Privacy notice
Effective 11 July 2026
What we process
We process account identity, workspace membership, project and inspection configuration, target URLs, repository metadata you authorise, browser evidence, findings, transcripts, recordings, credit usage, council instructions and learning records, and security audit events.
Why we process it
We use this information to provide inspections, coordinate live sessions, preserve review evidence, prepare approved handoffs, secure accounts, administer subscriptions, and send service updates. Optional product analytics is controlled separately.
Target test access
Release Council does not discover or obtain another application’s credentials. A workspace user may explicitly provide a dedicated, least-privilege test account for one requested inspection. The username, password and approved same-origin login URL are encrypted for the isolated browser worker, expire after the selected short access window, and are scrubbed from the durable browser job after completion or terminal failure. They are excluded from AI prompts, analytics, transcripts, findings, recordings and exports. Do not provide personal accounts, production passwords, OTPs, recovery codes, payment credentials or real customer data.
AI providers
Relevant evidence, standing instructions and accepted learning may be sent to the configured AI provider to perform the review or live voice session. AI processing requires consent for human-participation sessions. Do not submit personal or confidential information that is unnecessary for the inspection.
Recordings and transcripts
Human-participation reviews require explicit recording consent and a durably saved session recording before conclusion. Browser permission is required to capture microphone, screen or tab audio. The workspace stores the uploaded recording and speaker-attributed review record according to its retention setting.
GitHub and integrations
GitHub connection is optional and limited to repositories you select. Write-capable remediation actions and external handoffs remain approval-gated. Signed adapters may transmit an approved bundle to a destination configured by your workspace operator.
Retention, access and deletion
Workspace data uses tenant-scoped access controls. The account owner can request access, export or deletion, subject to security, billing and legal-record obligations. Council instructions and learning records are included in tenant deletion. Contact support@releasecouncil.app for a privacy request.
Security and service providers
Data is encrypted in transit. Security controls include authenticated access, tenant scoping, audit events, restricted administrative access and configurable private evidence storage. See the security overview and subprocessor list for more information.