Security & data handling
How HeyDeer accesses repositories, processes reviews, and stores data.
Repository permissions
Install the GitHub App with “Only select repositories” to limit access to the repositories you want reviewed.
HeyDeer does not request Administration or Workflows permissions. Tokens issued for a review are scoped to one repository and the permission needed for that step.
Review processing
HeyDeer clones the repository into a non-persistent Vercel Sandbox. Review agents inspect source code and can run targeted checks. The environment has a time limit and is stopped during review cleanup.
Model services
HeyDeer does not use your source code, review instructions or review results to train its own AI models.
HeyDeer uses OpenAI and Anthropic accounts with Zero Data Retention (ZDR) enabled for review requests. ZDR applies to review inputs and outputs handled by these model providers. HeyDeer stores review results and history separately; optional MCP services follow their own data policies.
Optional MCP connections
If you enable an MCP connection, requests to that service may include code or review context. You choose which services to connect and the credentials they use.
Credential boundaries
GitHub credentials used to publish reviews stay in the application backend and are not passed to review agents. Source-fetch credentials are scoped to read the selected repository.
Processing uses these infrastructure and model services and is not restricted to Singapore.
Stored data and retention
Review history is stored separately from the temporary review environment and remains available after the environment stops.
- HeyDeer stores review results, repository and PR identifiers, account and workspace information, settings, and billing records. Results and saved instructions may contain code or other sensitive context.
- Published review comments remain on GitHub under the repository’s controls.
HeyDeer does not currently publish a fixed retention period for all stored records, logs, and backups, or provide self-service deletion of workspace data. Provider and MCP records follow the applicable policies of those services.
Code handling and model provider policiesManaging access
- Select individual repositories when installing the GitHub App.
- Start reviews manually. Automatic reviews are off by default and can be enabled for selected repositories in Settings.
- Remove repositories from the installation or uninstall the app in GitHub to revoke access.
Installation changes control future GitHub access. An in-progress review may still have its existing code copy; saved history and provider records follow the retention details above. Turning off automatic reviews applies to future reviews.
Manage personal GitHub App installationsFor an organization, manage the installation in that organization’s GitHub settings.
GitHub, OpenAI and Anthropic names and logos are the property of their respective owners. Vercel, the Vercel design, Next.js and related marks, designs and logos are trademarks or registered trademarks of Vercel, Inc. or its affiliates in the US and other countries.