Privacy notice

Last updated 3 September 2026.

Operator: Léo Duquesnel, a natural person. Contact: leo@bravoure.co.

I am responsible for the collection, processing, privacy, security, and integrity of the data described here. I do not collect it on GitHub’s behalf. Application database and email storage are in the United States.

I store GitHub numeric user id, display name, avatar URL, and primary verified email, plus the installation account login when you bind an install. Invited member emails are stored so I can send the invite, until the invite expires or is accepted. Derived audit data is listed on Data & Security. Identity and audit rows are processed by the hosts named there: Vercel, Neon, Resend, GitHub, and Vercel AI Gateway when you ask for a written patch. Purpose: email a short decision list, track whether workloads are still active, show an install report to the signed-in operator, show a completed public-repo report at its URL without signing in, and, if you click an action, open a draft pull request or a ready-for-review pull request if GitHub refuses drafts, or give you a patch. A successful apply turns watch on. You can stop it. Watch mail may name jobs and paths and attach a .patch. That YAML then sits in Resend about 30 days. A marked copy of the completion email also goes to leo@bravoure.co. That copy then sits in that mailbox; uninstall does not wipe it. An install report URL does not grant access by itself. A completed public-repo report is readable at its URL without signing in, including the status JSON and any .patch download on that report. Those patches are built from the public workflow file on GitHub at request time. They are not stored in the application database.

A message sent from bravoure.co goes to leo@bravoure.co through Resend. It is not stored in the application database.

I do not sell this data. I do not train models on it. There is no model in the audit path. If you ask for a written patch, the measured numbers for the items you selected are sent to the inference provider named on Data & Security. Your workflow files are not. I do not track you across other sites. Other parties do not collect information about your activity across other sites through this app. There are no advertising or analytics pixels. The app sets a first-party CSRF cookie on every page, a session cookie when you are signed in, and short-lived cookies for the GitHub sign-in hop. Browsers may send Do Not Track. I do not change the service based on that signal. Vercel may keep request logs for this host only.

Uninstalling the GitHub App clears live audit rows for that install. It does not by itself delete identity. Revoking GitHub authorization ends access and deletes sessions. Deleting your account removes you from each org. The org stays while it has a member. When the last member leaves, the org and its data are wiped. To delete your user record, encrypted GitHub authorization, public-repo reports you started, and live audit rows for installs you bound, use Delete my data on the install page after you sign in, or email leo@bravoure.co. That control does not uninstall the GitHub App; do that on GitHub. To see what I hold, email leo@bravoure.co from the address on the account.

If I discover a breach of the system, I will email the address on your account within 30 calendar days of discovery (sooner if I can), unless law enforcement requires a delay. That includes unauthorized acquisition of unencrypted personal information, or of encrypted GitHub authorization data together with the encryption key, or of the App private key in a way that could make that data usable. If more than 500 California residents are notified from one incident, I will send the California Attorney General a sample of that notice within 15 days of sending it.

If this notice changes in a material way, I will email the address on your account and update the date on this page.

This service is offered in the United States. If you need a DPA or EU/UK processor terms, say so before signing in or installing. I will pause that handoff; there is no company entity to counterparty a DPA today. Terms.