Back to Amberly

Current as of 18 August 2026

Privacy notice

How the Amberly MVP handles personal data and product metadata.

Scope

This notice covers the Amberly marketing site and product MVP. It describes intended processing for local development and future hosted operation. It is not a claim of blanket GDPR compliance.

Data minimized by design

  • Authentication email and session records
  • GitHub installation, repository, pull-request, review, deployment, and delivery identifiers
  • Derived change maps, agent reports, findings, Risk and Attention signals, and outcomes
  • Allowlisted analytics metadata only after consent

Content boundaries

Amberly does not persist raw source, full patches, prompts, or model responses. PostHog never receives source, patches, prompts, findings, emails, or model output.

Retention and rights

Raw webhook payloads are cleared after 30 days, audit records after 400 days, and expired authentication material under the documented lifecycle policy. Hosted rights-request contact details must be completed before public launch.