法的情報

プライバシーポリシー

ウェブサイト、Juror Cloud、接続されたツールにおける個人情報の取り扱いについて。

このページの本文は現在、英語で提供されています。 English →

Who is responsible

Juror is operated by Derinbogaz Ventures UG (haftungsbeschränkt), Kolonnenstraße 8, 10827 Berlin, Germany. We are responsible for personal data used to run our website, manage accounts, communicate with you, secure the service, and administer billing. Contact us at jay@juror.dev for privacy questions or requests.

When a customer submits repository or QA data containing personal information, the customer determines the purpose of that processing. Our role and instructions for that data are governed by the applicable service and data-processing agreement. If you participate in someone else’s workspace, its administrator controls access and configured processing.

Data we process and why

The data involved depends on the features you use. It can come from you, your workspace administrator, your sign-in provider, GitHub, or a connected client.

  • Website requests: IP address, browser and device information, requested URL, time, and security or error information needed to deliver pages, investigate failures, and prevent abuse.
  • Accounts and workspaces: name, email address, profile image, provider identifiers, session and authorization records, memberships, roles, and settings needed for sign-in and access control.
  • Repository reviews: selected repository and pull-request metadata, commit identifiers, source context, diffs, comments, findings, and usage receipts needed to perform and present a review.
  • Browser QA: configured target URLs, test instructions, credentials, and captured screenshots, traces, or video where enabled. Use test accounts and synthetic data; evidence can contain information displayed by the tested application.
  • Payments and support: billing identifiers, usage, payment status, invoice information, and information you choose to include in correspondence. Stripe handles payment details; do not send card details or credentials in support requests.

Service providers and sharing

Cloudflare provides website delivery, hosted compute, databases, and object storage. GitHub provides sign-in, repository access, events, and review publishing. Google processes sign-in when you choose that option. Stripe processes hosted billing.

Review context is sent to the AI providers selected by the run configuration. Supported integrations include OpenAI, Anthropic, xAI, DeepSeek, Fireworks AI, OpenRouter, Scaleway, and Moonshot AI; not every provider is used for every run. Routing services may forward requests to the model provider. Their handling and retention are subject to the applicable provider terms.

Workspace members can see information permitted by their role. If review publishing is enabled, findings and summaries are sent back to GitHub and are visible to people who can access that repository, including the public for public repositories. We may also disclose information where legally required or necessary to establish or defend legal claims. We do not sell personal information.

Storage and deletion

Source checkouts are temporary run inputs in isolated execution environments and are cleaned up after execution. Full patches and model scratch text are not stored as dashboard reports. Findings and reports can still contain relevant code excerpts; redaction cannot guarantee removal of every piece of personal information.

Stored report files expire after 365 days and QA evidence after 90 days, with removal performed by scheduled cleanup. Resolved or ignored findings older than 365 days are also removed. Open findings, run metadata, account records, and billing records have different purposes and are not all deleted when a report file expires.

Account and workspace records are kept while needed to operate the account. Administrators can request workspace deletion in Settings; this is an asynchronous process that stops runs and removes workspace data and stored objects. Contact us for account-level requests. Billing records, security records, correspondence, and records needed for legal claims may be retained as required by law or for as long as their documented purpose requires. Copies already published to GitHub or exported to another service are controlled separately.

Optional training collection

Training collection is off by default. A workspace administrator must explicitly enable workspace-private improvement or shared Juror training, acknowledge the collection terms, and choose repositories. The administrator is responsible for having authority and a lawful basis to include contributors’ data; this setting does not replace an individual’s data protection rights.

Enabled collection includes selected review and conversation content. It is filtered, redacted, pseudonymized, and encrypted per workspace before storage. Raw file paths and PR descriptions require separate opt-ins. Source files, diffs, direct identity fields, credentials, and model scratch text are excluded from this corpus. Free text may still contain personal information.

Collection begins at opt-in. Administrators can disable future collection, export the corpus, or request its deletion in Settings. Retention follows the workspace’s selected period, with scheduled deletion after expiry. Disabling collection alone does not delete previously collected data; use the deletion control for that.

Connected clients and local use

ChatGPT, Codex, and other MCP clients connect through OAuth and your existing workspace permissions. They can receive permitted metadata and specifically requested retained finding content. The integration does not return raw diffs, source checkouts, full reports, screenshots, provider credentials, or prompt text. Starting a hosted review requires a separate confirmation. A client’s handling of data it receives is governed by that client’s policy; revocation stops future access but does not recall earlier exports.

The open-source CLI and GitHub Action run in infrastructure you choose. Their model requests go to your configured providers. Installing the open-source software alone does not create a Juror Cloud account or send its reviews to our dashboard.

Cookies and browser storage

Juror Cloud uses essential authentication cookies to maintain sessions and protect sign-in. Blocking these cookies can prevent sign-in from working. Our marketing application does not include advertising pixels or a cross-site advertising tracker. Infrastructure providers may process request and security data to deliver and protect the website. Following a LinkedIn, GitHub, or other external link takes you to a service with its own privacy and cookie practices.

International processing

Our service providers and selected AI providers may process information outside your country, including outside the EEA. Applicable transfer arrangements depend on the provider and service agreement. Where GDPR applies, a transfer requires an applicable adequacy decision or appropriate safeguards, such as standard contractual clauses. Contact us for information about the applicable arrangements or a copy of the relevant safeguards, and before submitting data with location restrictions. Juror does not promise EEA-only processing.

Your rights

Where applicable, you may request access, correction, deletion, restriction, or portability, and object to processing based on legitimate interests. You may withdraw consent and complain to a supervisory authority, including the Berlin Commissioner for Data Protection and Freedom of Information. We may need information to verify your identity. For customer-controlled repository data, contact the workspace administrator; we can help route your request.

Juror produces code-review suggestions. We do not use them to make solely automated decisions about you with legal or similarly significant effects. People remain responsible for review and merge decisions.

Policy updates

We update this policy when our service or processing changes. The date on this page identifies the current version. Material changes that require notice or consent will be handled through the service or an appropriate direct communication.