Skip to content

Privacy Policy

Last updated 2026-10-10日本語All documents

This Privacy Policy describes how WillBooster Inc. ("WillBooster", "we") handles information in ReviewFixLoop (the "Service"). In this policy, the "Act" means Japan's Act on the Protection of Personal Information.

This policy exists in English and Japanese. If the two versions differ, the Japanese version prevails.

Effective date: 2026-10-10

Terms used in this policy

  • Reviewer: a combination of a coding agent program (a "harness"), a model and an effort setting that reviews a pull request.
  • Resolver: the coding agent that conducts a review of a pull request: it decides how to treat each finding and changes the code.
  • Run: one execution of the review-and-fix loop on one pull request.
  • Finding: an issue that a reviewer reports in a run.
  • Judgment: the resolver's decision on a finding.
  • Judge: the automated classifier with which the Service assigns a tag, a severity and duplicate relations to each finding.
  • Workspace: the unit of the Service to which runs belong. A personal workspace is created when you sign in. Members of a workspace can see its runs.
  • L0, L1, L2: the three layers of run data, defined under "Run data" below.

Operator

  • Operator: WillBooster Inc. (WillBooster株式会社)
  • Address: 3F Shinjuku Dainana Hayama Building, 1-36-2 Shinjuku, Shinjuku-ku, Tokyo 160-0022, Japan
  • Representative: Kazunori Sakamoto

Information we collect

GitHub identity

You sign in with GitHub OAuth. The Service uses it only to identify you. It requests no scopes and obtains no access to your repositories. From GitHub we receive and store:

  • your GitHub numeric user id;
  • your GitHub login;
  • the creation time of your GitHub account.

At sign-up we also store the country code determined from where the request came from.

Account and workspace records

We store your workspace memberships, which runs you started, and the settings you save to your account, such as your limits on vendor CLI jobs. We also store the version of the notice you agreed to at sign-up and the time of that consent.

Run data

The Service's CLI sends run data from your machine in three layers.

LayerContentSent to the Service
L0 (metadata)The configuration of the reviewers and the resolver (harness, version, model, effort, review prompt variant, manifest identification), token counts, the severity, tag, judgment and duplicate relations of findings, which judge was used, and timestampsAlways
L1 (free text)The title, body and evidence of findings, the reasons for judgments and decisions, excerpts of the pull request description, and excluded findingsAlways
L2 (full sessions)All reviewer responses, tool output and logsNot by default. Only when you upload them with a bug report

The Service also receives the identification of the repository and the pull request of each run.

L1 and L2 are taken from your repository, your pull requests and your sessions. They can contain personal data if your repository, your pull requests or your sessions contain it.

The Service does not record which authentication method a vendor's command-line tool uses. It does not read, store or relay your vendor credentials.

The web site has no analytics tooling.

Purposes of use

We use the information above for the following purposes:

  • to identify you and to provide the Service, including showing runs to the members of their workspace;
  • to judge findings and their duplicate relations;
  • to compute and publish the leaderboard, including measuring the validity of its ratings;
  • to apply the eligibility rules and the free limits of the Terms of Service;
  • to show which notice you consented to at sign-up, and to tell whether a changed notice needs your consent again;
  • to investigate the bugs you report (L2).

Retention

LayerPublic repositoryPrivate repository
L0Kept indefinitelyKept indefinitely
L1Kept while the repository stays publicEmptied 30 days after the run's last activity
L2Deleted 30 days after uploadDeleted 30 days after upload
  • If a public repository becomes private or disappears, its L1 is hidden from the public within 24 hours. It is deleted only after both a grace period of at least seven days and the private-repository retention period have elapsed.
  • After a repository is renamed or transferred, its earlier runs are treated as no longer public once the recorded name stops identifying the original repository.
  • A run created while its repository was private stays under the rule for private repositories, and is not shown publicly, even if the repository becomes public later.
  • L1 is kept while a run is active. The L1 of a run whose findings another run inherited is kept while the inheriting run still holds its L1. Both exceptions extend beyond the periods in the table and also apply after account deletion.
  • Deletion empties the L1 and keeps the L0 rows.
  • Deleted data can remain in backups for up to 30 days.

Account deletion

When you delete your account, we remove your GitHub numeric user id, login, account creation time and sign-up country from your account record. We revoke your API tokens, remove your workspace memberships and saved vendor CLI limits, and stop displaying your contributor name. The account record remains so that the runs you started still count as one account in the aggregates. The record of the consent you gave at sign-up, the version of the notice and its time, also remains in that record.

To prevent deletion and re-registration from resetting the free limits, we temporarily retain a keyed digest (HMAC) of your GitHub numeric user id in that record. The Service can match it to the same GitHub account at a later sign-up, so the record is not yet fully detached from that GitHub account during this period.

You can sign up again at or after the later of 24 hours from deletion and the start of the next calendar month in UTC. The next daily retention sweep removes the digest after that time. The run metadata and aggregates remain.

Deleting your account reduces the private-repository L1 retention of your personal workspace to zero days. Its ended runs become eligible for the next retention sweep unless another run still holding L1 inherits their findings. The public-repository rule and its seven-day period still apply to runs that were public. Runs in shared workspaces keep that workspace's retention rules.

Publication on the public leaderboard

Free use of the Service requires contributing your runs to the public leaderboard.

DataWho can see it
Aggregates (ratings, intervals, cost multiples, account counts)Anyone
Runs on public repositoriesAnyone, down to the findings, judgments and cost of each pull request. The page links to the repository and the pull request. It never shows the handle of the pull request's author
Runs on private repositoriesThey contribute to the aggregates only. Their text is not published
Your personal leaderboardOnly you
Your name as a contributorShown only if you opt in
  • Judgments shown publicly are labelled as AI judgments.
  • The CLI masks strings that look like secrets in evidence before sending it. The Service checks again before publication. A finding in which a secret-looking string is detected is not published, and its owner is notified on the run page.

Service providers and AI processing

We entrust the storage of data and the judging of findings to cloud service providers and AI inference providers. These providers are companies in the United States of America, and they can handle the data in the United States and in other countries where they operate. The providers we use can change among companies in the United States.

  • To judge findings, we send the file, line, title, body and evidence of a finding, and of its duplicate candidates, to external AI models. To measure the validity of judgments, we also send the resolver's reason for a sample of judged findings.
  • What we send includes findings from private repositories. The validity measurement leaves out findings and reasons in which a secret-looking string is detected.
  • We request a route on which the data we send is not used to train models. We do not require that the providers retain no data at all.
  • Deleting your account cannot recall data that was already sent to a provider.

We choose a provider after checking the terms and data-handling conditions it publishes, and we check them again when they change. Some AI models are reached through another provider's service and are used under that service's terms. On request to the contact below, we tell you without delay the names of the providers and a summary of the measures we take.

Except where the law requires it, we do not provide personal data to any third party other than these providers without your consent.

Provision to third parties in a foreign country

Entrusting data to the providers above is a provision of personal data to third parties in a foreign country under the Act. We do it with your consent: when you sign up, you are shown the information below, and your account is created only if you agree. We record the version of the notice you agreed to and the time.

  • Country: the United States of America.
  • Its system for protecting personal information: the United States has no comprehensive federal law on personal information; federal laws for particular sectors and state laws such as California's apply. It takes part in the APEC Cross-Border Privacy Rules system. The European Union's adequacy decision for it covers only organisations certified under the EU–US Data Privacy Framework. See the survey by Japan's Personal Information Protection Commission.
  • Measures the providers take: they handle the data under the terms they publish, to provide their service. We request a route on which the data is not used to train models. A provider can keep the data for a limited time, for example to monitor abuse. No contract between us and the AI inference providers commits them to the measures Japanese law requires of us, and we have not confirmed that each of them takes every such measure.

Before we provide your data to a provider in another country, we ask for your consent again.

Security measures

We take the measures necessary and appropriate to prevent the leakage, loss or damage of personal data, such as encrypting communications, limiting who handles the data, and checking the conditions of the providers. On request to the contact below, we tell you what these measures are.

Requests and contact

You may request access to, or the correction, cessation of use or erasure of, your personal data, and ask about this policy, at contact@willbooster.com. A request is separate from account deletion, and you can make one while re-registration is blocked, without creating a new account.

We request only the information needed to verify your identity and locate the relevant data, assess each request under the Act, and notify you of the outcome. If we decline a request in whole or in part, we explain our reasons.

Changes to this policy

When we change this policy, we post the new text and its effective date on this page.