Current as of 18 August 2026
Privacy notice
How the Amberly MVP handles personal data and product metadata.
Scope
This notice covers the Amberly marketing site and product MVP. It describes intended processing for local development and future hosted operation. It is not a claim of blanket GDPR compliance.
Data minimized by design
- Authentication email and session records
- GitHub installation, repository, pull-request, review, deployment, and delivery identifiers
- Derived change maps, agent reports, findings, Risk and Attention signals, and outcomes
- Allowlisted analytics metadata only after consent
Content boundaries
Amberly does not persist raw source, full patches, prompts, or model responses. PostHog never receives source, patches, prompts, findings, emails, or model output.
Retention and rights
Raw webhook payloads are cleared after 30 days, audit records after 400 days, and expired authentication material under the documented lifecycle policy. Hosted rights-request contact details must be completed before public launch.