IMPECCABLEOpen workspace →

Permissions and data handling

Before connecting a repository to the Impeccable for PRs alpha, understand what the app can access and where review data goes.

Review images and audio are accessible to anyone with their URLs. Consider this when choosing which repositories and previews to connect.

GitHub permissions

The app requests these permissions to read repository context, publish review feedback and checks, and verify organization ownership at sign-in. It never commits to your repository: setup files it proposes open in GitHub’s editor, prefilled, for you to commit.

Repository contents
Read-only
Pull requests
Read and write
Checks
Read and write
Issues
Read-only
Repository metadata
Read-only, included automatically by GitHub
Organization members
Read-only, to verify organization ownership

Requested permissions are not a record of your installation’s grants. Your approved permissions and selected repositories are managed in GitHub. Existing installations need an owner to approve permission updates; changing the app’s request does not grant them automatically.

Review the GitHub App and your installed GitHub Apps. For an organization, open its GitHub Settings → GitHub Apps → Configure. Sign in to Impeccable again after approving an update.

AI processing

Repository files, diffs, pull-request context and preview media are sent to the model providers configured for a review as needed. Supported services include Google Gemini, OpenAI, Anthropic and DeepSeek; this list does not establish which are enabled for your team.

Provider training, retention and processing-region terms have not yet been verified for this alpha reference. These depend on the actual service, account and endpoint. A no-training or zero-retention commitment is not established.

Source snapshots can be stored, and review output and processing state can retain or quote private code. Repository content is not handled only in memory.

Storage and retention

We store review metadata and findings, derived design profiles and personas, account and permission information, billing state, preview details and encrypted preview credentials. Review files can include source snapshots, screenshots, crops, audio and raw model responses.

Review images and audio use public URLs for embedding on GitHub. They do not require sign-in and carry public cache headers allowing caching for one year. Private source snapshots and review-state JSON are not served through those media URLs. Uploaded site previews use a separate access gate.

Run files
A 90-day expiry rule was configured when checked on September 7, 2026. This includes source snapshots stored with a run.
Uploaded static previews
A 30-day expiry rule was configured when checked on September 7, 2026.
Other stored data
Those rules do not cover all generated assets, processing caches, database records, processing state, logs, provider copies or backups. Complete expiry and deletion coverage is not yet verified.

Configured expiry is not proof of completed deletion. These dated checks do not guarantee current settings or that every copy disappears within 30 or 90 days. Deleting our stored files cannot retract GitHub copies, public caches or downloads.

Removing access

You can change repository access or uninstall the app in GitHub. Uninstalling removes access and starts a limited cleanup attempt; it does not establish complete erasure of previously collected data.

Deletion needs verification across the affected stores, including any incomplete cleanup and copies held by service providers or in backups. There is no verified universal deletion deadline for the alpha.