Privacy policy

Last updated: 28 September 2026.

1. Introduction

This privacy policy explains how Crocotaste ("we", "us", "our") collects, uses, shares and protects personal data when you use the website at crocotaste.com, the Crocotaste GitHub App and the dashboard (together, the "Service").

Crocotaste is operated by Makeri, VAT IT13457560962 (the "Company"). We handle personal data in accordance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and, where it applies, the Italian Data Protection Code (D.Lgs. 196/2003).

By using the Service you agree to the processing described here. If you do not agree, do not use the Service.

This policy is written in English, which is the only binding version.

2. What the Service does, in one paragraph

Crocotaste is a GitHub App that reviews UI changes in pull requests against the repository's own design system (its DESIGN.md, design tokens, components and recorded decisions) and posts cited findings as pull request comments and check runs. It reads your repository; it never writes to it beyond those comments, check runs and one onboarding issue you explicitly ask it to open. Most of what it touches is code, not personal data; this policy describes the personal data that is involved.

3. Definitions

  • Personal data: any information relating to an identified or identifiable natural person.
  • User or you: the person who signs in to the dashboard, links a GitHub App installation, or whose GitHub activity (opening a pull request, writing a comment) is processed by a review.
  • Installation: an installation of the Crocotaste GitHub App on a GitHub account or organization, covering the repositories its owner chose.
  • Review: one run of Crocotaste on one pull request, producing a summary comment, inline findings and a check run.
  • Repository content: the files Crocotaste reads from a repository at review time: the pull request diff and the design references (DESIGN.md, stylesheets, token files, the Tailwind configuration, component files).
  • Findings: the review output Crocotaste posts and records: the text, the file and line it points at, the citation into your references, a suggested fix, and a content fingerprint.
  • Controller, processor, processing: as defined in the GDPR. For the processing described here the Company is the controller.

4. Data controller

Name: Makeri VAT: IT13457560962 Email: hello@crocotaste.com

Privacy questions and requests to exercise your rights go to that address.

Data protection officer

As a small business that does not process special categories of personal data at scale or systematically monitor individuals, we are not required to appoint a data protection officer under GDPR Article 37. Privacy inquiries go to hello@crocotaste.com.

5. What we collect

5.1 Information you provide

  • Account information: your GitHub login and the email address on your GitHub account. Signing in authorizes the Crocotaste GitHub App itself, which asks for read access to your account's email addresses; our authentication provider (Clerk) performs that exchange and passes us the result. Your GitHub account is the only way to create an account and to sign in; there is no separate Crocotaste password, and we never receive or store one.
  • Installation link: when you link an Installation from the setup page, we use the GitHub token issued to you through sign-in to check which Installations your GitHub account can access, and which repositories in them you can see. We store the link between your account and the Installation; we do not store the token, and we do not store which repositories you can see, because we ask GitHub again on every dashboard request.
  • Onboarding consent: whether you asked Crocotaste to open the "Generate your DESIGN.md" issue in your repositories, and the issue numbers it opened.
  • Dashboard actions: re-runs you request and the review mode you set on a repository.
  • Communications: anything you send us by email.

5.2 Information from GitHub

When an Installation is created, changed or removed, and when activity happens on an installed repository, GitHub sends us webhooks. From them and from the GitHub API we process:

  • the Installation id, the account login and type, and the ids, names and default branches of the installed repositories;
  • pull request numbers and titles, commit identifiers, the login of the author of a pull request comment that addresses Crocotaste (@crocotaste review, @crocotaste ignore <reason>) and that author's relationship to the repository (the association GitHub sends, and where it says less, the repository permission GitHub reports for the login), which decides whether the command is honoured; the same is read for the author of a pull request, to decide whether it is reviewed on its own;
  • at review time, the pull request's changed files and the repository's design references, read at the pull request's commits; a pull request with more than 300 changed files is skipped whole and not read.

5.3 Information collected automatically

  • Technical data: IP address, browser and device type, and the pages requested, in our hosting provider's request logs.
  • Page-view counts for the public pages (the home page, pricing, the docs and the legal pages), through Vercel Web Analytics: the page, the referrer, the country and the device type, with no cookie and no identifier that persists between visits. The signed-in pages (the dashboard and setup) send nothing to it.
  • Service data: rate-limit counters keyed to your account and installation (how many checkout, portal, setup and re-run actions you performed in an hour).

5.4 Information from our payment provider

Polar, our merchant of record, sends us the subscription and order events needed to keep your review balance: the Polar customer id, subscription id, product, billing period, and order ids. We never receive or store card numbers. When you start a checkout, we send Polar the GitHub account's id and name, and your email, GitHub username and our id for you, so Polar can set up that account's billing with you as its billing contact.

5.5 Mandatory and optional data

DataRequirementPurpose
GitHub account (email, login)Mandatory for the dashboardSign-up and sign-in; deciding which Installations you may see
GitHub App installationMandatory for reviewsWithout it there is nothing to review
Onboarding issue consentOptionalReviews run either way; the issue only helps your agent write DESIGN.md
Billing informationMandatory to buy a plan or packCollected and processed by Polar, never by us

6. Repository content and the model provider

Repository content is handled differently from everything else, and it is the heart of the Service:

  • Your code stays in your repository. We read it at review time from GitHub; we never write to it. The only things we ever create in your repository are pull request comments, check runs, a pull request approval on a clean pass, and, only if you asked for it on the setup page, one issue with instructions for your coding agent.
  • What is sent to the model provider. For each AI call a review makes, we send the added lines of the pull request's UI files, the lines removed from those same files, and a compact inventory of your parsed design references (tokens, components, conventions, decisions) to Anthropic, our model provider. Anthropic does not use API inputs or outputs to train its models. If the deterministic checks already cover the change, no AI call is made at all.
  • What is cached, for how long. Parsed references are cached in the review worker's memory for up to 30 minutes, keyed by the repository's commit. The model provider may cache the reference inventory as a prompt block for a short period to make repeated calls cheaper. We store no copy of your repository content at rest.
  • What is stored about a review. The pull request number, its title, the commit identifiers, the review's counts and verdict, whether the AI call ran, whether the review used a credit, and each posted finding (its text, location, citation, suggestion and fingerprint). A finding's text may quote the line of code it is about, the same text that is visible in your pull request.
  • Personal data inside code. If your repository content contains personal data (for example real customer data in a fixture), you are the controller of that data; we process it only to produce the review and do not keep it beyond the caches above.
  • Secrets and confidential material inside code. We read what a repository contains at review time and do not scan for or filter out credentials, keys or confidential material before processing. Keeping them out of a reviewed repository is your responsibility.

7. How we use personal data

  • To provide the Service: receive webhooks, run reviews, post comments and checks, show the dashboard, keep the review balance.
  • To decide who may see what: your GitHub account's access to an Installation decides whether you may open its dashboard; the repository relationship of a comment's author decides whether a command is honoured.
  • To bill: count reviews against the balance and apply Polar's subscription and order events.
  • To communicate: answer your emails. We send no marketing email and, today, no transactional email; everything Crocotaste tells you is on GitHub (the comments and checks) or in the dashboard.
  • To keep the Service working and safe: rate limits, abuse prevention, debugging from logs.
  • To comply with law.
ProcessingLegal basis (GDPR Article 6)Data
Account, sign-in, dashboard accessContractEmail, GitHub login, installation links
Receiving GitHub webhooks and running reviewsContractInstallation and repository identifiers, pull request data
Sending review inputs to the model providerContractAdded and removed lines, reference inventory
Posting comments, checks, approvals, the onboarding issueContractFindings, repository identifiers
Billing and the review balanceContractPolar identifiers, order ids, counts
Rate limiting, abuse prevention, debuggingLegitimate interestTechnical data, service data
Legal complianceLegal obligationAs required

9. Processors and other recipients

RecipientRoleWhere to read more
ClerkAuthentication (GitHub sign-in, sessions)clerk.com/legal/privacy
AnthropicModel provider for the AI part of a reviewanthropic.com/legal/privacy
PolarMerchant of record: checkout, invoices, VAT, portalpolar.sh/legal/privacy
StripePayment processing, through Polarstripe.com/privacy
VercelHosts the website and dashboard; cookieless page-view counts for the public pagesvercel.com/legal/privacy-policy
DigitalOceanHosts the review worker and the databasedigitalocean.com/legal/privacy-policy
GitHubThe platform the App runs on; an independent controllerGitHub privacy statement

GitHub is not our processor: your relationship with GitHub is governed by your agreement with GitHub. The Crocotaste GitHub App asks for repository contents and metadata read access and write access to pull requests, checks and issues, nothing else. The same App is what you sign in with, and for that it asks to read your account's email addresses; a token issued by signing in can do no more than the App and you can both do.

We do not sell personal data. We do not use personal data or repository content to train artificial intelligence models, and we do not permit our processors to do so on our behalf. Material changes to this list are reflected in an update to this policy.

9.1 International transfers

Our review worker and its database run in DigitalOcean's fra1 (Frankfurt) region. Every recipient in the table above is established in the United States or processes data there, so using the Service involves a transfer of personal data outside the European Economic Area.

Those transfers are made under Chapter V of the GDPR:

  • Standard Contractual Clauses. Each processor above is engaged under a data processing agreement incorporating the European Commission's Standard Contractual Clauses (Decision 2021/914), together with the technical and organisational measures described in section 14 and, where required, a transfer impact assessment.
  • EU–US Data Privacy Framework. Where a recipient is certified under the EU–US Data Privacy Framework, the transfer additionally relies on the Commission's adequacy decision of 10 July 2023. You can check a company's certification at dataprivacyframework.gov.
  • Your rights travel with the data. A transfer never reduces the rights in section 13, and you may ask us for a copy of the safeguards in place for a specific recipient using the contact details in section 19.

Repository content itself is sent to Anthropic for each model call a review makes and is not retained by us afterwards; section 6 describes that call and what it carries.

10. What other people can see

Crocotaste posts into pull requests on GitHub, so its output is visible to whoever can see the pull request, under GitHub's own rules: the summary comment, the inline findings, the check run, an approval, and a reply to an @crocotaste ignore command that states the next step (for an AI finding, a drafted decision for DESIGN.md). If a repository is public, so are those comments. The dashboard is visible to the people whose GitHub account can access the Installation; it shows repository names, pull request numbers and titles, review results and the balance, never anyone's email address.

11. Cookies

We use only the cookies the Service needs, all of them essential and all of them session cookies:

CookieProviderPurpose
__clerk_*, __sessionClerkSign-in session and account security
crocotaste-installationCrocotasteWhich Installation's dashboard you are looking at

No advertising, tracking, social or analytics cookies. The page-view counts in section 5.3 set no cookie and use no local storage. Essential cookies do not require consent under the GDPR and the ePrivacy Directive, and we set no cookie that would.

12. Retention

  • While installed: installation, repository, review and finding records are kept while the Installation exists, and balance and order records while any Installation of the same GitHub account exists, so a commit is reviewed once and a finding is never posted twice.
  • After uninstall: uninstalling the App stops everything at once; the Installation and every record under it (repositories, reviews, findings, jobs) are deleted 30 days later, and the account's balance and order records with them once no Installation of that account remains. The window exists so a reinstall inside it keeps its history and remaining balance. A balance whose paid plan is still running is kept until that plan ends, so that a payment can never be recorded against a deleted account; uninstalling asks the payment provider to end the plan at the end of the paid period.
  • Account: your account record (email, GitHub login, installation links) is kept while your account exists and deleted when you delete it.
  • Logs and caches: request logs and in-memory caches are short-lived (hours to days).
  • Payment records: kept by Polar and Stripe under their own retention rules and legal obligations; we keep the order ids needed to never credit the same purchase twice.
  • Legal: we may keep specific records longer when the law requires it or to defend a claim.

13. Your rights

Under the GDPR you may ask to access, correct, delete, restrict or receive a portable copy of your personal data, and you may object to processing based on legitimate interest. Write to hello@crocotaste.com; we answer within 30 days. You can also uninstall the App at any time (the 30-day deletion above then applies) and delete your account.

If you believe we have not handled your data properly you may lodge a complaint with your supervisory authority. For the Company that is the Italian authority, the Garante per la protezione dei dati personali (garanteprivacy.it).

14. Security

  • Everything travels over HTTPS/TLS; the database is encrypted at rest.
  • Authentication is managed by Clerk and uses GitHub sign-in only, so there is no Crocotaste password to store, leak or reset; the review worker has no inbound network access at all.
  • Every webhook (GitHub, Clerk, Polar) is verified by signature before it is processed.
  • The GitHub App holds the minimum permissions; the review worker talks only to Postgres, GitHub and the model provider.
  • The private key and API keys live in environment secrets, never in the repository.
  • Access to production data is limited to the people who operate the Service.

No method of transmission or storage is completely secure; we cannot guarantee absolute security.

15. Automated processing

Crocotaste's review is automated: a program and a language model produce findings about code. Findings are advisory comments on a pull request; they do not decide anything about a person, produce legal effects or similarly significantly affect anyone, and the people and branch policies of the repository decide what merges. We do no profiling of users and no automated decision-making within the meaning of GDPR Article 22.

16. Data breaches

If a personal data breach occurs we contain and assess it, notify the supervisory authority without undue delay and where feasible within 72 hours unless the breach is unlikely to result in a risk to your rights and freedoms, and notify affected users without undue delay where the risk is high.

17. Children

The Service is not intended for anyone under 18, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has given us personal data, write to hello@crocotaste.com and we will delete it.

18. Changes

We may update this policy. The date at the top changes when we do; continued use after a change means you accept it. Material changes are announced on this page.

19. Contact

Email: hello@crocotaste.com