Privacy policy
Effective 1 October 2026.
CrashPatch is operated by Altix Code Ltd, a company registered in and governed by the law of the Republic of Cyprus (“Altix”, “we”, “us”). This policy explains what personal data, and what of your source code and crash data, we collect when you use our website and dashboard (the “Service”), why, how long we keep it, who we share it with — including the AI provider we send code context to for triage — and the rights you have over it. It applies to the CrashPatch marketing site, dashboard, ingestion API, and the GitHub App.
Two different roles are in play throughout this policy: for data about you and your account, Altix is the data controller. For crash data and source code we process to triage and patch your application, you are the data controller and Altix is a data processor acting on your instructions — see “When we process data on your behalf” below.
1. Data we collect about you
When you sign up and use the Service, we collect:
- Account details — your email address, an optional name, your organisation name, and a salted, irreversibly hashed copy of your password. We never store or have access to your actual password.
- Team and permission data — if your account has more than one person on it, we store each member’s email, role, who invited them, and when, so an owner or admin can manage access.
- Billing information — your subscription plan, status, and renewal date. Card and payment details are collected and held by Stripe, our payment processor; we only ever receive a subscription and customer identifier from them, never your card number.
- Support and account communications — anything you send us by email, including transactional email we send you (password resets, email verification, team invitations, billing receipts).
- Usage and security logs — sign-in timestamps, API key metadata (a one-way hash and a short prefix, never the key itself after it is first shown to you), and a security audit log of membership actions on your account (invitations, role changes, removals, and account deletion requests), each tagged with the actor’s email and the time it happened.
- Technical data — standard web server and request logs (IP address, user agent, timestamps) generated when you use the dashboard, kept briefly for security and abuse prevention.
2. Crash data, source code, and the AI model
CrashPatch is a crash-triage and auto-patch tool. To do that job it necessarily processes two kinds of data on your behalf, under your instructions: crash reports from your application, and — if you turn triage on for a project — source code read from the GitHub repository you connect. For both, you are the data controller (you choose what application sends us crashes, and which repository, if any, we may read) and Altix is a data processor. This is the most sensitive part of what CrashPatch does, so we set it out specifically rather than folding it into a general list:
- Crash reports. Your application’s error monitoring SDK (a Sentry-compatible client) sends us exception types and messages, stack frames, environment and server names, and any other field the SDK includes in the envelope it posts. This can incidentally include data embedded in an exception message or a local variable by your own application — we do not inspect it for personal data, and you are responsible for what your error-reporting configuration sends us.
- Source maps. If you upload them, we store the map content so stack frames can be unminified into real file names and line numbers.
- Repository access. Connecting a repository installs the CrashPatch GitHub App, which grants us: read access to repository contents, write access to create a branch and commit to it, and read/write access to pull requests. We never write to your default branch and never merge anything — every change we make is a draft pull request for a human to review.
- Sending code to an AI model. If you enable triage for a project, when a new issue is grouped we read the specific files named in its stack trace from your connected repository (capped at a small number of files and a size limit per file) and send that code, together with the crash details, to a large language model to diagnose the bug and draft a fix. That request is made through OpenRouter or directly to Anthropic, depending on how this deployment is configured, and is in either case served by Anthropic’s API — a US-based model provider. This means source code excerpts from your repository leave the European Economic Area and are transferred internationally for the sole purpose of generating that one patch suggestion. Neither OpenRouter nor Anthropic is instructed to, and under their respective commercial-API terms does not, use API input to train their models.
- What we keep from that process. We do not store the source files we read for triage. What we do keep is the model’s output: the unified diff it proposed, its written rationale, and what verification (if any) was actually run — shown in your dashboard and in the pull request itself — plus whatever content ends up committed to the branch and pull request CrashPatch opens on GitHub, which is of course visible in your own repository exactly like any other commit.
Because of this, you must have the right to share the connected repository’s source code with us, and with our AI sub-processor, before you connect it. Do not connect a repository you do not own or are not authorised to grant this access to — for example, code under a client NDA, or containing a third party’s proprietary material you do not have permission to disclose. Triage is off by default for every new project; turning it on is a deliberate, per-project decision, never a side effect of connecting a repository.
3. Why we process it
- To provide the Service — ingesting, grouping, and displaying your crashes.
- To triage and draft a patch for a crash, when you have opted a project into it, which requires reading the relevant source and calling the AI model described above.
- To bill you, via Stripe, for a paid subscription you chose.
- To communicate with you about your account, including emails necessary to operate it (verification, password resets, invites, billing receipts) and, if you have not opted out, occasional product updates.
- To maintain a security audit trail of who did what on your account, so account owners and admins can review activity and we can investigate suspected compromise.
- To secure the Service and prevent abuse of our ingestion endpoints.
- To comply with our legal and accounting obligations, including tax law.
4. Who we share it with
We do not sell personal data or your source code. We share it only with the processors needed to run the Service, each bound by contract to use it solely to provide their service to us:
- Anthropic, PBC (directly, or via OpenRouter, Inc. as an intermediary, depending on configuration) — receives crash details and the specific source files involved, to generate a triage diagnosis and a candidate patch. US-based; see section 2 for the international-transfer implication.
- GitHub, Inc. (Microsoft) — holds the repository our GitHub App is granted access to, and is where the draft pull requests we open live. You already have a direct relationship with GitHub as the repository host; our App only ever acts within the permissions you grant it at install time.
- Stripe, Inc. — payment processing and subscription billing.
- Resend (via its SMTP relay) — delivery of transactional email.
- Cloudflare, Inc. — bot and abuse protection (Turnstile) on our sign-up form.
- Hetzner Online GmbH — our infrastructure host, where our servers and databases physically run (EU-located).
Issued invoices are recorded in Altix Code Ltd’s own internal invoicing system, used across our products, so we can meet our accounting and tax obligations as a single company.
Where a sub-processor above is located outside the European Economic Area — including Anthropic, OpenRouter, GitHub (Microsoft), and Stripe — we rely on the European Commission’s Standard Contractual Clauses, or an equivalent recognised safeguard, to cover the transfer.
We may also disclose data where required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Altix, our customers, or others.
5. How long we keep it
- Account data, crash events, issues, source maps, and patch history are kept for as long as your account is active.
- Source code read from your repository for triage is never written to our database and is not retained beyond the single model request it was read for — see section 2.
- If you delete your account, every project, issue, patch, connected repository, and team member’s access is removed immediately and permanently, and our GitHub App’s installation on each connected repository is revoked — see “Deleting your account”.
- Invoices already issued remain in our invoicing system independently of your account, for as long as Cyprus tax and accounting law requires us to keep financial records (currently up to seven years).
- Security audit log entries are retained after an account is deleted, because the point of a security log is to survive the event it may need to explain; entries are kept for as long as needed for security, fraud-prevention, and legal purposes.
- Server and request logs are kept briefly (typically a few weeks) and then deleted or anonymised.
6. Deleting your account
Account owners can permanently delete their account from Settings at any time. Doing so:
- Cancels any active subscription immediately — you are not billed again, and lose access right away rather than at the end of the billing period.
- Revokes our GitHub App’s installation on every repository connected to the account, removing our standing read/write access to it.
- Permanently deletes every project, issue, event, source map, and patch.
- Removes every team member’s access to the account immediately.
- Records that the deletion happened, in a log entry that is not deleted with the account (see above).
- Does not affect invoices already issued, which remain in our invoicing system under our legal retention obligations, independently of the deleted account.
- Does not affect a pull request CrashPatch already opened on your repository — that commit exists in your repository’s own history, under GitHub’s retention, independently of your CrashPatch account.
This action cannot be undone. The dashboard asks you to type your account’s name to confirm before it proceeds.
7. Cookies
Our website and dashboard use a single strictly necessary cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.
8. Your rights
If you are in the European Economic Area, the UK, or another jurisdiction with similar protections, you have the right to:
- Access the personal data we hold about you, and get a copy of it.
- Correct inaccurate data.
- Erase your data, including by deleting your account yourself as described above.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent, where processing relies on it (for example, optional product-update emails, or turning triage off for a project to stop any further code being sent to the AI model).
- Lodge a complaint with your local data protection authority — for Cyprus, the Office of the Commissioner for Personal Data Protection.
To exercise any of these rights, email privacy@altixcode.com. If the data you are asking about is crash data or source code processed on behalf of one of our customers rather than your own account, we will direct the request to that customer, who is the controller for that data, unless they have instructed us otherwise.
9. Security
Passwords are hashed with bcrypt and never stored in plain text. API keys are hashed at rest and shown to you only once, at creation. Invite and password-reset links use single-use, cryptographically random tokens that are hashed at rest. GitHub App installation tokens are minted per job, live for at most an hour, and are never stored. Traffic to the Service is encrypted in transit with TLS. Access to production infrastructure is restricted to the people who need it to operate the Service.
10. Children
The Service is intended for businesses and professional software developers and is not directed at, or knowingly used to collect data from, children under 16.
11. Changes to this policy
If we make a material change to this policy, we will notify account owners by email and update the effective date above before the change takes effect.
12. Contact
Altix Code Ltd (Cyprus). For any question about this policy or your data, email privacy@altixcode.com.