Privacy policy
Last updated 13 August 2026
Draft pending legal review. This document describes how the service is built and intended to operate. It has not been reviewed by counsel, and items marked to be confirmed are unresolved. Do not treat it as a final agreement.
The short version
LikelyAI uses selected-repository GitHub access to scan code for affected API usages. We do not sell customer data, use repository contents for advertising, or train models on customer code.
This is an early product policy and still requires review by counsel before accepting production customers.
Who we are
The service is operated by LikelyAI, legal entity name (to be confirmed), registered at registered address (to be confirmed). Privacy questions can be sent to privacy contact address (to be confirmed).
What we collect
- Account identity from GitHub or Google: name, email address, avatar, and provider identifier.
- Organization, membership, invitation, and audit information.
- GitHub App installation metadata and the repositories explicitly selected for access.
- Source code and package metadata temporarily processed during a repository scan.
- Normalized integration usages, small evidence excerpts, scan status, impact reports, and GitHub issues created from them.
- Security and operational logs that exclude repository contents, secrets, and installation tokens.
How repository data is handled
LikelyAI requests metadata and read-only contents for selected repositories. Issue write permission is used only when issue creation is enabled. We use short-lived GitHub installation tokens and do not store them in plaintext.
A scan checks out a specific commit in temporary storage. The checkout is deleted after analysis. We retain normalized usages and the minimum evidence needed to explain a finding. Likely secrets are redacted before any small excerpt is sent to a model provider, and a complete repository is never sent to a model.
The exact production deletion window after repository disconnection or GitHub App removal is to be finalized before private beta (to be confirmed).
Why we process data
- To authenticate users and authorize organization access.
- To inventory dependency usages and match them to changes in published type declarations.
- To show impact reports and create GitHub issues when requested.
- To secure, operate, and improve the reliability of the service.
- To meet legal and accounting obligations.
The applicable legal bases and region-specific retention schedule are to be confirmed with counsel (to be confirmed).
Subprocessors and transfers
We use hosting, database, email, authentication, and model providers. The production subprocessor list and processing locations are to be published before private beta (to be confirmed). GitHub processes data under the permissions you grant to the GitHub App.
Your controls
You can restrict access to individual repositories in GitHub and remove the GitHub App at any time. Depending on where you live, you may also request access, correction, export, deletion, or restriction of personal data. Contact privacy contact address (to be confirmed).
Changes
Material changes will be announced before they take effect. The date above identifies the current version. See also the terms of service.