Diffraction · Legal
Privacy Policy
What we collect, why we need it, and your choices.
Last updated 6 September 2026
About this policy
Diffraction provides UI review and browser evidence for software teams. This policy explains how we handle personal information when you visit our websites, create an account, connect a repository, or use our services. Contact us using the email below for privacy questions or requests.
We manage account, billing and service information for our own operations. When a workspace submits code or other information about people for a review, we process that information to provide the service to that workspace. Your workspace administrator also controls membership, connected repositories and access to results.
What we collect
Account and workspace information: your name, email, profile image, authentication identifiers, GitHub account details, workspace membership, invitations and seat type. We receive this from you, your administrator and the services you connect.
Review information: selected repository contents, pull requests, diffs, configuration, test instructions, and information exposed by the application under review. Evidence can include screenshots, videos, recorded DOM content and interactions, console output, network diagnostics and generated findings. These materials may contain personal or confidential information present in your test application.
Billing information: subscription and credit balances, purchase history, billing contact information and payment status. Polar and its payment providers process payment details; Diffraction does not store full payment card numbers.
Service information: usage events, identifiers, device and connection information, logs, errors, and messages you send us. Hosting and delivery providers may process IP addresses and request metadata to operate and secure the service.
How we use information
We use information to authenticate users, manage workspaces and access, run reviews, deliver evidence, process subscriptions and credits, send service emails, provide support, diagnose problems and improve reliability. We also use relevant records to prevent abuse, resolve disputes and meet legal obligations.
Please use test data and only connect repositories and environments you are authorised to share. Avoid including production secrets or unnecessary sensitive personal information. If you do not provide information needed for an account, payment or review, we may not be able to provide that feature.
AI processing
Reviews send relevant code, instructions and browser evidence to AI models through OpenRouter and its model providers. Provider processing, retention and training rules depend on the selected endpoint and applicable settings and agreements. We do not promise universal zero retention or that every provider has identical data practices.
Do not submit information subject to special processing or residency requirements unless you have first confirmed with us that the service can meet them. AI-generated findings can be incomplete or wrong and require human review.
Storage, retention and security
Our providers operate internationally, including in the United States. Information may be processed outside your country and outside New Zealand. Applicable safeguards depend on the provider, processing arrangement and relevant law; we do not offer a general promise of New Zealand-only storage.
We retain information for as long as needed to provide the service and for legitimate security, dispute and legal purposes. Account and review records may remain until deletion is requested and processed. We do not currently promise a fixed automatic deletion period for every review artifact. Billing and tax records may need to be retained longer, and provider backups and logs can have separate retention schedules.
We use access controls and other safeguards to protect information, but no service can guarantee absolute security. Contact us to request account or review-data deletion. We may need to verify your identity or workspace authority and explain any records that must be retained. We will notify affected people and authorities about privacy breaches where required by law.
Your choices and rights
You can ask to access or correct your personal information, request deletion, or raise a privacy concern using the contact below. For information controlled by your employer or another workspace, please also contact its administrator. We will handle requests within the periods required by applicable law.
Depending on your location, you may also have rights to object, restrict processing, receive portable data or withdraw consent. Where those laws apply, we rely on the appropriate basis for the activity, such as providing a contract, legitimate interests in operating and securing the service, legal obligations or separately obtained consent.
You may complain to the New Zealand Office of the Privacy Commissioner at privacy.org.nz, or your local privacy authority. The service is intended for professional use and is not directed at children under 18. Let us know if a child has provided personal information.
Updates
We will update this page when our practices change and give appropriate notice of material changes. The date above identifies the current version.
Service providers
Links below lead to the providers’ own privacy information. Their policies do not replace this one or establish that a particular privacy setting is enabled for Diffraction.
- WorkOSAuthentication and workspace identity
- GitHubConnected repositories, sign-in and pull-request publication
- PolarMerchant of record, subscriptions and payments
- VercelApplication hosting, workflows and isolated execution
- CloudflareDatabase and review artifact storage
- OpenRouter and model providersAI planning and analysis
- PostHogProduct analytics and diagnostics
- ResendTransactional email delivery
- MintlifyDocumentation hosting
Get in touch
For privacy, billing or legal questions, email support@diffraction.sh.
You can also contact the New Zealand Office of the Privacy Commissioner.