PRIVACY

What we do with your code

Last updated 25 September 2026 · Ava Technologies Global Ltd

Probus is operated by Ava Technologies Global Ltd (company number13299701, registered office 8 Bridgeland Street, Bideford, EX39 2PZ, United Kingdom), which is the controller of the personal data described here. If anything on this page matters to your decision, write to hello@avatechnologies.org and we will answer directly.

What we can read

Probus connects through a GitHub App. It asks for two permissions and no others:Contents: read and Metadata: read, ononly the repositories you choose when you install it. It cannot write to your code, open pull requests, or see repositories you did not select. You can change or revoke that access at any time from your GitHub settings.

We do not store GitHub access tokens. Access is minted from our App key when a review runs, lasts one hour, and is discarded.

What happens to your code during a review

We download your repository as an archive, hold it in memory for the duration of the review, and send the source files that fall in scope to a language model to be analysed. We do not write your source code to disk and we do not keep a copy after the review finishes.

We never execute your code. No build runs, no tests run, no install scripts run. The review reads text.

Who analyses your code, and what we do not yet promise about it.

The source files in scope are sent to a language model — currentlyGLM 5.3 Flash, reached throughOpenRouter, which routes requests on to whichever provider is serving that model.

We want to be exact about the limits of that arrangement rather than reassuring. We have not obtained a contractual commitment that your code will not be retained or used for training, and because OpenRouter can route to a different upstream provider, we cannot today name a single company whose terms govern your code end to end.

So: treat Probus as suitable for public repositories. If you are considering it for a private repository and this matters to you — it should — write to hello@avatechnologies.org and ask where this stands before you connect anything. We would rather answer that question than have you assume.

This section will name a provider, its retention window and its training commitment once those are settled. It will not say more than we can evidence.

What we keep

  • Your GitHub username, numeric id and avatar.
  • Which repositories you connected, and their name, owner, size and visibility.
  • For each review: the findings, the score, the commit reviewed, timing, token counts and cost. Findings include file paths, line numbers and short code snippets from your repository — this is the report you paid for.
  • Your payment history, held by Stripe — including your name, email and billing address, and your VAT number if you give one. We never see or store card details.

Why we use it

  • To provide the service you bought — connecting your repositories, running reviews and showing you the results. The lawful basis is performance of our contract with you.
  • To take payment and keep tax records, which we are legally required to do.
  • To keep the service secure and working — preventing abuse, investigating failures and understanding cost. The lawful basis is our legitimate interest in running a reliable service.

We do not sell your data, use it for advertising, or send marketing email.

Who else handles it

  • GitHub — sign-in, and access to the repositories you choose.
  • Cloudflare — hosting, our database and the storage of share cards.
  • Stripe — payments, receipts and VAT.
  • OpenRouter and the model provider it routes to — the source files a review analyses, as described above.

Some of these companies process data outside the UK, including in the United States. GitHub, Cloudflare and Stripe do so under their standard data processing terms, which include safeguards for transfers from the UK. For OpenRouter, see the section above on what we do not yet promise.

Cookies

We set one cookie, which keeps you signed in for up to 30 days. It is strictly necessary for the service to work, so we do not ask for consent to it. We use no analytics or advertising cookies. Stripe sets its own cookies on its checkout page, for fraud prevention.

How long we keep it

Your account and reviews are kept until you ask us to delete them. Records of payments are kept for six years, because tax law requires it — deleting your account removes everything else.

What we publish

Nothing, unless you ask us to. Registry listings and badges are opt-in and revocable from your dashboard. Even when you opt in, we deliberately never publish counts of critical or high severity findings, and a badge never names a vulnerability — a public page describing an open hole in a named program holding funds would put you at risk, which is the opposite of the point.

Deleting your data

Write to hello@avatechnologies.org and we will delete your account, your reviews and any registry listing. Uninstalling the GitHub App immediately ends our access to your code.

Your rights

You can ask for a copy of the personal data we hold about you, and ask us to correct it, delete it, restrict how we use it, give it to you in a portable form, or stop using it where we rely on legitimate interests. Write tohello@avatechnologies.org; we will answer within a month.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office atico.org.uk. We would appreciate the chance to put it right first.

Who to ask

Ava Technologies Global Ltd, 8 Bridgeland Street, Bideford, EX39 2PZ, United Kingdom. Questions tohello@avatechnologies.org.