Skip to content

Privacy Policy

Last updated: 2026-09-07

Persian is a review client for GitHub. To work, it has to read your GitHub activity and keep a copy of some of it. This page says exactly what we keep, why, who else touches it, and how to get it deleted. It is written to be read, not skimmed past.

The short version:

  • We mirror pull request, issue and notification metadata plus the diffs of mirrored pull requests. We never clone a repository or store whole files.
  • AI features send the relevant text to Anthropic (or OpenAI as a fallback). Neither trains on it.
  • We do not sell your data and we do not run ad trackers.
  • Email team@persian.sh and we delete everything within 30 days.

1. What we collect

From GitHub when you sign in. Your GitHub user ID, username, display name, avatar and email address. We also store the OAuth token GitHub issues so Persian can read your work and act on your behalf when you ask it to.

From GitHub while you use Persian. Pull request, issue, discussion and notification metadata for the repositories you can access: titles, descriptions, comments, reviews, labels, reviewers, commit messages, file lists and timelines. We also store the diffs of the pull requests we mirror. We never clone a repository and never store whole files. Your source stays at GitHub.

Things you create in Persian. Bookmarks and notes, review progress, draft comments, and preferences such as theme and the languages you work in.

Billing. Your billing email and the Stripe customer and subscription identifiers. Card numbers go straight to Stripe. We never see or store them.

Usage and technical data. Which AI features you run, the tokens they used and what they cost. Product events such as sign-in, finishing onboarding, reviewing a walkthrough, submitting a review and completing checkout. Server logs and error reports.

2. How we use it

  • To show your GitHub work faster than GitHub does. The mirror is what makes pages open instantly.
  • To generate AI summaries, risk scores, walkthroughs and suggested comments for your pull requests, issues and discussions.
  • To write to GitHub only when you ask: posting a comment, submitting a review, merging, marking a notification done.
  • To bill you and send the emails that go with an account: welcome, trial ending, payment failed, receipts.
  • To enforce daily AI limits and keep the service healthy.
  • To see which features people use and to fix bugs.

We do not sell your data. We do not use your code, diffs or notes to train AI models, and our AI providers are contractually barred from doing so with data sent through their APIs.

3. AI processing

When you open a pull request or issue in Persian, or trigger an AI feature, the relevant text (metadata, diff hunks, comments) is sent to Anthropic. If Anthropic is unavailable we retry with OpenAI. We pick the model per task to keep cost down and cache the result, so running the same feature twice on the same commit does not resend your data.

AI output can be wrong. It is there to help you review, not to review for you. Nothing is posted to GitHub unless you press the button.

4. Who processes your data

We run Persian on a small set of providers. Each one only receives what it needs for its job.

ProviderWhat it doesWhere
GitHubSign-in and the source of every repository record we mirrorUnited States
AnthropicAI summaries, risk scores, walkthroughs and suggested commentsUnited States
OpenAIFallback AI provider when Anthropic is unavailableUnited States
StripePayments, invoices and the billing portalUnited States
ResendTransactional email (welcome, trial, billing)United States
NeonPostgres database that holds your mirrored dataLondon, United Kingdom
VercelHosting, cache and cookieless page analyticsUnited States
SentryError reporting so we can fix crashesUnited States
Datafa.stPrivacy-focused product analytics (visits, sign-ups, checkouts)European Union

5. Cookies

  • A session cookie so you stay signed in.
  • Two Datafa.st cookies (a visitor ID and a session ID) so we can count visits and see which pages lead to sign-ups.
  • Vercel page analytics uses no cookies.

No advertising cookies. No third-party ad trackers.

6. Retention and deletion

  • Mirrored GitHub data stays while your account is active. That is what keeps pages fast.
  • Raw webhook payloads from GitHub are deleted after 30 days.
  • If you uninstall the GitHub App or revoke Persian's access in your GitHub settings, we stop receiving new data at once. Data already mirrored stays until you ask us to delete it.
  • Billing records are kept for as long as tax law requires.

To delete your account and everything we hold about you, email team@persian.sh from the email address on your GitHub account. We delete within 30 days and confirm by email. There is no in-app delete button yet.

7. Your rights

Wherever you live, you can ask us what we hold about you, get a copy, correct it, delete it, or object to how we use it. If you are in the UK, the EU or California you have these rights by law, and you can also complain to your local data protection authority. Email team@persian.sh and we will answer within 30 days.

8. Security

All traffic uses TLS. The database is encrypted at rest. GitHub tokens live server-side and are never sent to the browser. Access to production is limited to the one person who builds Persian. No system is perfectly secure. If a breach affects your data, we will tell you without undue delay.

9. Where your data lives

The database is in London. The app runs on Vercel, mostly in the United States, and our AI and payment providers are in the United States. Transfers out of the UK and EU rely on the providers' standard contractual clauses.

10. Children

Persian is not for anyone under 16. We do not knowingly collect data from children. If you think we have, email team@persian.sh and we will delete it.

11. Changes to this policy

We will post changes here and update the date at the top. If a change matters to you, for example a new category of data or a new AI provider, we will email you before it takes effect.

12. Contact

Persian is run by Ubbe. Questions about this policy or your data: team@persian.sh.