Privacy
What visualdiff reads, what it keeps, and who else sees it.
What we read
To review a pull request we fetch its diff, commits, the repository’s file list at the base revision, its dependency manifests, its .visualdiff.json, and the current contents of up to forty changed source files (to resolve imports). The CLI sends the same from your CI. With ArchCanvas connected we read the resource map you chose.
What we keep
Signed out, nothing: the review is returned to your browser and kept there. Signed in, the report is stored in your workspace (it includes the diff, trimmed for size), until you delete it or it ages out after the newest 2,000 per workspace. Tokens and keys you save are encrypted at rest. Sessions and API keys are stored as one-way hashes.
Who else sees it
Members of your workspace, and anyone you give a report’s share link. If this deployment has a model summary switched on, Anthropic receives the computed facts about a change (counts, file paths, finding titles, the pull request’s title and description) to write the summary; never code. New dependencies are looked up by name on npm and PyPI.
Analytics
We record first-party product events (for example “report analysed”, with the verdict and host) against your user id. No advertising trackers, no third-party analytics, no IP addresses in the event log.
Deletion
Delete a report from its page or the API; remove a connection to delete its secrets. To delete your account and workspace, write to [email protected].