Truecount
Draft. Not yet in effect. Every item marked CONFIRM must be settled, and true of the running service, before launch.

Privacy

What Truecount receives, what it keeps, and where your code goes when a model reads it.

Who we are

Truecount is operated by CONFIRM: legal entity name and address. Contact: support@truecount.dev.

What we receive from GitHub

What we store

RecordContentsKept for
InstallationAccount login, id and type; the plan it is on; when it was installed, suspended or removedWhile installed, then 90 days after you uninstall
RepositoryId, name, public or private; when it was added or removedWhile installed, then 90 days after it is removed
JobRepository name, pull request number, commit ids, what triggered it, and whether it succeeded90 days after it finishes
Agent runRepository id, workflow run id, agent, trigger, the commit it audited, whether it finished, and the link to any pull request it opened90 days
Event receiptGitHub's delivery id and event type, so a resent event is not handled twice7 days

CONFIRM: these are the windows the code enforces today. Confirm them before launch. Expired records are deleted every hour.

We do not store your source code, diffs, pull request text, or what a model wrote about them. They are read when a job runs and kept only as long as the job takes. The review itself is posted to GitHub and lives there.

Where your code goes when a model reads it

Reviews and agents send code to a language model. By default that model runs on hardware we own and operate, not on a cloud provider's. CONFIRM: the inference gateway is configured not to log prompts or responses.

On paid plans, when our own hardware is busy or unavailable, a job may instead go through OpenRouter to a third-party model provider. CONFIRM: name the providers allowed, and that the routing is restricted to providers that neither retain nor train on prompts. Free plans never leave our hardware: a job waits instead.

We do not use your code to train models, and we do not sell or share it.

This website

truecount.dev sets no cookies, runs no analytics and loads no JavaScript. It is served by Cloudflare, which processes your IP address to deliver the pages.

Your choices

Changes

If this policy changes, the new version will be posted here with its date. CONFIRM: effective date.