Privacy Policy
Last updated: February 2, 2026
Introduction
At Rigour Labs (“we”, “our”, or “us”), we believe privacy is a fundamental right, not a feature. This Privacy Policy explains how we collect, use, and protect your information when you use our services, including Rigour Bot, Rigour MCP Server, and our website at rigour.run.
Our core principle: We collect the minimum data necessary to provide our services, and we never sell your data to third parties.
Information We Collect
When You Use Rigour Bot
- Repository metadata: Repository names, branch names, and pull request numbers necessary to perform code analysis.
- Code diffs: We analyze the changes in your pull requests to detect code quality issues. This data is processed in real-time and not stored permanently.
- GitHub App installation data: Installation IDs and account information required by GitHub's App platform.
When You Use Our Website
- Analytics data: We use Vercel Analytics to understand how visitors use our site. This includes page views, referrers, and general geographic regions. No personally identifiable information is collected.
- Contact information: If you contact us via email, we retain your email address and message content to respond to your inquiry.
When You Use Rigour MCP Server
- Local-first by design: The MCP server runs locally on your machine. Your code never leaves your environment unless you explicitly configure it to connect to our remote API.
- Zero telemetry: We do not collect usage statistics, error reports, or any other telemetry from the local MCP server.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Analyze code in pull requests and provide quality feedback
- Respond to your inquiries and support requests
- Detect and prevent security issues, fraud, or abuse
- Comply with legal obligations
We do not:
- Sell your data to third parties
- Use your code to train machine learning models
- Share your code with other users or organizations
- Retain your code after analysis is complete
Data Retention
- Code analysis: Code diffs are processed in memory and discarded immediately after analysis. We do not store your source code.
- Analysis results: Results are posted to GitHub via the Checks API and stored by GitHub according to their retention policies.
- Account data: If you uninstall Rigour Bot, we delete your installation data within 30 days.
- Support communications: We retain support emails for up to 2 years to provide context for future inquiries.
Data Security
We implement industry-standard security measures to protect your data:
- All data in transit is encrypted using TLS 1.3
- Webhook payloads are verified using HMAC signatures
- GitHub App authentication uses short-lived tokens
- Our infrastructure is hosted on secure, SOC 2 compliant platforms
- We conduct regular security reviews of our codebase
Third-Party Services
We use the following third-party services:
- GitHub: To receive webhook events and post analysis results
- Vercel: To host our website and collect anonymous analytics
- Railway: To host our bot infrastructure
Each of these services has their own privacy policies, and we encourage you to review them.
Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate personal data
- Deletion: Request deletion of your personal data
- Portability: Request your data in a machine-readable format
- Objection: Object to certain types of processing
To exercise any of these rights, please contact us at [email protected].
International Data Transfers
Our services are hosted in the United States. If you access our services from outside the United States, your data may be transferred to and processed in the United States. We ensure appropriate safeguards are in place to protect your data in compliance with applicable laws.
Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the “Last updated” date. We encourage you to review this policy periodically.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Email: [email protected]
- Website: https://rigour.run
- GitHub: @rigour-labs