Privacy policy
In short
- The website uses no cookies and no analytics for now.
- The desktop app doesn’t send any data to Diffwright today.
- If you write through the form, your message is kept for 90 days, only to reply to you.
- Downloads are counted anonymously and in aggregate, without IP addresses.
The diffwright.app website
The website sets no cookies and uses no trackers. Its fonts are hosted on the site itself: nothing is loaded from a third-party service.
There is no analytics for now. If such a tool is added later (Umami is being considered), this page will be updated at the same time, before it is turned on.
Like any web server, this one logs the requests it receives: a truncated IP address (IPv4: /24, IPv6: /48), the requested page, the response code and the usual browser headers, including the user agent. These logs rotate in size-limited files and are only used to diagnose outages or abuse.
The contact form
The form collects the name, email address and message you enter. This data is only used to reply to you.
The message is stored on the server, then deleted automatically after 90 days. It is also forwarded by email to the contact address, where it may stay longer while the conversation lasts; you can ask for it to be deleted.
To limit spam, the form contains an invisible trap field and a cap on messages per visitor. Your IP address is only used, in memory, to count those messages: it isn’t stored or logged with the message.
Downloads
The download buttons go through a redirect link that increments a counter aggregated by day, platform, architecture and version. Neither the IP address nor the user agent is recorded: to avoid counting the same visitor twice on the same day, a salted fingerprint is kept in memory only, and wiped every day at midnight UTC.
The file itself is served by GitHub (the public diffwright-releases repository), which applies its own privacy policy.
Hosting and backups
The website and its API run on a server rented from OVH.
Encrypted backups of the database are kept off the server, in a private repository, for 190 days at most. Deleted data can therefore remain in those backups until they rotate out, without being used.
The desktop app
Today, the app collects nothing and sends no usage data to Diffwright. It only makes the following kinds of connections.
- With Azure DevOps, directly from your computer and with your token: these exchanges don’t go through diffwright.app.
- With GitHub, to look for updates (the public diffwright-releases repository): GitHub then receives your IP address, as with any download.
- If you use the AI, the analyzed content (diff, comments) is sent to the service you chose, through the claude CLI or your local Ollama instance, under that service’s terms.
Optional telemetry (upcoming)
The app will offer anonymous, optional telemetry, off by default. It doesn’t exist in the app yet: nothing is collected today, and this section describes what would be collected if you ever turn it on.
What would be sent
- A random install ID, created when you turn the option on and never derived from your machine, your account or Azure DevOps.
- The app version, the operating system (name and major version), the CPU architecture and the interface language.
- Daily counters of actions from a closed list (for example the number of pull requests opened), with no other content.
- Crash reports: error type, message and stack frames, scrubbed of paths, addresses, identifiers and URLs by the app and then a second time by the server.
What would never be collected
- Your IP address (it is only used in memory to limit request rates, with no geolocation) and your user agent.
- Names of organizations, projects, repositories, pull requests, branches or files.
- Code, comments, tokens and credentials, email addresses.
Retention periods
- Raw events: 30 days.
- Crash reports: 90 days.
- Inactive installs: erased 180 days after their last signal.
- Anonymous daily totals, which aren’t linked to any identifier, are kept.
The app will offer a “Delete my data” button that immediately erases everything linked to your install ID, then forgets it and turns the option off. The backups described above take at most 190 days to purge it.
This data would be stored on the diffwright.app server and wouldn’t be shared with any third party or analytics tool.
Your rights and contact
You can ask for access to the data that concerns you, or for its correction or deletion, by writing to the address below. You can also contact the data protection authority of your country (in France, the CNIL).
Address for any request about your data: contact@diffwright.app