heydeer 登录
ETOILEE PTE. LTD.

隐私政策

我们处理哪些数据、保留哪些记录,以及如何就数据问题联系我们。

最后更新:

以下完整正文目前以英文提供。如需解释,请联系我们。

1. Who we are

ETOILEE PTE. LTD. operates HeyDeer. Our registered address is 60 Paya Lebar Road, #04-016, Paya Lebar Square, Singapore 409051. This policy explains how we handle information when you visit our site, use code reviews, contact us or apply for a role.

For privacy questions and requests, contact hey@heydeer.ai with “Privacy” in the subject. When reviewing repositories for an organisation, we process that repository content to provide the requested service. Your organisation controls which repositories, instructions and integrations it authorises.

2. Information we process

Account and workspace information: GitHub identity and account identifiers, workspace memberships, installation details, settings and credentials required to connect your authorised repositories.

Review information: source code and Git history needed for analysis; pull request details, file paths and commit identifiers; review instructions, repository checks, findings, review history, execution status and usage records. Some saved findings and configuration snapshots can contain code excerpts.

Billing and service information: subscription and transaction references, credit balances, usage, payment status, support messages and operational records needed to run and troubleshoot the service. Payment card details are handled by our payment provider rather than submitted to HeyDeer’s own payment form.

Recruitment information: the resume, portfolio, professional links and messages you choose to send when applying for a role. Please do not send identity documents, bank details or confidential code from a current or former employer with an initial application.

3. Source code, review history and AI training

HeyDeer does not maintain a permanent repository mirror for reviews. Repository clones run in temporary, non-persistent sandbox environments with a time limit. Cleanup stops the review environment; if cleanup cannot complete, the environment’s time limit provides a fallback.

Review results and history are retained separately so you can revisit findings. They may include code snippets. Saved review instructions, repository-check snapshots, file paths and other review metadata may also contain repository-derived information. “Temporary source processing” therefore does not mean that every piece of source-derived content is immediately deleted.

HeyDeer does not use your source code, review instructions or review results to train its own AI models. We process that content to carry out reviews and provide the service.

Reviews use OpenAI and Anthropic accounts with Zero Data Retention (ZDR) enabled. These model providers receive code and review context to process review requests under their ZDR terms. This provider-side commitment applies to review inputs and outputs; it does not mean that HeyDeer deletes saved review results or history. Optional MCP services you connect have their own data policies.

4. How we use information

We use information to authenticate users, connect authorised repositories, run and publish reviews, preserve review history, manage subscriptions and credits, respond to support requests and maintain the service. Operational and usage information helps us diagnose failures, prevent abuse and understand service performance.

We use application materials to assess suitability for a role and communicate with applicants. We also process information when necessary to meet legal obligations, handle disputes and protect the service and its users.

5. Service providers and international processing

We share information with providers as needed to operate the service: GitHub for repository access and review publication; infrastructure and database services, including Vercel for sandbox execution; OpenAI and Anthropic for model processing; Stripe for payments; and services used to handle messages you send us. Optional MCP connections receive the requests and context needed for the tools you enable.

Reviews and comments published to GitHub are visible according to the repository’s access settings. Workspace information and review history are available to authorised workspace members. We may disclose information where required by law or reasonably necessary to protect legal rights or investigate abuse.

Our company is incorporated in Singapore, but processing is not restricted to Singapore. Providers may process information in other countries. Where applicable law requires safeguards for an international transfer, we must put those safeguards in place. Contact us if your organisation has specific residency or contractual requirements before connecting a repository.

6. Retention and deletion

Temporary repository environments and retained workspace records have different lifecycles. Review history, settings and account information remain available to support your workspace. Billing, security and support records may need to be retained for business or legal purposes. We do not currently publish a single fixed retention period covering all records, logs and backups.

Request account deletion at /app/account/privacy or email hey@heydeer.ai. You can submit a request without signing in or obtaining permission from a workspace administrator. Include your GitHub username if known; do not send passwords, access tokens, source code or identity documents. If we reasonably doubt your identity, we ask only for information needed to verify it. Authority over a shared workspace is checked separately from your right to request deletion of your own account.

We assess personal data in shared workspace records separately; closing one account does not automatically delete the organisation’s workspace or other people’s records. Where applicable law permits or requires retention, such as for accounting obligations or legal claims, we explain the records retained, the reason and the applicable retention period or criteria. A general business preference is not a blanket exception to erasure. Backups and records held by service providers are included in our handling of the request.

Sending a deletion request does not itself cancel workspace subscription renewals. Current workspace admins manage renewals through workspace billing. If your personal card is still being charged after you leave a workspace, contact us at /contact#billing so we can verify the charge and help resolve the payment method. Cancellation is not required before requesting account deletion.

Uninstalling the GitHub App removes future repository access but does not itself delete saved review history. An active review may still have its temporary copy. Comments already published to GitHub remain subject to that repository’s controls; external providers and connected services apply their own retention rules.

7. Cookies and preferences

HeyDeer uses cookies to keep you signed in, protect the GitHub sign-in flow and remember language preferences. Browser storage may also remember whether you dismissed a language suggestion. Blocking these features may affect sign-in or preferences. We do not describe these necessary features as an advertising consent choice.

8. Your choices and privacy requests

Choose individual repositories during GitHub App installation, configure your review instructions and optional connections, and remove repositories or uninstall the app through GitHub to revoke future access. Automatic reviews can be managed in workspace settings.

Depending on applicable law, you may request access to or correction of personal information, withdraw consent where processing relies on it, or request deletion or other available rights. Send requests to hey@heydeer.ai. We may ask for information needed to verify the request, and will respond in accordance with applicable law. Withdrawing necessary permissions may prevent us from providing parts of the service.

If your organisation controls the workspace, you may also need to contact its administrator. You can raise a concern with the relevant data protection authority, including Singapore’s Personal Data Protection Commission where applicable.

9. GDPR & Data Protection

Where the EU General Data Protection Regulation (GDPR) applies, you may have rights to access, correct or erase your personal data, restrict or object to its processing, and receive certain data in a portable format, subject to the conditions and exceptions in the law. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing. You may also lodge a complaint with a competent data protection authority.

To make a privacy request or ask about our data handling, email hey@heydeer.ai with “Privacy” in the subject. Describe the request and the account or workspace it concerns; do not include passwords, access tokens or repository source code. If the request concerns personal data we process on behalf of your organisation, contact its workspace administrator as well so the appropriate controller can address the request.

For GDPR requests, we respond without undue delay and within one month of receipt. Where necessary because of complexity or the number of requests, the law allows an extension of up to two further months; we notify you within the first month and explain the reason. Requests are normally handled free of charge. If we cannot act on all or part of your request, we explain why and how you may complain to a supervisory authority or seek a judicial remedy.

10. Updates and contact

We may update this policy when our practices or service change. We will display the updated date and communicate material changes through the service or an available account contact. For privacy, deletion or security questions, email hey@heydeer.ai.