Data and retention
Your code is read for the review and cached for up to 30 minutes, never stored. Crocotaste keeps only what it needs to review and bill a pull request once.
The one thing worth knowing up front: no file from your repository is stored. Diffs and reference files are read at review time, held in memory, and gone. What persists is a record of the review itself and the text of each finding. A finding quotes the line it is about, which is the same text already sitting on your pull request.
During a review
- The pull request's changed files are read from GitHub at that commit.
- Your reference files (DESIGN.md, stylesheets, Tailwind configs, component files) are read at the pull request's base commit.
- Those parsed references are held in memory for up to 30 minutes so that several pull requests against one base commit do not re-read your system each time. Never written to disk, gone on restart.
- The added lines, the lines removed from those same files, and the inventory of your system are sent to the model provider for the AI part of the review. Inputs are not used to train models.
Nothing else leaves the review worker. Crocotaste talks to three things and no more: our database, GitHub, and the model provider.
What is stored
| What | Why | How long |
|---|---|---|
| Installation and repository ids, names and default branch | to route webhooks and reviews | while installed, then 30 days |
| Pull request numbers and titles, commit shas, the review's counts, verdict and usage | to review a PR once and never repeat a finding | while installed, then 30 days |
| Each posted finding's text, location, citation, suggestion and marker | to resolve, dismiss and never re-post | while installed, then 30 days |
| Review balance, credits and orders | billing | while installed, then 30 days |
| Your email and GitHub login | sign-in and the installation access check | while your account exists |
The counts are the ones quoted on the pull request (files, tokens, components, decisions, violations), plus how much model usage the review took, which is what makes a balance auditable.
Crocotaste stores no design knowledge of its own. No token values, no component definitions, no copy of DESIGN.md. Your repository is the only decision store, so there is nothing on our side that can quietly disagree with it.
What is reconstructible
Every comment Crocotaste posts carries a marker. If our database were lost entirely, the next review of a pull request would read those markers back from GitHub and still post nothing twice.
That property is why so little needs to be stored in the first place. The pull request is the record.
Deleting
Uninstall the App to stop everything. Every record above is deleted 30 days later; the window exists so a reinstall after an accidental removal keeps its history and its remaining balance. The balance and the order records belong to the GitHub account and go with its last installation. Uninstalling also asks Polar to end a paid plan at the end of its period, and an account whose plan is still running is kept until it ends, so a payment can never land on a deleted account.
For earlier deletion, or to see what is held about your account, email hello@crocotaste.com. The privacy policy has the full legal detail, including the sub-processors involved and the basis for each transfer.