Skip to content

About this policy

Diffraction provides UI review and browser evidence for software teams. This policy explains how we handle personal information when you visit our websites, create an account, connect a repository, or use our services. Contact us using the email below for privacy questions or requests.

We manage account, billing and service information for our own operations. When a workspace submits code or other information about people for a review, we process that information to provide the service to that workspace. Your workspace administrator also controls membership, connected repositories and access to results.

What we collect

Account and workspace information: your name, email, profile image, authentication identifiers, GitHub account details, workspace membership, invitations and seat type. We receive this from you, your administrator and the services you connect.

Review information: selected repository contents, pull requests, diffs, configuration, test instructions, and information exposed by the application under review. Evidence can include screenshots, videos, recorded DOM content and interactions, console output, network diagnostics and generated findings. These materials may contain personal or confidential information present in your test application.

Billing information: subscription and credit balances, purchase history, billing contact information and payment status. Polar and its payment providers process payment details; Diffraction does not store full payment card numbers.

Service information: usage events, identifiers, device and connection information, logs, errors, and messages you send us. Hosting and delivery providers may process IP addresses and request metadata to operate and secure the service.

How we use information

We use information to authenticate users, manage workspaces and access, run reviews, deliver evidence, process subscriptions and credits, send service emails, provide support, diagnose problems and improve reliability. We also use relevant records to prevent abuse, resolve disputes and meet legal obligations.

Please use test data and only connect repositories and environments you are authorised to share. Avoid including production secrets or unnecessary sensitive personal information. If you do not provide information needed for an account, payment or review, we may not be able to provide that feature.

Who receives it

Workspace members receive access according to their role. Review summaries and evidence references may be posted to the connected GitHub pull request and become visible to people who can access that repository. Public repositories can make those comments public. Access controls on Diffraction do not remove information already published on GitHub or copied by a recipient.

We use providers for authentication, payments, email, hosting, storage, AI processing and diagnostics. The provider list below explains their roles. Providers may also process limited information for their own security, legal and payment obligations under their policies.

We may disclose information when legally required, to address fraud or security incidents, or to protect legal rights. We do not sell personal information or use it for cross-site targeted advertising.

AI processing

Reviews send relevant code, instructions and browser evidence to AI models through OpenRouter and its model providers. Provider processing, retention and training rules depend on the selected endpoint and applicable settings and agreements. We do not promise universal zero retention or that every provider has identical data practices.

Do not submit information subject to special processing or residency requirements unless you have first confirmed with us that the service can meet them. AI-generated findings can be incomplete or wrong and require human review.

Cookies and analytics

Authentication uses cookies and similar storage to keep you signed in and protect sessions. Product analytics uses PostHog with local storage and selected usage events to understand how features work. Our browser analytics configuration respects Do Not Track and disables automatic interaction capture and session recording. Review evidence recording is a separate, requested product function.

You can control cookies and local storage in your browser, although blocking essential storage can prevent sign-in. Contact us about analytics or privacy choices. Where applicable law requires consent for optional tracking, that consent must be obtained separately; this policy is not a substitute for it.

Storage, retention and security

Our providers operate internationally, including in the United States. Information may be processed outside your country and outside New Zealand. Applicable safeguards depend on the provider, processing arrangement and relevant law; we do not offer a general promise of New Zealand-only storage.

We retain information for as long as needed to provide the service and for legitimate security, dispute and legal purposes. Account and review records may remain until deletion is requested and processed. We do not currently promise a fixed automatic deletion period for every review artifact. Billing and tax records may need to be retained longer, and provider backups and logs can have separate retention schedules.

We use access controls and other safeguards to protect information, but no service can guarantee absolute security. Contact us to request account or review-data deletion. We may need to verify your identity or workspace authority and explain any records that must be retained. We will notify affected people and authorities about privacy breaches where required by law.

Your choices and rights

You can ask to access or correct your personal information, request deletion, or raise a privacy concern using the contact below. For information controlled by your employer or another workspace, please also contact its administrator. We will handle requests within the periods required by applicable law.

Depending on your location, you may also have rights to object, restrict processing, receive portable data or withdraw consent. Where those laws apply, we rely on the appropriate basis for the activity, such as providing a contract, legitimate interests in operating and securing the service, legal obligations or separately obtained consent.

You may complain to the New Zealand Office of the Privacy Commissioner at privacy.org.nz, or your local privacy authority. The service is intended for professional use and is not directed at children under 18. Let us know if a child has provided personal information.

Updates

We will update this page when our practices change and give appropriate notice of material changes. The date above identifies the current version.

Service providers

Links below lead to the providers’ own privacy information. Their policies do not replace this one or establish that a particular privacy setting is enabled for Diffraction.

Get in touch

For privacy, billing or legal questions, email support@diffraction.sh.

You can also contact the New Zealand Office of the Privacy Commissioner.