Code Audit Studio

Privacy policy

Updated August 28, 2026

Code Audit Studio processes source only when a user explicitly requests an analysis. Needly Labs keeps no source or report history.

Data processed

The app processes source or a unified diff pasted into the form; local text/source files the user selects; supported source and patches fetched from an explicitly supplied public GitHub repository or pull request; optional focus instructions; public GitHub profile identity when the user signs in; a bounded pull-request diff and minimal pull-request metadata supplied by the GitHub Action; and basic request metadata needed for abuse prevention and operation, such as IP address, request identifier, counts, timing, and bounded error type. GitHub sign-in requests public profile identity only and does not request email, private-repository, organization, or repository-write access.

Where source goes

On Generate, pasted or selected source travels over HTTPS to the Code Audit Studio service on Render in Frankfurt, Germany. Public repository requests cause the service to fetch a bounded source subset through the GitHub API only after GitHub explicitly reports that the repository is not private. The service then sends the selected source and focus request to the OpenAI Responses API. The generated brief returns to the browser.

Eligible same-repository private pull requests can be reviewed only through the read-only GitHub Action. Its GitHub workflow token stays inside GitHub Actions. The Action sends the bounded current diff and minimal pull-request metadata to Code Audit Studio using a separate Code Audit Studio access token. The Action does not send the GitHub token, check out or execute repository code, or request write access.

Storage and retention

Needly Labs uses no object storage, source history, or report history. Source and reports exist in browser and server-process memory for the active request. The dedicated account database stores the GitHub numeric ID, login, public display name and avatar URL; plan and Paddle customer, subscription, status, and checkout timestamps; SHA-256 hashes of sessions and Action access tokens; and content-free monthly usage records. A usage record contains a random request ID, account ID, calendar-month period, plan, web-or-Action surface, completion state, and token counts. It does not store filenames, repository names or URLs, source, focus text, reports, GitHub OAuth tokens, or plaintext Action tokens. Needly Labs-owned and invented test accounts also carry a QA flag so internal testing is excluded from genuine account, conversion, paid-use, and retention totals.

The app sets store: false, so it does not create persisted Responses application state. OpenAI states that standard abuse-monitoring logs may retain API customer content for up to 30 days and that encrypted prompt-cache state may last up to 24 hours. API inputs and outputs are not used to train OpenAI models unless the API organization explicitly opts in. See OpenAI API data controls.

Accounts, billing, and operational metadata

A Secure, HttpOnly, SameSite cookie holds a random session token. Only its SHA-256 hash is stored. Paddle hosts checkout and billing management and sends signed subscription lifecycle events to Needly Labs. Paddle's own privacy and retention terms apply to the billing information it processes. Metadata-only service logs exclude source, focus text, credentials, and model output.

Export and deletion

The user can copy or download Markdown and print/save the brief as PDF. Closing the page clears its in-page state. There is no server-side content history to export or delete. Users can sign out, revoke Action tokens, and delete a Free account from the account panel. A paid user must cancel in Paddle and wait for the paid entitlement to end before account deletion, which prevents an active subscription from becoming detached from its account. Provider retention is described above.

Consequential actions

The app generates advice. It does not execute source, change a repository, open a pull request, submit a review, install software, or publish an artifact. The read-only GitHub Action fetches the triggering pull request diff, sends it with minimal repository and commit context for the requested audit, and writes the result to the workflow summary. It never checks out or executes repository code. AI output can be incomplete or wrong; users must verify findings against the supplied source before acting.

Questions

Email needlylabs@gmail.com. Include the request reference and approximate UTC time if available. Do not email source, access keys, tokens, passwords, personal data, or generated reports.

← Back to the product