- Review inputs
- Selected GitHub PR metadata and bounded diff text. Static repository context reads up to 24 authorized JavaScript or TypeScript files, at most 384 KiB total, and verifies each Git blob. Full static context files stay in Worker memory; reports retain selected evidence lines and paths. Supporting excerpts are excluded from AI by default. A current repository owner/admin must explicitly opt in, and the operator gate must be enabled, before bounded adjacent helper, guard and test excerpts from the immutable reviewed commit can be sent to Workers AI. The entire repository is not sent. When AI is enabled, bounded changed patches are processed through Cloudflare Workers AI. Organization policy can disable AI review. Pattern-based credential minimization omits matching changed-code hunks before AI analysis and masks matching finding text before persistence or publication; it does not detect every possible secret.
- Stored workspace evidence
- Connected reviews retain metadata, findings, source excerpts, and structured reports for workspace use. Do not assume zero source retention. GitHub comments may also contain excerpts and follow GitHub's retention controls.
- Proposed fixes
- Generated proposals include old and proposed file content. They expire after one hour; scheduled cleanup clears retained proposal content after 24 hours except while publication is pending or running. Minimal lifecycle metadata remains.
- Permissions
- The GitHub App reads selected repository content and review/check data. Publishing approved fixes needs Contents: read/write and pull-request permission. Installing it does not authorize unapproved patch publication.
- Evidence retention
- Administrators can configure 30–3,650 days, preview eligible report snapshots, finalized recovery payloads and terminal fix payloads, and explicitly confirm deletion. Configuration alone does not schedule deletion. This control preserves findings, feedback, audit, billing, authentication, and active work. Incomplete publication payloads remain recoverable; successful publication clears its journal payload atomically. Provider-managed copies and backups are separate.
- CI evidence
- After publication, CodLab can record check names, states, durations, and the exact candidate commit from GitHub. It does not execute repository commands or retain raw CI logs. Missing or skipped checks cannot establish passing validation.
- Deletion and questions
- Contact privacy@codlab.app about stored account or review information. Uninstalling the GitHub App removes future access; it does not by itself promise deletion of previously stored records.