Code Audit Studio

Privacy policy

Prepared July 18, 2026

Code Audit Studio processes source only when a user explicitly requests an analysis. Needly Labs keeps no source or report history.

Data processed

The app processes source or a unified diff pasted into the form; local text/source files the user selects; supported files fetched from an explicitly supplied public GitHub repository; optional focus instructions; the private-beta access key; and minimal request metadata such as network address, request identifier, counts, timing, and bounded error type.

Where source goes

On Generate, pasted or selected source travels over HTTPS to the Code Audit Studio service on Render in Frankfurt, Germany. Public repository requests cause the service to fetch a bounded source subset through the GitHub API. The service then sends the selected source and focus request to the OpenAI Responses API. The generated brief returns to the browser.

Storage and retention

Needly Labs uses no application database, object storage, source history, or report history for this private beta. Source and reports exist in browser and server-process memory for the active request. The app sets store: false, so it does not create persisted Responses application state. OpenAI states that standard abuse-monitoring logs may retain API customer content for up to 30 days and that encrypted prompt-cache state may last up to 24 hours. API inputs and outputs are not used to train OpenAI models unless the API organization explicitly opts in. See OpenAI API data controls.

Access and operational metadata

The beta access key is held in page memory, sent in an HTTPS request header, compared by the service, and not written to browser storage or intentional application logs. The service HMAC-hashes the counter namespace and network identifier before persisting only the hash, count, and reset time on its local filesystem. Analysis counters last up to 24 hours and failed-key counters last 15 minutes. This state can survive a process restart but can reset during a deployment or replacement instance. Metadata-only service logs exclude source, focus text, keys, and model output.

Export and deletion

The user can copy or download Markdown and print/save the brief as PDF. Closing the page clears its in-page state. Because Needly Labs creates no server-side source or report record, there is no content-history export or deletion request to perform. Expiring hashed counters and provider retention are described above.

Consequential actions

The app generates advice. It does not execute source, change a repository, open a pull request, submit a review, install software, or publish an artifact. AI output can be incomplete or wrong; users must verify findings against the supplied source before acting.

Questions

Email needlylabs@gmail.com. Include the request reference and approximate UTC time if available. Do not email source, access keys, tokens, passwords, personal data, or generated reports.

← Back to the product