Privacy Policy
Last updated: March 2026
1. Information We Collect
When you use AutomaDocs, we collect information necessary to provide our documentation generation services:
- GitHub Account Information: Your GitHub username, email, and profile information via OAuth authentication.
- Repository Data: Source code and repository metadata for repositories you connect to our service.
- Usage Data: Information about how you interact with our service, including features used and pages viewed (with your consent).
- Support Communications: Chat messages and support requests if you use our live chat feature (with your consent).
2. How We Use Your Information
We use the collected information to:
- Generate automated reference pages for your repositories
- Provide semantic search and AI chat functionality
- Improve our service quality and reliability
- Communicate important updates about the service
- Provide customer support (with your consent)
- Analyze usage patterns to improve the product (with your consent)
3. Data Storage and Security
Your data is stored securely using industry-standard encryption. Repository data is processed by Claude AI (Anthropic) for documentation generation. We use Pinecone for vector storage to enable semantic search capabilities.
We do not sell your data to third parties. Your source code is only used to generate reference content and is not shared with other users.
Security measures include:
- TLS for traffic between you and our services
- Encryption at rest where our providers and database support it (see hosting and DB vendor docs)
- Automated CI security scans on our public repository (Semgrep, TruffleHog)
- Application-level access control; optional audit logs where the feature is enabled
4. Third-Party Services
We integrate with the following third-party services:
- GitHub: For authentication and repository access
- Anthropic (Claude AI): For automated documentation generation
- Pinecone: For vector database and semantic search
- OpenAI: For text embeddings
- PostHog: For product analytics (requires your consent)
- Crisp: For live chat support (requires your consent)
- Vercel: For hosting and performance monitoring
- Sentry: For error tracking and diagnostics
- Stripe: For payment processing (PCI DSS compliant)
Each service has its own privacy policy and data handling practices. We only share the minimum data necessary for each service to function.
5. Data Retention
We retain your data according to the following schedule:
- User account data: Retained until you delete your account
- Repository documentation: Retained until you remove the repository or delete your account
- Analytics data: Retained for 90 days, then automatically deleted
- Chat history: Retained until you delete your account
- Audit logs: Retained for 1 year for security purposes
When you delete a repository from AutomaDocs, we remove the associated documentation and embeddings within 24 hours. Account deletion removes all your data immediately.
6. Cookies and Tracking
We use the following types of cookies and tracking technologies:
- Essential cookies: Required for authentication, security, and core functionality. These cannot be disabled.
- Analytics cookies (optional): Used by PostHog to understand how you use our service. Requires your consent.
- Support chat (optional): Crisp live chat functionality. Requires your consent.
You can manage your cookie preferences at any time in Settings > Privacy.
We use Vercel Analytics for privacy-focused performance monitoring that does not use cookies or track personal information.
7. Your Rights
Under GDPR (for EU/UK users) and CCPA (for California users), you have the following rights:
- Right to access: Download all data we hold about you via Settings > Download My Data
- Right to deletion: Permanently delete your account and all associated data via Settings > Delete Account
- Right to withdraw consent: Disable optional data collection at any time in Settings > Privacy
- Right to data portability: Export your data in JSON format
- Right to object: Opt out of analytics and marketing communications
- Disconnect repositories: Remove any repository from our service at any time
To exercise any of these rights, visit your Settings page or contact us at privacy@automadocs.com.
8. International Data Transfers
Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses where required.
9. Children's Privacy
AutomaDocs is not intended for use by children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we will also send an email notification.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
- Email: privacy@automadocs.com
- General inquiries: hello@automadocs.com
For GDPR-related requests, our Data Protection Officer can be reached at dpo@automadocs.com.