Information We Collect
When you connect CodePulse to your GitHub account, we collect and process the following information to provide our engineering analytics service.
What We Collect
- GitHub user profile (username, display name, avatar URL, email)
- Organization and repository names and metadata
- Pull request metadata (titles, authors, timestamps, review status, merge status)
- Commit metadata (SHA, author, timestamp, additions/deletions count)
- Code review activity, comments, and short diff context attached to inline comments
- CI/CD status check results (pass/fail status only)
What We Never Collect
- Your source files - we never clone your repository or read file contents
- Private messages or discussions outside connected pull requests and issues
- Private messages or team discussions
- Secrets, API keys, or environment variables
- CI/CD logs or deployment configurations
- Personal data beyond your GitHub profile
How We Use Your Information
We use your information solely to provide and improve the CodePulse engineering analytics service:
Analytics & Metrics: - Calculate DORA metrics (deployment frequency, lead time, change failure rate, MTTR) - Generate cycle time analysis and team velocity metrics - Identify knowledge silos and collaboration patterns - Create developer leaderboards and recognition systems
Service Operation: - Authenticate your identity via GitHub OAuth - Display dashboards and reports in the CodePulse interface - Send service-related notifications (sync status, alerts you configure)
Service Improvement: - Aggregate anonymized usage patterns to improve the product - Debug and fix technical issues
We do NOT: - Sell your data to third parties - Use your data for advertising - Share individual developer metrics outside your organization - Train AI models on your code or data
Data Storage & Security
Your data security is our top priority. Here's how we protect your information:
Encryption: - Production storage: Encrypted at rest - Connected-service credentials: GitHub tokens and webhook secrets are encrypted with Fernet (AES-128-CBC with HMAC-SHA256 authentication) before they are written to the database, and decrypted only in memory when a sync runs - Data in transit: TLS 1.2 or higher for every connection, with TLS 1.3 supported - Database connections: Encrypted and authenticated
Multi-Tenant Isolation: - Every customer-data query is scoped to your organization - Organization membership and role are verified before any protected request is served - Your organization's data is never combined with another organization's in a query result - Administrative actions are recorded in an audit log
Infrastructure: - Hosted on AWS in the EU (Ireland) region - CodePulse controls are mapped to the applicable SOC 2 Trust Services Criteria - Regular automated backups with encryption - Network isolation between components - Customer access flows through authenticated application APIs
Retention: - Active data retained while your account is active - Deleted data permanently removed within 30 days - Backup data purged according to backup rotation schedule
Data Sharing
We do NOT sell your data. Ever. Our business model is software subscriptions, not data brokering.
We do NOT share your data with third parties for marketing, advertising, or any commercial purposes.
Limited third-party services we use: - Cloud hosting provider (infrastructure only) - Error monitoring service (anonymized error reports only) - Google Analytics (anonymized usage analytics to understand user behavior) - Microsoft Clarity (session recording and analytics to improve user experience)
All third-party providers are vetted for security compliance and bound by data processing agreements that prohibit them from using your data for any purpose other than providing their service to us.
Legal Disclosure: We may disclose your information if required by law, court order, or government request. We will notify you of such requests unless legally prohibited from doing so.
Your Rights
You maintain full control over your data at all times:
Access: You can view all data we have about your organization through the CodePulse dashboard.
Export: Download all your organization's data as CSV files at any time. Every metric, every data point - it's yours.
Delete: Request deletion of all your organization's data from Settings. Once deleted, data is permanently removed from our systems within 30 days.
Revoke Access: You can revoke CodePulse's GitHub access at any time: 1. Go to GitHub → Settings → Applications → Authorized OAuth Apps 2. Find CodePulse and click "Revoke" 3. We immediately lose access to your repositories
Modify Scope: Add or remove repositories from analysis at any time. We only sync data from repositories you explicitly choose.
GDPR Rights (for EU users): - Right to access: Export all your data anytime - Right to rectification: Contact us to correct inaccurate data - Right to erasure: Delete all data with one click - Right to data portability: CSV export of all metrics - Right to object: Contact us to opt out of specific processing
Children's Privacy
CodePulse is a professional engineering analytics tool intended for use by software development teams and organizations.
Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
If you believe we have inadvertently collected information from a child under 13, please contact us immediately at privacy@codepulsehq.com and we will promptly delete such information.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons.
How we notify you: - Material changes: Email notification to account administrators - Minor changes: Updated "Last modified" date on this page - All changes: Posted to this page with revision history
Your continued use of CodePulse after changes are posted constitutes acceptance of the updated policy.
We encourage you to review this policy periodically.
Last modified: March 2026
Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
Keep Pushing Forward Ltd (trading as CodePulse) Registered in England and Wales. Based in Hampshire, UK.
Email: privacy@codepulsehq.com
For security concerns: security@codepulsehq.com
We aim to respond to all privacy inquiries within 5 business days.