Legal

Privacy Policy

How GregoAI collects, uses, shares, secures, and retains personal information and customer code.

Effective July 13, 2026

This Privacy Policy explains how GregoAI ("GregoAI," "we," "us," and "our") collects, uses, shares, and retains personal information when you visit our websites, request access, create an account, connect a repository, or use our security scanning services (collectively, the "Service").

This policy applies globally as a baseline. Local law may provide additional rights. If your organization has a separate written agreement with GregoAI, that agreement may include additional privacy or data-processing terms.

1. Information we collect

We may collect the following categories of information:

  • Contact and access-request data, such as name, work email, company or project, repository URL, and any message you submit.
  • Account data, such as email address, display name, authentication events, access status, role, and account settings.
  • Repository and integration data, such as repository owner and name, visibility, branch or pull-request references, installation identifiers, and integration status.
  • Customer Content, including selected source code, repository files, scan scope, instructions, findings, reports, and exported results.
  • Billing and usage data, such as credit balance, transactions, scan estimates, scan status, and feature activity.
  • Technical and security data, such as IP address, user agent, request timestamps, device or browser information, logs, rate-limit events, abuse-prevention signals, and error diagnostics.
  • Communications you send to us, including support, sales, legal, and account-deletion requests.

2. How we collect information

We collect information directly from you, automatically when you use the Service, from an organization that manages your access, and from services you connect, such as a source-code hosting provider. We may also receive limited information from vendors that help us operate, secure, and communicate about the Service.

3. How we use information

We use information to:

  • review access requests and create, authenticate, and administer accounts;
  • connect authorized repositories, estimate scans, process selected code, and produce findings and reports;
  • provide support, service communications, run-status notices, and security alerts;
  • operate credits, billing records, exports, and account-deletion workflows;
  • protect the Service, enforce limits, prevent spam and abuse, and investigate incidents;
  • monitor reliability, understand aggregate product usage, and improve Service operation;
  • comply with law, resolve disputes, and enforce agreements; and
  • carry out another purpose that we disclose when collecting information or that you authorize.

4. Source code and AI processing

We process only the repository content and scope made available through your authorized use of the Service. Private code may be processed by infrastructure, security-analysis, and AI service providers acting on our behalf and subject to contractual or technical restrictions appropriate to their role.

We do not use Customer Content or customer-specific reports to train general-purpose models, and we do not share one customer's private code or reports with another customer.

5. How we share information

We do not sell personal information, and we do not use personal information for third-party behavioral advertising. We may disclose information to the following categories of recipients when reasonably necessary:

  • cloud hosting, database, storage, authentication, and infrastructure providers;
  • source-code hosting and integration providers you choose to connect;
  • security, abuse-prevention, observability, and incident-response providers;
  • email, support, and operational communications providers;
  • AI and security-analysis providers used to deliver scan functionality;
  • professional advisers, auditors, insurers, regulators, or law-enforcement authorities when legally appropriate; and
  • a buyer, investor, successor, or other party involved in a merger, financing, reorganization, or sale of all or part of our business, subject to appropriate safeguards.

6. Cookies and local storage

We use cookies and similar browser storage that are necessary for authentication, session continuity, security, abuse prevention, and user preferences such as theme or sidebar state. We may record aggregated first-party page-view and product-usage metrics. We do not use third-party advertising cookies.

7. Retention

We generally retain account data, Customer Content, scans, reports, and transaction history while your account is active so that we can provide the Service, support you, and maintain a usable history. Access requests and operational or security logs may be kept for as long as reasonably necessary for business, security, anti-abuse, and legal purposes.

Following a verified account-deletion request, we aim to remove active account data and Customer Content within 30 days, except where we must retain information to comply with law, complete legitimate transactions, prevent fraud or abuse, resolve disputes, or enforce agreements. Residual copies may remain temporarily in backups until those backups rotate.

8. International processing

GregoAI and its providers may process information in countries other than where you live or work. Those countries may have different data-protection laws. Where required, we use contractual or other recognized safeguards for international transfers.

9. Security

We use administrative, technical, and organizational measures designed to protect information, including access controls, scoped integrations, short-lived credentials where supported, encryption in transit, and monitoring. No method of transmission, processing, or storage is completely secure, and we cannot guarantee absolute security.

You are responsible for protecting your account, controlling repository permissions, and promptly reporting suspected unauthorized access to grego@grego.ai.

10. Your choices and rights

Depending on where you are located, you may have rights to access, correct, export, delete, restrict, or object to certain processing of your personal information, or to withdraw consent where processing relies on consent. You may update available account information, export account data, or request account deletion through Settings.

You may also submit a privacy request to grego@grego.ai. We may need to verify your identity and authority before completing a request. We will not discriminate against you for exercising a privacy right. You may have the right to complain to a local data-protection authority.

11. Children

The Service is intended for businesses and professionals and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information to us, contact grego@grego.ai.

12. Changes to this policy

We may update this Privacy Policy as the Service or applicable requirements change. We will post the updated policy and change the effective date. If a change is material, we will provide reasonable notice through the Service or by email when practicable.

13. Contact

For privacy questions, data requests, or complaints, contact grego@grego.ai.