provider retention and data-use terms apply separately from Yanib’s storage. See Anthropic’s commercial data-retention policy and AWS Bedrock’s data-retention documentation. Yanib does not offer a general zero-retention or regional-processing guarantee. Some response caches have a one-hour validity period; stored review results and repository indexes are separate records.
AI features use Yanib’s platform account. Provider processing information for dependency reasoning is shown in the repository’s review settings.
5. Sub processors and data sharing
We do not sell your personal data. We share data only with the following sub processors and partners, each bound by appropriate data protection terms:
- Anthropic, PBC (USA), processing repository metadata, draft content, source-code diffs, and selected code evidence for enabled review and writing features.
- Amazon Web Services, Inc. (USA), processing repository metadata, draft content, source-code diffs, and selected code evidence when review and writing features use Amazon Bedrock.
- Paddle.com Market Limited (UK), payment processing and Merchant of Record services.
- Resend, Inc. (USA), transactional and subscriber email delivery.
- Neon, Inc. (USA), managed PostgreSQL database hosting.
- Vercel Inc. (USA), application hosting and CDN.
- Inngest, Inc. (USA), background job orchestration.
- Sentry (Functional Software, Inc.) (USA), application error tracking.
- PostHog, Inc. (USA / EU region), product analytics.
- GitHub, Inc. and GitLab Inc., only the authorized access needed to read connected repository data and source code, and to publish checks, reviews, issues, or pull requests when those actions are enabled.
We may also disclose data when required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Yanib, our users, or others.
6. International data transfers
Yanib is operated globally and several of our sub processors are based in the United States. When we transfer personal data of users in the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) as the legal transfer mechanism. Where our sub processors offer EU region data residency we use it by default.
7. Cookies and tracking
We use a small number of cookies and similar technologies:
- Strictly necessary, session and authentication cookies (NextAuth) and CSRF tokens. The Service cannot function without these.
- Functional, remembering your active team / workspace context.
- Analytics, first party PostHog identifiers used to aggregate product usage. You can opt out with a standard browser content blocker; the Service will continue to work normally.
We do not use cookies for advertising or cross site tracking.
8. Data retention
We retain account and repository data to provide the enabled service. Disconnecting a repository disables its future processing and schedules cleanup of associated records. Surface records have a 30-day recovery period before their scheduled purge. Code indexes use a separate background purge process. Cleanup can require retries; disconnecting is not a confirmation that every stored copy has already been erased. Contact support for the status of a deletion request and applicable backup or processor retention.
Billing records (invoices, transaction IDs, tax data) are retained for as long as required by applicable tax and accounting law, typically 7 years. Deleted accounts are included in our analytics deletion process. Retention required for legal obligations is handled separately from service data.
Repository indexes, source excerpts, and review records are distinct from short-lived response caches. Disconnect and deletion requests use background cleanup, which can require retries. Disabling review posting alone does not delete the index. Reviews or notifications already delivered to GitHub or another configured destination remain subject to that destination’s access and retention controls. Contact support for help with a deletion request.
9. Security
All data is transmitted over TLS/HTTPS. Webhook signatures are cryptographically verified. Database connections use SSL. Access to production data is limited to authorised engineers and protected by strong authentication and audit logging. Despite reasonable safeguards, no system is perfectly secure; you use the Service at your own risk.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data ("right to erasure").
- Restrict or object to certain processing.
- Receive your data in a portable format ("data portability").
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection authority. EEA users may contact their national supervisory authority; UK users may contact the ICO at ico.org.uk.
California residents (CCPA/CPRA): you have the right to know what personal information we collect, request deletion, opt out of "sale" or "sharing" of personal information (we do not sell or share for cross context behavioural advertising), and not be discriminated against for exercising these rights.
To exercise any of these rights, email support@yanib.dev. We will respond within 30 days (or the shorter period required by your local law). You can also export and delete most data directly from your dashboard under Settings.
11. Children
Yanib is not directed to children under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact support@yanib.dev and we will delete it.
12. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in app notice and updated here with a new "Last updated" date. Continued use of the Service after a change constitutes acceptance of the revised Policy.
13. Contact
For privacy, data protection, billing, or general enquiries, email support@yanib.dev.