Last updated: September 6, 2026
This policy explains what SOFTLINK LTD, the company operating SourcePRD ("we", "us"), collects when you use sourceprd.com and pm.sourceprd.com (the "Service"), why we collect it, and the choices you have. The short version: we collect what the product needs to work, we don't sell data, we don't run ad trackers, and your code stays yours.
We use this data to operate the Service: generate and update your documents, run the PR approval gate, show notifications, provide support, and keep the Service secure. We do not sell personal data, we do not run advertising or cross-site tracking, and we do not use your repository content to train models of our own.
Document generation sends excerpts of repository content to third-party AI model providers, routed through OpenRouter — currently models from xAI, OpenAI, and/or Anthropic — under API terms which do not permit using API data to train their models. Excerpts are sent only when you (or webhooks you enabled) trigger analysis.
One cookie: __session, first-party, and its only job is keeping you signed in to the application. There is no second one.
The marketing site sets no cookies at all, and runs no advertising pixels or third-party trackers. That is why nothing asked you to accept anything on the way in.
It does count page views, on our own servers. Each page tells us which page was opened and which campaign link brought it — and nothing else. No cookie, no device or visitor identifier, no fingerprint, and no IP address is stored, so two views can never be connected to each other or to you. What we keep is a tally, not a trail: we can see that thirty people read the pricing page after a LinkedIn ad, and we cannot see that any one of them was the same person twice, or who they were.
The typefaces are served from this domain as well, so opening a page here contacts nobody but us — no fonts, scripts, or images are fetched from anyone else, and no third party learns your IP address because you read about our product.
Account and project data is kept while your account is active. Deleting a project deletes its derived documents; disconnecting a git provider deletes its tokens; deleting your account removes your personal data except what we must keep for legal or security reasons. Contact messages are kept as long as needed to handle them.
Traffic is encrypted in transit (TLS). Git provider tokens are encrypted at rest. Access to production systems is restricted. No system is perfectly secure — if we learn of a breach affecting your data we will notify you without undue delay.
You can access, correct, export, or delete your personal data. Depending on where you live (including the EU/EEA, UK, and Israel) you may have statutory rights to the same effect and the right to complain to a supervisory authority. To exercise any of these, reach us through the contact form.
We operate from Israel and process data in the United States on Google Cloud. Where required, transfers rely on appropriate safeguards such as standard contractual clauses implemented by our providers.
The Service is not directed at children under 16, and we do not knowingly collect their data.
We will post any changes to this policy on this page, and for material changes we will notify account holders by email.
Privacy questions or requests: use the contact form on our homepage — we read everything.