Data handling
What Warpway stores, for how long, what it sends to Slack and to the model provider, and how deletion works.
This page lists what Warpway stores, where, and for how long; what it sends to Slack and to its model provider; and how deletion works. The Privacy Policy is the legal version of the same commitments.
What Warpway stores
| Data | Stored | Kept |
|---|---|---|
| Your GitHub profile from sign-in (user id, username, name, avatar, email when GitHub shares it) | Yes | While your account exists |
| Sign-in sessions: a hash of the session token, your GitHub sign-in token (encrypted), a hash of your IP address and your browser's user agent | Yes | While your account exists |
| Organization, installation, repositories, settings and roles | Yes | While the organization exists |
| Pull request details (number, title, author, branches, commits reviewed) | Yes | While the organization exists |
The pull request snapshot a review works from: title, description, comments, reviews, linked issues, commit messages, CODEOWNERS, your .warpway.yml, and the changed files with their diff | Yes, so every lens reviews the same snapshot | Retention period |
| Review records: plans, lens results, findings, human tasks with the answers that resolved them, routing decisions, policy results | Yes | While the organization exists |
| Evidence: code excerpts of up to 4 KB each, with a title, a summary and the file location | Yes | Excerpts for the retention period; the rest while the organization exists |
| Task conversations: the messages about a task exchanged in Slack, on GitHub or in the dashboard | Yes | Message text for the retention period |
| Webhook payloads from GitHub, Slack and Stripe | Yes, for processing and replay protection | Payloads are deleted after 7 days; the delivery id is kept so a replay is still recognized |
| A full snapshot of the repository | No | Only in the review worker's temporary storage, in a small cache that discards older snapshots as new commits are reviewed |
| Model prompts and raw responses | No | Only metadata is stored: model, prompt version, token counts, cost, duration and status |
| Tool calls made by lenses | Arguments only (paths, search terms, line ranges), never file contents | While the organization exists |
| People: names, GitHub usernames, Slack user ids, titles, verified email addresses and expertise | Yes | While the organization exists |
| Slack: workspace id and name, encrypted bot token, and the workspace's member directory (names, titles and time zones; email addresses only if email matching is on) | Yes | While the organization exists |
| Audit events (never source code) | Yes | While the organization exists |
| Billing: plan, subscription status, seats, Stripe customer id | Yes; card details stay with Stripe | While the organization exists; Stripe keeps invoices and payment records as tax and accounting law requires |
| First-touch marketing attribution (UTM parameters, referring domain, landing page) | Yes, on your account if you sign up | While your account exists |
Retention
Each organization has a retention period for review content: 180 days by default. An Owner can set it from 7 to 3,650 days in organization settings. A scheduled job deletes review content older than the period: the stored pull request snapshots, evidence excerpts and the text of task conversations. Webhook payloads are deleted after 7 days, whatever the period. Shortening the period applies to existing data at the next run of that job.
The review records themselves (statuses, findings, questions and the answers that resolved them, routing decisions and policy results) are kept until the organization is deleted, so review history and analytics stay available.
Deleted data can remain in encrypted database backups until those backups expire.
Where data lives
Warpway's database is Neon Postgres in AWS us-east-1, and the application runs on Vercel. Data is processed in the United States. See the subprocessor list.
Slack messages
Slack messages are written for the person answering, not for a code reviewer. A task message contains the repository and pull request (number and title), the question in plain language, what the code does today, why it matters, why the person was chosen, answer buttons and a signed link to the details.
They do not contain diffs or source files, and Warpway does not read channels: it reads only the direct messages people exchange with the Warpway app. The text of a conversation is stored with the task it belongs to. An answer that settles a question also becomes evidence for that review, and GitHub only ever sees a one-line summary of it. Warpway may draft a reusable organization rule from an answer, but the rule applies only after an Admin approves it.
What the model provider receives
To review a pull request, Warpway sends OpenAI's API the parts of the change a step needs: the diff, file excerpts the lenses read, pull request text, comments and commit messages, linked issues, CI and runtime verification results, your lens instructions and rules, relevant organization knowledge, the GitHub usernames and routing targets of people who may be asked, and answers to the pull request's questions. Warpway does not train models on your code, and OpenAI does not train its models on data sent through its API unless a customer opts in, which Warpway has not. See Model providers.
Logs
Application logs contain identifiers, counts, durations and statuses. A redacting logger drops fields that carry code, diffs, file contents, prompts, model output, questions and answers, shortens other long text, and masks secrets such as tokens and keys wherever they appear. Hosting logs are kept for a short period for operations and security.
Feedback
Feedback your team gives, such as marking a finding as a false positive, saying a question went to the wrong person, or reporting an issue Warpway missed, is used to measure and improve review quality. It is never used to train AI models, and it never changes your policy by itself.
Deletion
- Your account: email marcus@cmglabs.ai.
- An organization: an Owner deletes it from organization settings. A background job revokes Warpway's Slack token, then removes everything tied to the organization; a record that the deletion happened is kept, with counts of what was removed and no customer content.
- Uninstalling the GitHub App or disconnecting Slack stops access but does not delete data by itself.
Deletion requests are completed within 30 days. See Uninstall and deletion.
Something unclear or missing? Email marcus@cmglabs.ai.