Privacy Policy

What we collect, and why.

Written to be read rather than agreed to. If anything here is unclear, ask us and we will fix the wording.

Effective 14 August 2026

Who we are

Dicast provides automated code review. For the purposes of data protection law we act as a processor for the source code and review data we handle on your behalf, and as a controller for account and billing data. Contact: privacy@dicast.dev.

What we collect

CategoryExamplesWhy
AccountName, email, avatar and username from your Git providerTo create your workspace and identify you
RepositoryRepository names, branch names, pull request metadataTo run reviews and show them to you
CodeDiffs and the surrounding code needed for contextTo review the change
Review outputFindings, votes, juror reasoning, dismissalsTo post comments and keep the struck record
BillingCompany name, billing address, card token held by StripeTo charge for a paid plan
UsagePer-day page and referrer totals. With your consent, Google Analytics adds device type, approximate location, and page interactions such as how far you scroll and which outbound links you followTo understand what people find useful

We do not collect special category data, and we ask you not to send it. We do not sell personal data, and we do not share it with advertisers.

Your source code

Code is read to review it and for no other purpose. It is sent to the model vendors seated on your panel, held for the duration of the review, and not retained afterwards. We do not train models on your code, and our vendor agreements prohibit them from doing so. The full list of subprocessors is on the security page.

Cookies and analytics

We run two separate things, and they are treated differently because they are different.

Our own counter — always on, no cookies

Every page view is counted by us, on our own domain. It sets no cookie, assigns no identifier, and records no IP address or user agent. What is stored is a per-day total: how many pages were opened, which paths, and which site linked to us. Nothing written down can be traced back to a person, because nothing person-shaped is written down. There is no consent prompt for this because there is nothing to consent to.

Google Analytics — only if you say yes

We also offer Google Analytics, which does set cookies and assign you an identifier. It does not load at all until you allow it. You will be asked once; decline and it never runs. Clearing this site’s storage in your browser resets the question.

When it is running, Google Analytics records the pages you open, your device type and browser, an approximate location derived from your IP address, and how you interact with a page — how far down you scroll, and which links to other sites you follow. We ask Google to anonymise your IP address. We never send it your name, your email, or anything about your code.

We do not build advertising profiles and we do not carry tracking pixels from advertising networks.

Sign-in

One essential cookie keeps you signed in. It is required for the service to function and cannot be declined while you are signed in.

Legal basis

How long we keep it

Review data follows your plan’s retention window, described on the security page. Account data is kept while your account exists. Deleting a workspace removes review data within 30 days. Backups are purged on a rolling 35-day cycle.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to a use. Email privacy@dicast.dev and we will respond within 30 days. If you are unhappy with the outcome you may complain to your local data protection authority.

Where we act as a processor for your organisation, requests about repository or review data should go to your workspace administrator; we will help them fulfil it.

International transfers

We are based in the United Kingdom and our infrastructure runs in the European Union and the United States. Transfers outside the UK and EEA rely on Standard Contractual Clauses. EU-only processing is available on the Scale plan.

Children

Dicast is not directed at anyone under 16 and we do not knowingly collect their data.

Changes

Material changes are announced by email to workspace administrators at least 30 days before they take effect. The effective date at the top of this page always reflects the current version.