Privacy policy
Last updated 2026-05-29.
Passmuster is operated by Echowire. This policy describes what data we process, why, who we share it with, and how to have it deleted.
What we process
- Account data — your name and email, your organization, and your role, via our authentication provider.
- Source-derived data — for each processed pull request: the diff, the linked ticket's text, the generated test plan, and the QA verdicts your team records.
- Billing data — billing contact and payment details, via our payments provider.
Where it goes
When a pull request is processed, your PR diff and the linked ticket's text are sent to Anthropic to generate the plan. That is the data that leaves your infrastructure, and Anthropic is who receives it.
A complete list of the third parties we share data with is on the subprocessors page.
What we don't do
We don't train on your code. The Anthropic account is configured for no-training and limited-or-zero data retention; your diffs and tickets are used to generate your plan and nothing else. We don't sell your data.
Retention & deletion
Ask us to delete your data and we purge your diffs, generated plans, and derived data within 7 days. Uninstall the GitHub App and your repositories go inactive immediately, with a 30-day recoverable grace before the same purge. We retain only the minimal billing/invoice records the law requires and audit-log entries that record what happened — never your source.
- Deletion on request: within 7 days.
- On GitHub App uninstall: repositories go inactive immediately, with a 30-day recoverable grace before purge.
To request deletion or a copy of your data, email privacy@passmuster.io.
Data Processing Agreement
Available on request — see the security page.