Privacy Policy
Last updated: October 1, 2026 · OhMyBug is operated by Explyt (Explicit Insights, LLC) · questions: ohmybug@explyt.com
OhMyBug reviews code you send us and bills you when it finds a real bug. To provide the service, we handle your code, account, and billing data. This page explains what we collect, why we use it, who processes it, how long we keep it, and how to request deletion. We keep only what we need, do not sell it, and never train models on your code.
1. Who is responsible
Explicit Insights, LLC (16192 Coastal Hwy, Lewes, DE 19958, United States) controls the data for OhMyBug at ohmybug.ai, app.ohmybug.ai, and mcp.ohmybug.ai. For privacy questions, write to ohmybug@explyt.com.
2. What we collect
- Account. You sign in with GitHub OAuth. We ask GitHub for the
read:userscope and store your GitHub account id and login. We do not receive your email address or any access to your repositories from sign-in. - API keys. Keys we issue to your agent are stored as SHA-256 hashes. We cannot read a key back; we can only check it.
- The code you send. The diff, plus the context files your agent selects and shows you before upload, plus any files the reviewers ask for during the review. When you install the read-only OhMyBug GitHub App, or the repository is public, we may fetch the diff or a repository copy from GitHub instead of your machine.
- Review records. Review id, repository name, ref, mode, timestamps, size, the findings, the report, and the verdicts your agent submitted. Findings and the report can quote lines from your diff.
- Run transcripts. What the reviewers did during a review. Used to debug failed reviews and to spot billing abuse.
- Billing. Your Stripe customer id, the balance, and every movement of it (charges, packs, subscriptions, expiry, refunds). Your card number and receipt email live at Stripe; they never reach our servers.
- Published stories. If you approve a story for the public feed, we store and publish its text, its lesson, and your GitHub login. The text is anonymised by your agent before you see it; you decide whether to post. Publishing also puts your login on the public leaderboard. Nothing appears there without that step.
- Website. On
ohmybug.aiwe use PostHog analytics and a few first-party cookies (see section 8). If you arrive through an invite link we record the invite code and which landing page brought you to your account when you sign up. Voting on a landing page sends a random visitor id that we cannot tie to you.
We do not ask for data outside these categories. There is no profile form or browser extension, and we do not send email ourselves; Stripe sends receipts.
3. Why we use it
- To run the review you asked for and hand the findings back to your agent.
- To bill you correctly and keep the ledger you can audit.
- To prevent fraud: mainly the pattern of marking a real bug
NOT_REALto dodge the fee, which we check against later diffs. - To debug a failed review, using the transcript.
- To keep the service running and understand which parts of the site people use.
We process your code only to produce the review. We do not use it to train models. The model providers process it under their own API terms, which do not permit training on customer content: Anthropic's commercial terms and OpenAI's enterprise privacy commitments. For some reviews, a classifier picks which known bug types to look for: it gets the changed file paths and how many lines changed in each, never your code, and TypeSafe's privacy policy says it does not train on that input. Those are the providers' commitments, not promises we make for them.
4. Who processes it for us
We use these providers. Each receives only the data its job requires.
- Fly.io (Frankfurt, European Union): hosting of the API and database.
- Sprites (Fly.io) (United States): each review runs in its own throwaway VM whose only network access is the model endpoint and our own API. The VM is destroyed when the review ends.
- Large-language-model inference providers (Anthropic, OpenAI; United States): the reviewers are models; your diff and context are sent to them from inside the sandbox, only to produce the review.
- OpenRouter and TypeSafe (United States): for some reviews, before the sandbox starts, our API asks TypeSafe's classifier, through OpenRouter, which known bug types fit the change. They receive the changed file paths and how many lines changed in each, never lines of code. They keep it under their own terms (OpenRouter's privacy policy, TypeSafe's); TypeSafe's names no retention period.
- GitHub: sign-in, and repository access when you install the GitHub App or the repository is public.
- Stripe: payments, cards, invoices, and the billing portal.
- PostHog (United States): website analytics.
We do not sell your data or share it with advertisers. We disclose it outside this list only when the law requires it or when needed to protect the service from abuse.
5. How long we keep it
- Diff and context files: deleted from our database once the sandbox receives them. The worker streams them into memory for the run. A retry stores them again until its sandbox receives them. Each attempt is capped at 6.5 hours; a worker hand-over continues in the same sandbox under a fresh cap.
- Repository snapshot (full-repository reviews only): held on our API for up to 10 minutes so parallel reviews of one commit can share it, and until the last review finishes seeding (seeding is capped at 60 minutes). We keep no repository copy after that.
- Files requested during a review: held in a hand-off table until the worker reads them, then deleted. Anything left at the end is deleted with the review. The files then live only in the sandbox memory, which is destroyed with the sandbox.
- Run transcripts: 7 days after a completed review, 30 days after a failed one, then deleted automatically.
- Review records (metadata, findings, report, and verdicts): kept as your billing receipt until you delete your account. When a classifier picked bug types for a review, its answer (the bug types and their scores) is kept with the record; the paths it was sent are not.
- Account and API keys: until you delete your account.
- Billing ledger and invoices: 7 years, as tax and accounting law requires, even after account deletion.
- Published stories: until you ask us to take one down.
- Analytics: per PostHog's retention settings for our project; cookies expire after 12 months.
- Landing-page votes: we store the random visitor id, design, and vote direction to show a live tally. We keep this history and do not prune it. Deleting your account does not remove it because it is not linked to an account.
6. Where it is processed
Our API and database run in Frankfurt, in the European Union. Review sandboxes, model inference, the bug-type classifier (OpenRouter, TypeSafe), and PostHog analytics run in the United States. Your review data is therefore processed there as well. If you use OhMyBug from another country, its privacy laws may differ from yours; by using the service, you accept this transfer.
7. Your rights
You can ask us to show, correct, export, or delete your data, or to stop using it for a specific purpose. Email ohmybug@explyt.com with the GitHub login for the account. We do not hold your email address, so we will ask you to prove you control that GitHub account (for example, by posting a short text we provide as a public gist). We reply within 30 days. Deleting your account removes everything except the ledger entries we must keep by law (section 5) and published stories; you can ask us to remove those stories in the same email.
California residents. Under the CCPA, you can ask what personal information we collect and how we use it, and you can ask us to delete or correct it. We will not discriminate against you for using these rights. We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of. Use the email above to make a request.
8. Cookies
omb_v: which landing page variant you saw, so it stays the same on return. 12 months.omb_engine: your choice of coding agent on the landing page. 12 months.omb_promo: an invite code from the link you arrived on, so sign-in can apply it. 30 days.omb_src: which landing page sent you to sign-in, so we know which page works. 30 days.- Local storage on the landing pages, kept until you clear site data:
omb_vid(a random visitor id minted when you first vote on a landing design and sent with your vote),omb_votes(which designs you voted on) and a copy ofomb_engine. - PostHog analytics cookies and local storage: page views and clicks on
ohmybug.ai. 12 months.
The sign-in page (app.ohmybug.ai, served by the same server as mcp.ohmybug.ai) sets the same omb_promo, omb_src, and omb_engine cookies, and nothing else. They are set for .ohmybug.ai (all subdomains), so they survive the hop from sign-in to the API. There is no session cookie; sign-in state stays on our server. You can clear or block these cookies and the site will still work.
9. Security
Traffic is encrypted in transit. We store API keys as hashes. Each review runs in its own VM with network access limited to the model endpoint and our API; the VM is destroyed afterwards. Only the people who run the service can access the database.
10. Children
OhMyBug is not for anyone under 16. We do not knowingly collect data from children; if you believe we have, email us and we will delete it.
11. Changes
We may update this policy. We will post changes here with a new date. If a change materially reduces your rights, we will say so before it takes effect.
12. Contact
Explicit Insights, LLC, 16192 Coastal Hwy, Lewes, DE 19958, United States. ohmybug@explyt.com.