Privacy policy

Effective 1 October 2026.

CrashPatch is operated by Altix Code Ltd, a company registered in and governed by the law of the Republic of Cyprus (“Altix”, “we”, “us”). This policy explains what personal data, and what of your source code and crash data, we collect when you use our website and dashboard (the “Service”), why, how long we keep it, who we share it with — including the AI provider we send code context to for triage — and the rights you have over it. It applies to the CrashPatch marketing site, dashboard, ingestion API, and the GitHub App.

Two different roles are in play throughout this policy: for data about you and your account, Altix is the data controller. For crash data and source code we process to triage and patch your application, you are the data controller and Altix is a data processor acting on your instructions — see “When we process data on your behalf” below.

1. Data we collect about you

When you sign up and use the Service, we collect:

2. Crash data, source code, and the AI model

CrashPatch is a crash-triage and auto-patch tool. To do that job it necessarily processes two kinds of data on your behalf, under your instructions: crash reports from your application, and — if you turn triage on for a project — source code read from the GitHub repository you connect. For both, you are the data controller (you choose what application sends us crashes, and which repository, if any, we may read) and Altix is a data processor. This is the most sensitive part of what CrashPatch does, so we set it out specifically rather than folding it into a general list:

Because of this, you must have the right to share the connected repository’s source code with us, and with our AI sub-processor, before you connect it. Do not connect a repository you do not own or are not authorised to grant this access to — for example, code under a client NDA, or containing a third party’s proprietary material you do not have permission to disclose. Triage is off by default for every new project; turning it on is a deliberate, per-project decision, never a side effect of connecting a repository.

3. Why we process it

4. Who we share it with

We do not sell personal data or your source code. We share it only with the processors needed to run the Service, each bound by contract to use it solely to provide their service to us:

Issued invoices are recorded in Altix Code Ltd’s own internal invoicing system, used across our products, so we can meet our accounting and tax obligations as a single company.

Where a sub-processor above is located outside the European Economic Area — including Anthropic, OpenRouter, GitHub (Microsoft), and Stripe — we rely on the European Commission’s Standard Contractual Clauses, or an equivalent recognised safeguard, to cover the transfer.

We may also disclose data where required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Altix, our customers, or others.

5. How long we keep it

6. Deleting your account

Account owners can permanently delete their account from Settings at any time. Doing so:

This action cannot be undone. The dashboard asks you to type your account’s name to confirm before it proceeds.

7. Cookies

Our website and dashboard use a single strictly necessary cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.

8. Your rights

If you are in the European Economic Area, the UK, or another jurisdiction with similar protections, you have the right to:

To exercise any of these rights, email privacy@altixcode.com. If the data you are asking about is crash data or source code processed on behalf of one of our customers rather than your own account, we will direct the request to that customer, who is the controller for that data, unless they have instructed us otherwise.

9. Security

Passwords are hashed with bcrypt and never stored in plain text. API keys are hashed at rest and shown to you only once, at creation. Invite and password-reset links use single-use, cryptographically random tokens that are hashed at rest. GitHub App installation tokens are minted per job, live for at most an hour, and are never stored. Traffic to the Service is encrypted in transit with TLS. Access to production infrastructure is restricted to the people who need it to operate the Service.

10. Children

The Service is intended for businesses and professional software developers and is not directed at, or knowingly used to collect data from, children under 16.

11. Changes to this policy

If we make a material change to this policy, we will notify account owners by email and update the effective date above before the change takes effect.

12. Contact

Altix Code Ltd (Cyprus). For any question about this policy or your data, email privacy@altixcode.com.