What DocFit reads
For each enabled repository DocFit reads merged pull requests (title, description, diff, commits, review comments), the documentation folder, and, when connected, the linked Jira or GitHub issue. Code is cloned into a temporary container for the duration of one run and deleted when the run ends.
What DocFit stores
- Your GitHub account id, login, name, avatar and email address, to sign you in and send notifications.
- Run records: which pull request was processed, which pages changed, the resulting diff, check results, model usage and cost, for the retention period set in Settings (7, 30 or 90 days for logs).
- Embeddings of your documentation pages, so DocFit can find the pages a change affects. Embeddings are not readable text and are deleted when a repository is removed.
- Rules your team teaches DocFit through pull-request replies, until you delete them.
- Encrypted OAuth tokens for Jira and Slack and, if you provide one, your own model API key. They are encrypted at rest and decrypted only inside a run.
Who processes it
DocFit runs on Google Cloud. Model requests go to Google Vertex AI and, for some models, to Anthropic. Only the parts of a change needed to write documentation are sent: the diff, the ticket text and the relevant documentation pages. Model providers do not train on this data under the terms DocFit uses. Email is sent through Resend; Slack messages through Slack.
What DocFit does not do
DocFit does not store your source code after a run, does not sell data, and does not read repositories you have not enabled.
Your choices
You can change retention, disconnect integrations, delete rules, remove repositories and delete the workspace from the dashboard. Deleting the workspace removes all stored data after a 30-day grace period. Uninstalling the GitHub App stops all access immediately.
Contact
Privacy questions: use the channel shared with your workspace during onboarding, or reply to any DocFit email.