Version 1.0 · Last updated: 5 July 2026
This policy explains what DXLens (“we”, “us”) collects when you use dxlens.io and the DXLens application (the “Service”), why, and the choices you have.
DXLens (“we”, “us”) operates dxlens.io and the DXLens application. For any privacy question or to exercise your rights, contact support@dxlens.io. Our legal entity and registered address are in the Contact section below.
For data about your organization’s repositories and contributors, your organization is the data controller and DXLens acts as a data processor on its behalf.
| Category | Data | Source |
|---|---|---|
| Account | GitHub user ID, login, display name, primary email, avatar URL | GitHub OAuth, when you sign in |
| Organization | Organization/account ID, login, installation ID, membership role | GitHub, when the app is installed |
| Pull-request metadata | PR number, title, author/reviewer logins & IDs, timestamps (opened, first review, merged, closed), lines added/deleted, changed-file counts, and review counts | GitHub App, for the repositories you enable |
| Commit author metadata | Commit author and co-author identities (names, emails, logins), including Co-authored-by trailers — used to detect AI-assisted pull requests. We read the author list GitHub derives from these trailers, not the commit message body. | GitHub App, for the repositories you enable |
| Configuration | Tracked repos/people, timezone, ignored authors, plan, subscription status | You / your billing provider |
| Session | A single authentication cookie | Set when you sign in |
Legal bases (GDPR Art. 6): performance of our contract with you; our legitimate interests in operating and securing the Service; and compliance with legal obligations. We do not use your data for automated decisions with legal effects.
We use one strictly-necessary cookie to keep you signed in. We do not use analytics, advertising, or tracking cookies, so no cookie-consent banner is required. The cookie is Secure, scoped to dxlens.io, and cleared on sign-out.
We share data only with providers that help us run the Service, under contract:
us-east-1).We do not sell personal data.
The Service is hosted on Amazon Web Services in the United States (region us-east-1), where your data is stored and processed. If you access the Service from outside the United States, your data is transferred there. Where required by applicable law, such transfers rely on appropriate safeguards (such as Standard Contractual Clauses or equivalent mechanisms). Payment data is handled separately by Paddle in the regions where it operates.
Subject to applicable law you may request access, correction, deletion, restriction, portability, or object to processing, and withdraw consent where relevant. Contact support@dxlens.io; we respond within the timeframes the law requires. You may also complain to your local data-protection authority.
We use encryption in transit, least-privilege access, and reputable infrastructure. No system is perfectly secure, but we work to protect your data. In the event of a personal-data breach affecting you, we will notify you without undue delay after becoming aware, in accordance with applicable law.
The Service is for organizations and is not directed to children under 18. We do not knowingly collect their data.
We may update this policy from time to time. The “Last updated” date reflects the current version, and it is your responsibility to review this policy periodically. For material changes affecting how we collect or use your personal data, we will provide notice through the Service or by email before the change takes effect. Other changes take effect immediately upon posting. Your continued use of the Service after any change constitutes your acceptance.
DXLens is operated by Estrela Neva Limited, Unit B, 3/F, Kai Wan House, 146 Tung Choi Street, Mongkok, Kowloon, Hong Kong. For any privacy question or to exercise your rights, contact support@dxlens.io.
This is version 1.0, the initial version of this policy. When this policy is superseded, prior versions will be listed and linked here for reference.