Skip to content

Privacy Policy

Effective October 2, 2026

Warpway reviews GitHub pull requests for the organizations that install it. This policy explains what we collect, how we handle your code, how long we keep data, and how to have it deleted. It covers the Warpway website, documentation, dashboard, GitHub App and Slack app.

Who we are

Warpway is operated by CMG Labs, LLC, 3790 El Camino Real, Unit #593, Palo Alto, CA 94306, USA (“CMG Labs”, “we”, “us”). For anything privacy related, email marcus@cmglabs.ai.

For your account and our website we decide how personal data is used (we are the controller). For the code, pull requests and review records of an organization that installs Warpway, we process data on that organization’s behalf and follow its settings, such as its retention period (we act as a processor or service provider).

What we collect

When you sign in

Warpway uses GitHub to sign you in; there is no Warpway password. We receive your GitHub user ID, username, name, avatar URL and, when GitHub shares it, your email address, plus which of your GitHub installations you can access so we can confirm your membership. We keep a session record with a hash of your session token, an encrypted GitHub sign-in token, a hash of your IP address and your browser’s user agent.

When an organization installs Warpway

  • Organization and repository details: the GitHub account, installation, the repositories you select, settings, member roles and plan.
  • Pull request content: to review a pull request, Warpway reads the code and diff, commit metadata, the title, description, comments and reviews, CODEOWNERS, the .warpway.yml file, linked issues and CI results.
  • Review records: review plans, lens results, findings, evidence (including code excerpts of up to 4 KB each), human tasks and their conversations, routing decisions, policy results and audit events.
  • People and expertise: names, GitHub usernames, Slack user IDs, display names, titles and verified email addresses of people who can be asked questions, and expertise signals from CODEOWNERS, review and commit history. Slack email addresses are read only if an admin enables email matching.
  • Slack: the workspace ID and name, an encrypted bot token, the workspace’s member directory (Slack user IDs, names, titles and time zones, and email addresses only if an admin enables email matching), and the direct messages exchanged with the Warpway app about review tasks, including button choices. Warpway does not read channels.
  • Billing: plan, subscription status, seat count and Stripe customer ID. Card details are collected and held by Stripe; we never see the full card number.

Usage and technical data

Request logs (with code and secrets removed), counts and durations of reviews, and model usage records (model, token counts, cost, timing). Model usage records do not contain prompt or response text.

How you found us

The first time you visit, we set a first-party cookie, ww_attr, recording the UTM parameters in the link you followed, the referring site’s address (domain only), the page you landed on and the time. It lasts 90 days and is saved to your account if you sign up. It is not set if your browser sends a Global Privacy Control signal.

How we handle your code

  • Warpway can read only the repositories an organization selects when it installs the GitHub App.
  • Code is processed only to review pull requests. The parts a review needs are sent to our model provider, OpenAI, to analyze the change.
  • Your code is not used to train AI models. We do not train models on it, and OpenAI does not train on data sent through its API unless a customer opts in, which Warpway has not.
  • Repository snapshots used during a review are kept only in temporary storage on the review worker. Each review stores the pull request data it worked from, including the diff, and short code excerpts as evidence, until the organization’s retention period ends.
  • Code, diffs, prompts and answers are kept out of our logs.
  • Slack messages contain a plain-language question and a link, not diffs.

How we use data

  • To provide Warpway: review pull requests, route questions, send Slack messages and publish GitHub checks.
  • To secure the service: authenticate users, enforce permissions, rate limit and investigate abuse.
  • To bill organizations on paid plans.
  • To answer support requests and send service messages, such as security or billing notices.
  • To improve review quality: feedback your team gives on findings and tasks (such as “false positive” or a missed-issue report) is used to measure and improve Warpway. It is not used to train AI models.
  • To understand which channels bring people to Warpway, using the attribution cookie described above.

We do not sell personal data, and we do not share it for cross-context behavioral advertising.

Who we share data with

We share data only with these subprocessors, for the purposes listed:

Subprocessors
ProviderPurposeLocation
OpenAI, L.L.C.AI model provider (GPT models) that analyzes changes and drafts review resultsUnited States
Vercel, Inc.Hosting and serverless compute for the web app and API (sign-in, webhooks, dashboard)United States
Google LLC (Google Cloud)Compute for the review worker (Cloud Run) and its logsUnited States (us-east4, Virginia)
NeonManaged Postgres database (AWS us-east-1)United States (AWS us-east-1)
Stripe, Inc.Payments, subscriptions and invoicesUnited States

Warpway also acts in GitHub and Slack on your organization’s behalf, with the access you grant. We may disclose data when the law requires it, or as part of a merger or sale of our business, in which case this policy keeps applying to it. The current list is also on our security page.

How long we keep data

  • Review content (the pull request data a review worked from, including its diff, code excerpts kept as evidence, and the text of task conversations): for the organization’s retention period, 180 days by default. An Owner can set it from 7 to 3,650 days. A scheduled job deletes older content.
  • Review records (statuses, findings, questions and the answers that resolved them, routing decisions and policy results): while the organization exists; they are deleted with it.
  • Webhook payloads: 7 days. We keep the delivery ID so a repeated delivery is still recognized.
  • Account and organization data: while the account or organization exists.
  • Audit events: while the organization exists; they are deleted with it.
  • Billing records: as long as tax and accounting law requires.
  • Hosting logs: for a short period for operations and security.
  • The attribution cookie: 90 days in your browser.

Deleted data can remain in encrypted database backups until those backups expire.

Deleting data

An organization Owner can delete the organization’s data from its settings. Deletion runs as a background job and removes the organization’s repositories, reviews, tasks, people and settings; we keep a record that the deletion happened, without customer content. Uninstalling the GitHub App stops Warpway’s access but does not delete data on its own. To delete your personal account, email marcus@cmglabs.ai. We complete deletion requests within 30 days. Details are in Uninstall and deletion.

Cookies

  • Session cookie: keeps you signed in. Strictly necessary.
  • Sign-in state cookie: short-lived and single use; ties a GitHub or Slack sign-in flow to your browser to prevent forgery. Strictly necessary.
  • ww_attr: first-party attribution, described above. Not set with Global Privacy Control.

The Warpway app does not currently use third-party advertising or analytics cookies.

Security

We protect data with TLS, encryption at rest, encrypted tokens, least-privilege access, tenant isolation and audit logs. No system is perfectly secure; we will notify affected customers and authorities of a breach as the law requires. More on the security page.

International transfers

We and our subprocessors process data in the United States. For transfers from the UK, EU or EEA we rely on safeguards such as the European Commission’s standard contractual clauses and the UK addendum, or the EU-U.S. Data Privacy Framework where a provider is certified.

Legal bases (UK and EU)

  • Contract: to provide Warpway to you and your organization.
  • Legitimate interests: security, abuse prevention, improving review quality and understanding how people find us.
  • Legal obligation: billing and tax records.

Your rights

Depending on where you live, you can ask to access, correct, delete or export your personal data, object to or restrict how we use it, and complain to a data protection authority. California residents can ask what we collect and how we use it, and ask us to delete or correct it; we do not sell or share personal data and will not treat you differently for using these rights. Email marcus@cmglabs.ai. If your request concerns data an organization controls, such as review records, we will work with that organization to respond.

Children

Warpway is for professional use and is not directed to anyone under 16.

Changes to this policy

We will post changes here and update the effective date. If a change materially affects how we use data we already hold, we will email organization Owners before it takes effect.

Contact

CMG Labs, LLC, 3790 El Camino Real, Unit #593, Palo Alto, CA 94306, USA. Email marcus@cmglabs.ai.