Trust & Privacy
How we handle your code and data
This page answers common security and privacy questions about Repodex. It is not an independent audit or third-party certification.
What Repodex does
Repodex is a mobile companion for reviewing branches, reading diffs, and coordinating with an AI agent that drafts commits against your repositories. You stay in control of what lands on which branch.
Accounts & access
- Access to repositories follows the permissions of the Git provider account you sign in with — Repodex never escalates beyond what your account already has.
- You can revoke Repodex's access at any time from your Git provider's settings; this immediately cuts off new operations.
Data we collect
- TestFlight signups: email address only, used solely to send your TestFlight invite. Stored in our backend with public read access disabled.
- Operational data: minimal logs needed to keep the service running and debug errors.
- We do not sell your data and we do not use your code to train third-party models without your explicit opt-in.
Shared responsibility
Repodex is responsible for the app's code, configuration, and customer-facing controls described here. The underlying hosting and backend platform provides infrastructure-level controls such as encryption in transit, managed authentication primitives, and row-level access enforcement on our database — we configure those features but do not own the platform itself.