Last updated: July 25, 2026
This policy explains what SOFTLINK LTD, the company operating SourcePRD ("we", "us"), collects when you use sourceprd.com and pm.sourceprd.com (the "Service"), why we collect it, and the choices you have. The short version: we collect what the product needs to work, we don't sell data, we don't run ad trackers, and your code stays yours.
We use this data to operate the Service: generate and update your documents, run the PR approval gate, show notifications, provide support, and keep the Service secure. We do not sell personal data, we do not run advertising or cross-site tracking, and we do not use your repository content to train models of our own.
Document generation sends excerpts of repository content to third-party AI model providers — currently OpenAI and/or xAI — under their API terms, which do not permit them to use API data to train their models. Excerpts are sent only when you (or webhooks you enabled) trigger analysis.
We use one first-party cookie, __session, to keep you signed in to the application. There are no analytics or advertising cookies on this site.
Account and project data is kept while your account is active. Deleting a project deletes its derived documents; disconnecting a git provider deletes its tokens; deleting your account removes your personal data except what we must keep for legal or security reasons. Contact messages are kept as long as needed to handle them.
Traffic is encrypted in transit (TLS). Git provider tokens are encrypted at rest. Access to production systems is restricted. No system is perfectly secure — if we learn of a breach affecting your data we will notify you without undue delay.
You can access, correct, export, or delete your personal data. Depending on where you live (including the EU/EEA, UK, and Israel) you may have statutory rights to the same effect and the right to complain to a supervisory authority. To exercise any of these, reach us through the contact form.
We operate from Israel and process data in the United States on Google Cloud. Where required, transfers rely on appropriate safeguards such as standard contractual clauses implemented by our providers.
The Service is not directed at children under 16, and we do not knowingly collect their data.
We will post any changes to this policy on this page, and for material changes we will notify account holders by email.
Privacy questions or requests: use the contact form on our homepage — we read everything.