Privacy

Plain-language data map

Effective 5 September 2026 · Draft until reviewed by counsel

Local use

The local path processes repository evidence on your machine. Rolt does not receive your code. GitHub and any installed agent you invoke may receive data under the access and provider policy you choose.

Hosted reviews

A hosted review sends the authorized source context for one pull-request head to Rolt infrastructure and to an approved model API through Rolt's own accounts. We keep the captured comparison, the result and the Story for the retention window your organization configures, then delete them with their artifacts.

What we never do by default

  • Train a global model on private code.
  • Upload raw authoring prompts unless you include one in a named cloud review.
  • Publish raw requirement documents to GitHub.

Learning

Team knowledge is governed, versioned context scoped to a repository or organization. It is inspectable, exportable and deletable by owners. Personal reviewing preferences stay local by default.

Zero data retention

No training and zero data retention are different promises. We use ZDR language only for provider, project and model routes whose eligibility has been verified.

Account data

Identity comes from your sign-in provider. We store a display profile, organization membership, session metadata and the usage ledger. You can export or request erasure of your personal data from your account page; organizations can request scoped export or erasure. Financial records required by law are retained.

Analytics

Product analytics never contain source code, prompts, repository names or replay. Counts and coarse campaign context only.