Privacy Policy
How Izri collects, uses, and protects your data — with an honest account of the LLM data flow at the core of the product.
{{…}} are placeholders. Effective date: {{EFFECTIVE_DATE}}.Who we are
{{LEGAL_ENTITY}} ("we", "us") operates Izri, an AI-powered QA automation platform. For questions about this policy or to exercise your data rights, contact {{PRIVACY_EMAIL}}.
What we collect
- Account & identity: your GitHub identifier, username, email, avatar, and OAuth tokens, plus your organization membership and role.
- Code you submit for analysis: source code, pull-request diffs, and repository metadata you send to Izri for test generation and analysis.
- Billing: billing email, plan, and Stripe identifiers. We never receive or store your card number — Stripe handles payment details.
- Operational data: IP address, request metadata, and application logs used for security and reliability.
How your code reaches LLM providers
Izri's core function routes your code and diffs to third-party large-language-model (LLM) providers to generate and analyse tests. The providers who may process your code are listed on our sub-processors page (currently OpenAI, OpenRouter, and Anthropic).
We do not use your code to train models. On every request we pin the strongest routinely-available data protection: providers are instructed not to log prompts or train on your data (technically: OpenRouter data_collection:"deny", OpenAI store:false; Anthropic does not train on API data by default). Analysis inputs are transient and are not retained by us.
Zero Data Retention (ZDR)
Zero Data Retention is OFF by default. The always-on protections above (no training, no prompt-logging) apply to everyone. Beyond that, ZDR — which restricts routing to provider endpoints that retain nothing — is an opt-in choice you control per organization in your settings. We disclose this plainly so your use of Izri reflects an informed choice: unless you enable ZDR, providers may apply their own default (short) retention for abuse-monitoring, though they still will not train on your data.
International transfers
The LLM and infrastructure providers are located in the United States, so data originating in the EU/EEA or UK is transferred there. We rely on the EU-US Data Privacy Framework where a provider is certified, with EU Standard Contractual Clauses (and the UK IDTA) plus a transfer-impact assessment as the fallback. Our EU representative is {{EU_REP}} and our UK representative is {{UK_REP}}.
Retention
Account data is kept for the life of your account and deleted after closure. Analysis inputs sent to LLM providers are transient. Billing records may be retained where tax law requires. Operational logs are kept for a limited period for security.
Your rights
Depending on your location you may have rights to access, correct, delete, restrict, port, or object to the processing of your personal data. To exercise them, contact {{PRIVACY_EMAIL}}. Where we process your code on behalf of your organization, we act as a processor and will direct your request to that organization. You may also lodge a complaint with your supervisory authority.
Changes
We will update this policy as the service evolves and post the new effective date here. For material changes to our sub-processors, see the change-notification commitment on the sub-processors page.