Privacy Policy
Last updated: 2026-04-17
Grassion is a GitHub App that reads pull request metadata to help teams measure AI coding tool ROI. This policy explains what we collect and how we use it.
What we collect
- GitHub metadata only: PR titles, descriptions, labels, commit messages, author, merge status, CI check results. We do NOT fetch or store code content.
- Account data: your GitHub login, email (from GitHub OAuth), and team membership.
- Usage data: pages visited, errors, performance (via Sentry/Plausible).
What we don't collect
- Source code
- File contents
- Private messages or issue contents beyond what's in PR metadata
- Any data from repositories you haven't explicitly connected
How we use it
- Detect AI-generated PRs and compute ROI metrics for your team
- Send weekly digest emails (you can opt out in settings)
- Provide dashboard features
Who we share it with
- OpenAI receives anonymized PR titles and outcome signals to generate human-readable summaries. We do not send commit messages, code, or author information.
- Resend delivers transactional emails on our behalf.
- Razorpay processes payments.
- We do not sell data to anyone, ever.
Your rights
- Export your data: email contact@grassion.com
- Delete your data: uninstall the GitHub App or email us for full account deletion
- Access logs, DPA, security: available on request
Contact
Questions about privacy: contact@grassion.com
Grassion is operated by Cluenuts Technology Private Limited, Bhubaneswar, Odisha, India.