SourcePRD
How it works Security Pricing Sign in Contact us

Privacy Policy

Last updated: July 25, 2026

This policy explains what SOFTLINK LTD, the company operating SourcePRD ("we", "us"), collects when you use sourceprd.com and pm.sourceprd.com (the "Service"), why we collect it, and the choices you have. The short version: we collect what the product needs to work, we don't sell data, we don't run ad trackers, and your code stays yours.

1. What we collect

  • Account data. When you sign in with Google we receive your name, email address, and avatar. With email sign-in we store your email and a credential managed by Firebase Authentication. On first sign-in we ask for your name, job title, and company.
  • Git connections. When you connect GitHub, GitLab, or Bitbucket we store the OAuth tokens needed to act on your behalf, encrypted at rest. We never see your git provider password.
  • Repository content. To generate a PRD we read repository content and pull-request metadata through the access you granted. Excerpts are processed transiently for analysis; what we store is the derived documentation (PRDs, feature descriptions, change reports) and the settings of your projects.
  • Messages you send us. Contact-form and waitlist submissions (email address and message).
  • Technical data. Standard server logs (IP, timestamps, request paths) for security and operations, and a single authentication cookie.

2. What we do with it

We use this data to operate the Service: generate and update your documents, run the PR approval gate, show notifications, provide support, and keep the Service secure. We do not sell personal data, we do not run advertising or cross-site tracking, and we do not use your repository content to train models of our own.

3. AI processing

Document generation sends excerpts of repository content to third-party AI model providers — currently OpenAI and/or xAI — under their API terms, which do not permit them to use API data to train their models. Excerpts are sent only when you (or webhooks you enabled) trigger analysis.

4. Who else processes data

  • Google Cloud & Firebase — hosting, authentication, and databases (processed in the United States, us-central1).
  • OpenAI / xAI — AI analysis of repository excerpts, as described above.
  • Paddle — payments. Paddle acts as merchant of record and is an independent controller of the billing data you provide at checkout (we never see your full payment details).
  • GitHub / GitLab / Bitbucket — per the connections you choose to make.

5. Cookies

We use one first-party cookie, __session, to keep you signed in to the application. There are no analytics or advertising cookies on this site.

6. Retention

Account and project data is kept while your account is active. Deleting a project deletes its derived documents; disconnecting a git provider deletes its tokens; deleting your account removes your personal data except what we must keep for legal or security reasons. Contact messages are kept as long as needed to handle them.

7. Security

Traffic is encrypted in transit (TLS). Git provider tokens are encrypted at rest. Access to production systems is restricted. No system is perfectly secure — if we learn of a breach affecting your data we will notify you without undue delay.

8. Your rights

You can access, correct, export, or delete your personal data. Depending on where you live (including the EU/EEA, UK, and Israel) you may have statutory rights to the same effect and the right to complain to a supervisory authority. To exercise any of these, reach us through the contact form.

9. International transfers

We operate from Israel and process data in the United States on Google Cloud. Where required, transfers rely on appropriate safeguards such as standard contractual clauses implemented by our providers.

10. Children

The Service is not directed at children under 16, and we do not knowingly collect their data.

11. Changes

We will post any changes to this policy on this page, and for material changes we will notify account holders by email.

12. Contact

Privacy questions or requests: use the contact form on our homepage — we read everything.

© 2026 SourcePRD · Sign in · Pricing · Security · Terms · Privacy · Refunds This page's spec lives in our PRD — of course.