Pilot privacy notice
ReviewBeacon processes selected GitHub repository metadata to identify pull requests awaiting first human review and explain review delays. The ReviewBeacon pilot is operated by Luiz Borba. External organization onboarding remains closed until operational and provider checks are verified.
Data includes GitHub account and repository identifiers, member access, PR titles and links, author/reviewer identifiers, lifecycle and activity timestamps, submitted review states, synchronization status and signed webhook notifications. ReviewBeacon does not retain source code, commit diffs or comment/review bodies in normalized records. Raw webhooks can contain private metadata and are treated as sensitive.
GitHub supplies identity and repository data. The approved hosting plan uses Render for the application and Neon PostgreSQL in Frankfurt; GitHub Actions and private GHCR handle delivery. Provider backup locations, subprocessors and contractual retention must be confirmed before external use. Local development uses the owner's computer and local PostgreSQL.
Raw webhook bodies, including failed-job payloads, expire within 30 days. Normalized records remain while an account participates. Account deletion, uninstall and confirmed repository removal block access and schedule affected records and queued payloads for purge within seven days. Backups must expire within 30 days; provider compliance is an onboarding gate, not a currently verified promise. Suspension blocks access without deleting history.
Owners can request deletion in Pilot settings and manage repository selection or uninstall on GitHub. Logout ends a session; it does not delete account data. Account deletion retains the sign-in identity and encrypted session/key infrastructure needed by other accounts; no affected repository metadata remains after purge. To request identity deletion or ask a privacy question, contact the pilot owner through your existing invitation contact.