Privacy Policy
Last updated: 25 August 2026
This describes what Review Baton stores, why, for how long, and who else touches it. It is written from the actual database and code rather than from a template, so it says what we hold and no more.
Two roles
For your account — the person who signs up, the billing relationship, the sign-in emails — we are the data controller.
For the review data we process on your behalf — your colleagues’ usernames, the pull requests, the chat messages — you are the controller and we are your processor, acting on your instructions.
What we store
| Data | Why |
|---|---|
| Work email address of each console user, role, and time of last sign-in | To sign you in and to know who may change your account |
| IP address of sign-in requests, and a hash of each sign-in link | To rate-limit sign-in attempts and to make each link single-use. The link itself is never stored. |
| Access tokens and webhook secrets for GitHub, GitLab, Slack and Telegram | To read review activity and post messages. Stored encrypted, never displayed back. |
| Pull request metadata: project, number, title, URL, author, reviewers, approvals, state, timestamps | To build the thread and work out whose turn it is |
| Chat identifiers: workspace or chat id, channel, message ids, the mention handle of each person | To post into the right thread and address the right person |
| The link between a source-control username and a chat account | So a reminder reaches a person rather than a string. Matched automatically by email where the platforms expose it. |
| Preferences: timezone, vacation dates, snooze | To stay quiet when we should |
| Raw webhook payloads from your source control | To process events reliably and not lose them during an incident |
| An audit log of console actions, with the acting email address | So an account owner can see what changed and who changed it |
We do not store the contents of your repositories, your source code, or diffs. Comment text appears in a notification when the platform sends it to us as part of an event, and is kept only as part of the message we delivered.
What we do not do
- No analytics, no advertising pixels, no third-party trackers on this website or in the console.
- No cookies on this website at all. The console sets one session cookie, which exists only to keep you signed in.
- Web fonts are served from our own server, so loading a page here does not tell anyone else that you visited.
- We do not use your data to train machine learning models, and we do not sell or share it for anyone else’s marketing.
Legal bases
Where the GDPR applies: we process account and review data to perform our contract with you; we process sign-in IP addresses and the audit log under our legitimate interest in keeping accounts secure; and we keep billing records because the law requires it.
Who else processes it
| Processor | What for | Where |
|---|---|---|
| DigitalOcean | Servers and database | Amsterdam, Netherlands |
| Resend | Sign-in and notification email | United States |
| Paddle | Payments, invoicing, tax — as Merchant of Record | United Kingdom / European Union |
Your own GitHub, GitLab, Slack or Telegram are not our processors — they are your services, which you authorise us to talk to.
How long we keep it
- Raw webhook payloads and delivered messages: 30 days, then deleted automatically.
- Sign-in links and pending authorisation states: until they expire, then cleared daily. A link is burned the moment it is used.
- Backups: 7 days, rolling, held on the same server in the Netherlands.
- Account, integration and review data: for as long as your account exists. Delete the account and it goes, except records we are legally required to keep — chiefly invoices.
Security
Access tokens and webhook secrets are encrypted before they are written to the database, under a master key held only in the server environment and rotatable without downtime. Everything travels over TLS. The database is not reachable from the internet. Backups are compressed rather than encrypted, are kept on the same server, and their restore is tested weekly against a throwaway database rather than assumed to work.
If a breach affects your data, we will tell you — within 72 hours of becoming aware where the GDPR requires it, and in plain language about what happened.
Your rights
You can ask for a copy of your data, correction of it, deletion of it, or a machine-readable export; you can object to processing based on legitimate interest. Write to support@reviewbaton.com and we will answer within 30 days. If you are in the EEA or the UK and think we have handled this badly, you may complain to your national data protection authority.
If you are a member of someone else’s Review Baton account, send the request to them: your data is under their control and we act on their instructions.
International transfers
The servers and the database are in the Netherlands, inside the EU. Of our processors, only Resend is in the United States; transfers to it rely on the European Commission’s standard contractual clauses. Paddle operates from the United Kingdom and the European Union.
Children
This is a tool for professional software teams. It is not directed at anyone under 16, and we do not knowingly hold their data.
Changes
Material changes are emailed to account owners before they take effect, and the date at the top always reflects the current version.
Contact
Aleksandr Kazakov, individual entrepreneur, Tbilisi, Georgia — support@reviewbaton.com.