Privacy policy
How we handle your information when you use QApp for AI code review.
Last updated September 19, 2026
1. Who we are
Cognitic s.r.o., Pernerova 697/35, Karlín, 186 00 Praha 8, Czech Republic. Company ID (IČO): 09117741. VAT ID (DIČ): CZ09117741. Registered in the Commercial Register maintained by the Municipal Court in Prague, file C 331203. Contact: hello@cognitic.ai.
Cognitic s.r.o. is responsible for account, support, and service-security information. For personal information contained in an organization’s repository or review materials, that organization determines what it submits and why; we process that material to provide the requested service on its behalf. This notice does not replace a data processing agreement with your organization.
2. Information we process
- Account and team information: your name, email address, profile image, sign-in provider and identifiers, organization membership, roles, and invitations. Clerk manages authentication and team membership.
- GitHub information: connected accounts and installations, selected repositories, source code, commits, pull requests, author information, and relevant discussion or review comments.
- Review information: instructions, configuration, findings, code excerpts, test and build output, agent session history, execution metadata, and any screenshots or other artifacts produced by enabled review features.
- Configuration and credentials: integration credentials and environment values needed to access authorized repositories and run configured checks.
- Technical and support information: request and security logs, IP addresses, browser information, errors, and messages or feedback you choose to send us.
We receive information from you, your organization’s administrators and collaborators, connected providers, and the review jobs you request. Submit only information you are authorized to share. Avoid production customer data, unnecessary personal information, and credentials in repository content or review instructions.
3. Why we use it
We use this information to authenticate users, manage team access, connect repositories, execute and verify reviews, retain review history, deliver results according to your settings, provide support, investigate failures or abuse, and meet legal obligations.
Where we act as a controller under the GDPR, our legal bases are performance of our agreement with you; our legitimate interests in securing and operating QApp, supporting users, and improving reliability; and applicable legal obligations. We use consent where legally required for an optional activity. You can withdraw that consent without affecting earlier lawful processing. Account information is needed to provide an account; repository access and relevant code are needed to perform a review.
Reviews are advisory. We do not use review findings to make legally binding or similarly significant decisions about individuals.
4. Google and GitHub sign-in
Google sign-in requests basic identity information: your name, email address, profile image, and account identifier. It does not request access to Gmail, Drive, calendars, or contacts. We use Google account information for authentication and account management, not advertising or AI model training.
GitHub sign-in is separate from installing the QApp Bot GitHub App. Signing in does not itself give QApp access to your private repositories. An authorized administrator chooses which repositories the App can access. You can revoke either connection in the relevant provider’s settings.
5. AI processing and sharing
Reviewing code requires processing it outside GitHub. Authorized repository content is checked out into a hosted execution workspace. Relevant code, instructions, and tool output are sent to the AI provider to generate and verify findings. Do not submit material that your organization prohibits from being processed by these services.
- Clerk: authentication, account security, organizations, and invitations.
- GitHub and Google: the sign-in and repository integrations you choose to use.
- Cloudflare and PlanetScale: application hosting, network delivery, product database, and artifact storage.
- AGNT and its execution infrastructure, including E2B: review workspaces, environment configuration, agent sessions, and execution history.
- Anthropic: AI processing of review prompts, relevant source code, and tool results.
- Expo: builds and hosted devices when those review capabilities are used.
- Hivenet: product feedback submitted through QApp’s feedback tools. Those tools do not automatically attach repository code, captures, or session transcripts.
Provider processing and retention also depend on the applicable service configuration and agreements. Organization members can view their organization’s review data. If GitHub sharing is enabled, results and quoted code may be posted to the pull request and become visible to everyone who can access it, including the public for a public repository.
We do not sell personal information or use repository content for targeted advertising. We may disclose information where required by law, to protect people and the service, or in connection with a business transfer subject to applicable protections.
6. Storage, retention, and security
Account records, review history, and artifacts are retained while needed to provide the service to you or your organization. Retention also depends on the purpose of the record, your deletion requests, security investigations, legal obligations, and backup lifecycles. Execution providers may retain workspace and session records separately from QApp’s product database.
Disconnecting GitHub stops future authorized repository access; it does not automatically erase previous reviews, provider-side records, or comments already posted to GitHub. Deleting a sign-in account does not automatically delete organization-owned reviews. Contact us to request deletion of those records. Some records may need to be retained for legal claims or legal obligations, and backup deletion may take additional time.
We use encrypted connections, organization-based access checks, private artifact storage, and scoped credentials. No service can guarantee absolute security. Report a suspected security issue to hello@cognitic.ai.
7. International processing
QApp’s infrastructure and providers may process information outside your country and the European Economic Area, including in the United States. Our product database is currently hosted in the United States. Applicable transfer arrangements depend on the provider and service agreement, including adequacy decisions or standard contractual clauses where required. Contact us for information about the arrangements and safeguards relevant to your data.
8. Cookies and browser storage
QApp and Clerk use cookies and similar storage to keep you signed in, secure authentication, and remember interface preferences. The current QApp application does not include advertising trackers. Blocking essential authentication storage can prevent sign-in from working.
9. Your choices and rights
You can manage account details in QApp, ask an organization administrator to change team access, and revoke Google or GitHub connections through those providers. For access, correction, deletion, restriction, portability, withdrawal of consent, or an objection to processing based on legitimate interests, email hello@cognitic.ai. We may need to verify your identity and coordinate with your organization. The rights available depend on applicable law and the circumstances.
You can complain to your local data protection authority. In the Czech Republic, this is the Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7.
10. Children and changes
QApp is a professional software-development service and is not directed to children. Contact us if you believe a child has provided personal information without appropriate authorization.
We will update this page when our practices change, revise the date above, and provide additional notice where required. Questions about this policy can be sent to hello@cognitic.ai.