Reviews

Privacy

Reviews is made and run by Hugo Dias. Its source is public, so you can check everything below against the code. Last updated 5 October 2026.

What Reviews reads on GitHub

You sign in with GitHub. The Reviews GitHub App asks for read-only access to repository contents and metadata, and only for the repositories you install it on. Reviews reads files with your own GitHub token, so it only ever sees what your account can read. It never writes to GitHub.

What Reviews stores

  • Your GitHub profile: your user id, username, display name and avatar URL, refreshed each time you sign in. Not your email address.
  • Your comments: the comment text, the passage you selected (copied from the file, with a little text on either side so it can be found again), and the repository, file and commit it belongs to. Also who wrote it, when, and whether the thread is resolved. When a coding agent posts for you, the name the agent gave itself is stored with the comment.
  • Your session: a random token in a cookie that lasts 30 days. The server keeps the session's GitHub tokens encrypted and deletes them when you sign out. If you never sign out, they're deleted within about six months, once GitHub's own expiry for them passes.
  • Connected agents: each agent you connect gets its own encrypted GitHub token. Its access lasts an hour at a time and ends after 30 days without use, or as soon as you disconnect it.

Reviews doesn't store your IP address or email address.

Cached copies of your repositories

To keep pages fast, Reviews caches what it reads from GitHub at Cloudflare: file contents, file lists and commit history for up to 30 days, and images shown in documents for up to a year. Cached copies are stored by content, and Reviews checks that you can read the repository before serving any of them. Checks of who can read what are cached for a few minutes, so access removed on GitHub can take up to about 6 minutes to take effect here.

Who can see your comments

Only people who have been given access to the repository on GitHub, and only once the Reviews GitHub App is installed on it. That holds for public repositories too: being able to read a public repository isn't enough, so comments are never published to the web. What someone can do with comments follows their role on the repository, as described in the README. Agents you connect can read comments in the same repositories you can, and post as you if you allowed that when connecting them.

Logs and error reports

Reviews runs on Cloudflare Workers with Cloudflare's logs, traces and error reports turned on. Errors are labeled with your GitHub user id and username, a one-way hash of your session token, and, for agents, the agent's name. Query strings are removed from logged URLs. Cloudflare may record more about each request, such as your IP address; see Cloudflare's privacy policy.

Analytics

Reviews counts visits with Umami, run by Hugo Dias. For each page you open, your browser sends the page's address and title, the page you came from, your screen size and language, and how quickly the page loaded. On file pages, the address and title are replaced before they leave your browser: Umami sees /:owner/:repo and “File”, never the repository or file. Query strings and # anchors are left off every address.

From the request, Umami works out your browser, operating system, device type and rough location (country, region and city). It counts returning visitors with an id made from your IP address and browser that changes every month, and it doesn't store your IP address or set cookies. To opt out, run localStorage.setItem('umami.disabled', '1') in your browser's console on this site.

Reviews has no ads, and no scripts from anyone else. Its fonts are served from Reviews itself. Your browser loads avatars from GitHub, and images in documents from wherever they're hosted, without sending the page address.

Cookies and browser storage

  • __Host-session: keeps you signed in, for 30 days.
  • oauth and return_to: carry a sign-in across the trip to GitHub, for 10 minutes and 1 hour.
  • Cookies starting with __Host-oauth-: carry an agent connection through its consent screen, for 10 minutes.
  • theme and sidebar_state: remember your light or dark choice for a year, and whether the file sidebar is open for a week.
  • Your browser's local storage keeps the last few files you opened, for the home page. It never leaves your browser.
  • umami.disabled in local storage, if you set it, turns analytics off.

Who else handles your data

Cloudflare hosts Reviews: its database, caches and logs. Railway hosts the Umami analytics. GitHub handles sign-in and serves your repositories. Agents you connect receive the comments they ask for. Nobody else gets your data, and it's never sold.

Removing your data

  • Signing out deletes your session and its GitHub tokens.
  • Connected agents in your account menu disconnects an agent and deletes its tokens.
  • Uninstalling the GitHub App, or revoking it in your GitHub settings, stops Reviews from reading your repositories.
  • Deleting a comment hides it from everyone, but its text stays in the database. To remove your profile, comments and threads for good, open an issue. You don't need to say more than your GitHub username.

Changes

This page changes when Reviews does. Every version is in the repository's history.