Corrigio is a self-healing API integration agent. We watch the APIs your codebase depends on, detect breaking changes, and open pull requests with verified fixes. That work requires us to touch a small, well-defined set of data — your GitHub identity, repository metadata, OpenAPI specifications, and the patches we generate. This policy explains exactly what we touch, why, how long we keep it, and the controls you have over it.
1. Overview & scope
This Privacy Policy applies to the Corrigio web application (the "Service"), our CLI, our GitHub App, and any documentation, marketing, or support channels that link back to it. It covers personal data processed by Corrigio("we", "us") on behalf of the individuals and organizations that use the Service ("you", "users").
Where Corrigio processes personal data on behalf of a customer organization — for example, when an administrator connects a workspace's GitHub account — we act as a data processor and the customer organization acts as the data controller. The terms of that processing are governed by our Terms of Service and, where applicable, a Data Processing Addendum available on request. For personal data we collect directly from you (such as your email address when you create an account), Corrigio is the data controller.
This policy does not apply to the websites or services of third parties, including GitHub, Clerk, Vercel, or any API provider whose specifications you monitor through Corrigio. Their privacy practices are governed by their own policies.
2. Who is responsible for your data
Data controller: Corrigio, responsible for the personal data we collect directly from you (account, billing, support communications).
Data processor: Corrigio, acting on the instructions of a customer organization when processing workspace data (repositories, API sources, generated patches).
Contact: You can reach us at support@corrigio.tech for any privacy-related question, including requests to exercise the rights described later in this policy.
3. The data we collect
We collect only the data we need to operate the Service, keep it secure, and comply with our legal obligations. We do not sell personal data, and we do not run advertising trackers on the Service.
3.1 Data you provide directly
- Account data: your email address, display name, and avatar, obtained via GitHub OAuth through our authentication provider, Clerk. We do not collect or store passwords.
- Workspace data: the name of the workspace you create, the repositories you choose to monitor, and the API sources you register (name, spec URL, or uploaded OpenAPI document).
- Support & communications: the contents of any email, support ticket, or chat message you send us, plus the metadata needed to reply.
- Optional profile data: role, company size, and similar fields you may provide during onboarding. All optional fields are clearly marked.
3.2 Data we collect automatically
- Usage telemetry: which features you use, when, and for how long. We use this to improve the product and to detect abuse. Telemetry is aggregated where possible and never includes the contents of your source code beyond what is needed to render a patch.
- Device & session data: IP address, browser type, operating system, and referring URL. Retained for up to 30 days for security and abuse prevention.
- Diagnostic logs: server-side logs of API requests to our own endpoints, used for debugging and incident response.
3.3 Data we generate on your behalf
- Diff results: the structured output of comparing two OpenAPI specifications, including detected breaking changes.
- Patch artifacts: the file edits, confidence scores, and PR bodies we generate. These are derived from your source code and the API specifications you monitor.
- Audit log entries: records of who changed what in a workspace, retained for the lifetime of the workspace plus 90 days.
4. How and why we use it
We process personal data for the following purposes, each tied to a specific legal basis described in the next section:
| Purpose | What we process | Why |
|---|---|---|
| Provide the Service | Account, workspace, repo, spec data | To detect changes and generate patches |
| Open pull requests | Repo metadata, generated patch content | To deliver the core product feature |
| Authenticate you | GitHub identity via Clerk | To let you sign in securely without passwords |
| Communicate with you | Email address, message contents | For product, security, and support updates |
| Improve the product | Aggregated usage telemetry | To decide what to build next |
| Prevent abuse | IP, device fingerprint, request logs | To detect fraud, scraping, and attacks |
| Comply with law | Identity, billing, tax records | To meet legal and tax obligations |
5. Legal bases for processing
For users in the European Economic Area, the United Kingdom, and any other jurisdiction with a similar legal framework, we rely on the following bases under the GDPR:
- Performance of a contract (Art. 6(1)(b)) — for processing needed to provide the Service you signed up for, including reading your repositories and opening pull requests.
- Legitimate interests (Art. 6(1)(f)) — for product improvement, security, abuse prevention, and analytics, each balanced against your reasonable expectations and rights.
- Consent (Art. 6(1)(a)) — for optional communications and for any non-essential cookies. You can withdraw consent at any time without losing access to the Service.
- Legal obligation (Art. 6(1)(c)) — for record keeping required by tax, accounting, or other applicable law.
6. What we read from your GitHub account
Corrigio integrates with GitHub through OAuth and a GitHub App. The scope of access is intentionally narrow:
- Read access to repository metadata, OpenAPI specification files, and the source files we search for affected call sites.
- Write access limited to creating branches, commits, and pull requests in repositories you explicitly connect. We never push to a default branch.
- Webhook access to receive push events for spec files on default branches, so we can detect changes promptly.
Scope is per-repository, not blanket
We do not read your GitHub direct messages, pull request review comments unrelated to Corrigio activity, or any repository you have not explicitly connected.
7. Data retention
We keep personal data only as long as necessary for the purposes described in this policy, then delete it or anonymize it. The following table lists our standard retention periods:
| Data category | Retention period | Basis |
|---|---|---|
| Account data | Until account closure + 30 days | Contract |
| Workspace & repo metadata | Lifetime of workspace + 90 days | Contract |
| OpenAPI spec snapshots | Lifetime of workspace + 90 days | Contract |
| Generated patches & PR bodies | Until PR is closed + 90 days | Contract |
| Audit logs | Lifetime of workspace + 90 days | Legitimate interest / law |
| Server & access logs | 30 days | Security |
| Support communications | 2 years from last contact | Legitimate interest |
| Billing & tax records | 7 years | Legal obligation |
When you delete your account, we initiate deletion of workspace data within 30 days. Backups containing that data may persist for up to 35 additional days for disaster-recovery purposes, after which they are overwritten.
8. Sharing & subprocessors
We do not sell personal data. We share it only with subprocessors who help us operate the Service, and only under written contracts that impose GDPR-grade obligations. Our current subprocessors are:
| Provider | Purpose | Region |
|---|---|---|
| Clerk | Authentication & identity | United States |
| GitHub | Repository access & PR delivery | United States |
| Vercel | Web application hosting | United States / EU (configurable) |
| Supabase | Database & background jobs | EU or US (per workspace) |
| Postmark | Transactional email | United States |
| Sentry | Error monitoring (PII scrubbed) | EU |
We may also disclose personal data where required by law, court order, or to protect the rights, safety, or property of Corrigio, our users, or the public. We challenge requests we believe are overbroad or unlawful.
The current list of subprocessors is published at /legal/security and is updated at least 30 days before we add a new subprocessor that handles customer data. You can subscribe to subprocessor change notifications from your workspace settings.
9. International data transfers
Corrigio uses infrastructure that may store or process data in multiple regions, including the United States and the European Union, through our subprocessors. Where personal data is transferred from the EEA, UK, or Switzerland to a third country, we rely on:
- The European Commission's adequacy decision for the destination country, where applicable; or
- Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented by transfer impact assessments and, where necessary, supplementary technical measures such as encryption in transit and at rest.
A copy of our SCCs and our latest transfer impact assessment is available to customers under NDA on request to support@corrigio.tech.
10. Security of your data
We encrypt personal data in transit using TLS 1.2+ and at rest using AES-256. Access to production systems is restricted by role, enforced with single sign-on and hardware-backed multi-factor authentication, and logged for audit. We do not store GitHub tokens in plaintext; tokens are held by Clerk or, for GitHub App installations, exchanged on demand from short-lived JWTs.
A complete description of our security architecture, certifications, and incident response process is in our Security Overview.
11. Your rights & choices
Depending on where you live, you may have some or all of the following rights over your personal data:
- Access — a copy of the data we hold about you.
- Rectification — correction of inaccurate data.
- Erasure — deletion of your data, subject to legal exceptions.
- Restriction — asking us to pause processing.
- Portability — receiving your data in a structured, machine-readable format.
- Objection — objecting to processing based on legitimate interests.
- Withdrawal of consent — at any time, without affecting prior processing.
- Automated decision-making — you have the right not to be subject to solely automated decisions with legal or similarly significant effects. Corrigio's patch generation is automated but never applies changes to a default branch; a human reviewer on your team must merge every pull request.
To exercise any right, email support@corrigio.tech from the address associated with your account. We respond within 30 days, and within 72 hours for urgent erasure requests following account closure.
California, Virginia, and Colorado residents
12. Cookies & similar technologies
We use cookies and similar technologies for three purposes only: authentication (keeping you signed in), security (preventing CSRF and session hijacking), and product analytics (understanding which features are used). We do not use cookies for advertising.
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
__clerk_dbjs | Authentication session | 1 year | Strictly necessary |
__clerk_status | Authentication state | Session | Strictly necessary |
corrigio_csrf | CSRF protection | Session | Strictly necessary |
corrigio_anon_id | Privacy-preserving analytics | 13 months | Analytics (opt-out) |
You can opt out of analytics cookies from the cookie banner shown on first visit or from your workspace settings at any time. Strictly necessary cookies cannot be disabled because the Service will not function without them.
13. Children's privacy
The Service is intended for professional developers and organizations. We do not knowingly collect personal data from anyone under 16 (or the minimum age of digital consent in their jurisdiction). If you believe we have collected data from a minor, contact support@corrigio.tech and we will delete it promptly.
14. Changes to this policy
We update this policy as the Service evolves. When we make material changes, we bump the version number above, update the "last updated" date, and notify signed-in users at least 30 days before the change takes effect. A changelog of material amendments is available on request.
For sub-material changes (typography, structural clarifications that do not change meaning), we update the "last updated" date without prior notice.
15. Contacting us
You can reach us at support@corrigio.tech for any question about this policy or your personal data, including requests to exercise the rights described above.
If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. In the EU, you can find your authority at edpb.europa.eu. In the UK, the authority is the ICO.
Continue reading
This document is maintained by Corrigio and is published from a single source of truth in our repository. If you spot an inconsistency or have a question about how a clause applies to your integration, contact support@corrigio.tech. For security-specific inquiries, including vulnerability reports, see the Security Overview's reporting section.