compatcompatSign in

Privacy

compat processes your source code to keep integrations current. We keep the minimum needed to run and explain a job, and we never keep a copy of your code.

Last updated 15 September 2026

What we store

For upstream monitoring we also store, per repository, the SDK packages detected, their versions, the latest published version we saw, and proposals derived from public release notes together with the model's relevance judgement. None of this includes your source code.

  • Account: your email address and, when you sign in with GitHub, the identity GitHub returns. Used for sign-in and notifications.
  • Organization: the organization name you create in compat and its members.
  • Repository metadata: the GitHub installation id, repository names, default branches and visibility for repositories you connected.
  • Job evidence: the migration you described, the plan, the pipeline states a job moved through, which checks ran and their results, and short excerpts of command output. Excerpts are truncated and redacted before they are stored.
  • Pull request metadata: the branch name, pull request number and URL that compat opened.

What we do not store

  • No persistent copy of your source code. Repositories are cloned into a sandbox that is destroyed when the job ends.
  • No GitHub tokens. We keep the installation id and mint a short-lived token for each job.
  • No environment variables, secrets or credentials from your repository or CI.

How we use it

To run the jobs you request, to open pull requests in the repositories you connected, to notify you when a job finishes or fails, and to support you. We do not sell data and we do not use your code or job evidence to train models.

Subprocessors

ProviderPurpose
SupabaseAuthentication and the database that holds the records above.
GitHubRepository access through the compat GitHub App, branches and pull requests.
E2BDisposable sandboxes in which jobs clone, edit and verify your repository.
AnthropicThe model that plans and edits. Receives the relevant repository content during a job.
ResendTransactional email such as sign-in links and job notifications.
VercelHosting for this website and the application.

Retention and deletion

Job evidence is kept while your organization exists so you can look back at what changed and why. Ask us to delete your organization and we remove the account, organization, repository metadata and job records. Uninstalling the GitHub App revokes our access immediately.

Contact

Questions about this policy go to hello@compat.dev.