Privacy Policy

Last updated: October 1, 2025

1. Introduction

ObbyLabs ("we", "us", or "our") operates diff0, an AI-powered code review service. This Privacy Policy explains how we collect, use, and protect your personal information when you use our Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Name and email address (from GitHub OAuth)
  • GitHub profile information (username, avatar)
  • Account preferences and settings

2.2 GitHub Integration Data

When you connect your GitHub account, we access:

  • Repository information (names, descriptions)
  • Pull request data (code changes, comments, metadata)
  • Installation and permission details

2.3 Usage Data

  • Credit transactions and balance information
  • Review history and results
  • Service usage patterns and analytics
  • Technical data (IP address, browser type, device information)

2.4 Code Data

We process your code temporarily to perform AI reviews. Code is not stored permanently after review completion unless required for troubleshooting specific issues.

3. How We Use Your Information

  • To provide and maintain the AI code review service
  • To process payments and manage your credit balance
  • To send service-related notifications and updates
  • To improve our AI models and service quality
  • To detect and prevent abuse or fraud
  • To comply with legal obligations

4. Data Storage and Security

Your data is stored securely using industry-standard practices:

  • Encrypted data transmission (HTTPS/TLS)
  • Secure database storage with access controls
  • Regular security audits and updates
  • Limited access to authorized personnel only

While we implement reasonable security measures, no method of transmission over the internet or electronic storage is 100% secure.

5. Data Sharing

We do not sell your personal information. We may share data with:

  • Service Providers: Third-party services that help us operate (e.g., Convex for database, Dodopayments for payments, OpenAI for AI processing)
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

6. Third-Party Services

We use the following third-party services:

  • GitHub: For authentication and repository access
  • Convex: For database and backend services
  • Dodopayments: For payment processing
  • OpenAI: For AI code analysis

Each service has its own privacy policy. We encourage you to review their policies.

7. Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data
  • Withdraw consent for data processing
  • Object to certain processing activities

To exercise these rights, contact us at legal@obby.dev.

8. Data Retention

  • Account data is retained while your account is active
  • Transaction records are kept for legal and accounting purposes
  • Code data is processed temporarily and deleted after review completion
  • Analytics data may be retained in anonymized form

9. Cookies and Tracking

We use essential cookies for authentication and session management. We may use analytics tools to understand how users interact with our Service.

10. Children's Privacy

Our Service is not intended for users under 13 years of age. We do not knowingly collect information from children under 13.

11. International Data Transfers

We operate from the United Arab Emirates. Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes via email or through the Service. Continued use after changes constitutes acceptance.

13. Open Source

diff0 is open source software under the MIT License. You can review our code on GitHubto understand how we handle your data.

14. Contact Us

For privacy-related questions or concerns: