Privacy Policy

Quartet ("we", "our", "us")

Effective date: April 13, 2026

1. Who We Are

Quartet is an autonomous PR review platform for GitHub teams. It operates as a GitHub App that reviews pull requests using AI and manages the review lifecycle. Quartet is operated by an independent developer and we are the data controller for all information described in this policy.

2. What Data We Collect

We collect only the minimum data necessary to operate the service.

From GitHub

DataWhy we collect it
GitHub organization and repository namesIdentifies which repositories Quartet reviews
Pull request metadata (number, branch, author, SHA)Tracks review state and lifecycle
Pull request diff contentSent to the tenant-configured AI provider's API for code review (not stored permanently by Quartet)
GitHub user loginDisplayed in review comments and audit logs

Technical data

DataWhy we collect it
IP addressRate limiting and webhook verification
Session ID (dashboard cookie)Maintains your authenticated dashboard session
Operational logsService debugging; retained for 30 days

3. What We Do Not Collect

4. How We Use Your Data

PurposeLegal basis
Reviewing pull requests and posting review commentsContract (service operation)
Tracking PR review state and round historyContract
Sending PR diff content to your configured AI provider for reviewContract
Dashboard authentication and session managementContract
Audit trail for review actionsLegitimate interest (security and dispute resolution)

5. How We Store and Protect Your Data

All data is stored on Amazon Web Services infrastructure in the us-east-1 (N. Virginia) region.

6. Third-Party Data Sharing

We do not sell, trade, or share your personal data with third parties for commercial purposes. We share data only in the following limited circumstances:

7. Data Retention

Data typeRetention period
PR review state and round history90 days (automatically deleted via DynamoDB TTL)
Dashboard sessions24 hours (automatically deleted on expiry)
Operational logs30 days
PR diff contentNot stored; sent transiently to your configured AI provider during review

Upon uninstalling Quartet, all associated data expires automatically via TTL. For immediate deletion, contact privacy@quartet.tools.

8. Your Rights

Depending on where you live, you may have the following rights regarding your personal data:

To exercise any of these rights, contact privacy@quartet.tools. We will respond within 30 days.

9. Cookies

The Quartet dashboard uses a single session cookie:

CookiePurposeExpiry
quartet_sessionMaintains your authenticated dashboard session24 hours; cleared on logout

This cookie is HttpOnly, Secure, and SameSite=Lax. We do not use advertising, tracking, or analytics cookies of any kind.

10. Children's Privacy

Quartet is not directed at children under 13. Our services are intended for software developers and team leads. If you believe we have inadvertently collected data from a minor, contact privacy@quartet.tools and we will delete it promptly.

11. International Data Transfers

Data is stored in the United States (AWS us-east-1). If you are located in the European Economic Area or United Kingdom, your data may be transferred to and processed in the United States. Where required by applicable law, we rely on Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms to protect your data. We take appropriate measures to ensure your data remains protected in accordance with this policy.

12. Changes to This Policy

When we make material changes, we will update the effective date above. Continued use of Quartet after the effective date constitutes acceptance of the updated policy.

13. Contact

Email: privacy@quartet.tools

We aim to respond to all privacy-related inquiries within 5 business days.