heydeer Sign in
SECURITY & DATA HANDLING

Security & data handling

How HeyDeer accesses repositories, processes reviews, and stores data.

01 / GITHUB PERMISSIONS

Repository permissions

Install the GitHub App with “Only select repositories” to limit access to the repositories you want reviewed.

Repository contents Read
Read the full source and Git history of authorized repositories to understand changes in context.
Pull requests Read & write
Read pull request details and publish reviews and inline comments. HeyDeer does not request permission to push source code.
Repository metadata Read
Read basic repository information required by GitHub Apps.
Issues: read
Receive PR comment commands. HeyDeer does not request Issues write permission.
Organization members: read
Check organization and team membership when your review policy uses member or team rules.
Email addresses: read
Use your verified primary email for billing and trial reminders. Sign-in remains available without this permission.

HeyDeer does not request Administration or Workflows permissions. Tokens issued for a review are scoped to one repository and the permission needed for that step.

02 / PROCESSING & PROVIDERS

Review processing

HeyDeer clones the repository into a non-persistent Vercel Sandbox. Review agents inspect source code and can run targeted checks. The environment has a time limit and is stopped during review cleanup.

Model services

HeyDeer does not use your source code, review instructions or review results to train its own AI models.

HeyDeer uses OpenAI and Anthropic accounts with Zero Data Retention (ZDR) enabled for review requests. ZDR applies to review inputs and outputs handled by these model providers. HeyDeer stores review results and history separately; optional MCP services follow their own data policies.

Optional MCP connections

If you enable an MCP connection, requests to that service may include code or review context. You choose which services to connect and the credentials they use.

Credential boundaries

GitHub credentials used to publish reviews stay in the application backend and are not passed to review agents. Source-fetch credentials are scoped to read the selected repository.

Processing uses these infrastructure and model services and is not restricted to Singapore.

03 / STORED DATA & RETENTION

Stored data and retention

Review history is stored separately from the temporary review environment and remains available after the environment stops.

  • HeyDeer stores review results, repository and PR identifiers, account and workspace information, settings, and billing records. Results and saved instructions may contain code or other sensitive context.
  • Published review comments remain on GitHub under the repository’s controls.

HeyDeer does not currently publish a fixed retention period for all stored records, logs, and backups, or provide self-service deletion of workspace data. Provider and MCP records follow the applicable policies of those services.

Code handling and model provider policies

Privacy & security · hey@heydeer.ai

04 / MANAGING ACCESS

Managing access

  • Select individual repositories when installing the GitHub App.
  • Start reviews manually. Automatic reviews are off by default and can be enabled for selected repositories in Settings.
  • Remove repositories from the installation or uninstall the app in GitHub to revoke access.

Installation changes control future GitHub access. An in-progress review may still have its existing code copy; saved history and provider records follow the retention details above. Turning off automatic reviews applies to future reviews.

Manage personal GitHub App installations

For an organization, manage the installation in that organization’s GitHub settings.

GitHub, OpenAI and Anthropic names and logos are the property of their respective owners. Vercel, the Vercel design, Next.js and related marks, designs and logos are trademarks or registered trademarks of Vercel, Inc. or its affiliates in the US and other countries.