Legal

Privacy Policy

Plain words about what DocFit reads, what it keeps and how to make it go away.

Draft for the early-access period. This policy will be reviewed by counsel before general availability.

Summary

  • DocFit reads merged pull requests, their linked tickets and your docs to write docs PRs.
  • Your source code is cloned for one run and deleted when the run ends. It is never used to train models.
  • We don't sell data, and this website uses no tracking cookies or third-party analytics.
  • You can delete repositories, rules, integrations or the whole workspace from the dashboard at any time.

This website

docfit.dev is a static website. It sets no cookies, runs no analytics or advertising scripts and loads its fonts from its own domain. Our hosting provider (Google Firebase Hosting) keeps standard server logs, such as IP address, user agent and requested page, for security and reliability. If you email us through the contact page, we receive what you write and your email address.

What DocFit reads

For each repository you enable, DocFit reads merged pull requests (title, description, diff, commits and review comments), the documentation folder, and, when connected, the linked Jira or GitHub issue. Code is cloned into a temporary container for the duration of one run and deleted when the run ends. DocFit does not read repositories you have not enabled.

What DocFit stores

  • Your GitHub account id, login, name, avatar and email address, to sign you in and send notifications.
  • Run records: which pull request was processed (its title and number), a summary of the change, which pages changed, the docs diff and edited pages, check results and model usage. These are kept while your workspace exists. Run logs are kept for the period you choose in Settings (7, 30 or 90 days).
  • Your documentation pages, split by heading and stored with embeddings, and the names of code symbols from diffs, so DocFit can find the pages a change affects. They are deleted with your workspace, or within 30 days of uninstalling DocFit.
  • Rules your team teaches DocFit through pull-request replies and edits, until you delete them.
  • Encrypted OAuth tokens for Jira and Slack and, if you provide one, your own model API key. They are encrypted at rest and decrypted only inside a run.
  • Billing details handled by our payment provider; we store your plan, billing email and tax number.

How we use it

We use this data to run the service for your workspace: to produce docs PRs, show what each run did, apply your team's rules, send the notifications you ask for and bill your plan. We use aggregate, non-identifying measures (such as run counts and durations) to keep the service reliable. We do not use your code, docs or tickets to train models, and we do not sell personal data.

Who processes it

DocFit runs on Google Cloud with a MongoDB Atlas database on Google Cloud. Model requests go to Google Vertex AI and, for some models, Anthropic; only the parts of a change needed to write documentation are sent. Email is sent through Resend, payments through Dodo Payments, and Slack and Jira messages through those services when you connect them. The full list is on the Security page. Some providers process data outside your country, under their standard data protection terms.

Retention

Run logs are kept for the period you choose in Settings. Run records, including docs diffs, and other workspace data are kept while the workspace exists. When you delete a workspace, or uninstall the GitHub App, stored data is purged after a 30-day grace period. Backups age out on their own schedule.

Your choices and rights

You can change retention, disconnect integrations, delete rules, remove repositories and delete the workspace from the dashboard. Uninstalling the GitHub App stops all access immediately. Depending on where you live you may have rights to access, correct, export or delete your personal data, or to object to its use; email privacy@docfit.dev and we'll respond within 30 days.

Security

Tokens and keys are encrypted with AES-256-GCM, every query is scoped to your workspace and traffic is encrypted in transit. Details are on the Security page.

Changes

If we change this policy in a way that matters, we'll update the date above and tell workspace admins by email before the change takes effect.

Contact

Privacy questions and requests: privacy@docfit.dev.