Privacy Policy

Effective date: August 18, 2026

1. Who we are

Pelcrow is operated by RappaDev LLC (“we”, “us”, “our”). This policy describes how we collect and use information when you use Pelcrow at pelcrow.com.

2. Information we collect

Repository content. When you install the Pelcrow GitHub App and grant it access to repositories, we read the Markdown files in those repositories to build your content index. This content is stored in your tenant’s isolated database partition and is never shared with other tenants.

Account information. We store your GitHub user ID and username to authenticate you and associate your actions with your account.

Usage logs. We log API requests (method, path, HTTP status, duration, and a redacted token identifier) for security auditing and debugging. Logs do not contain request or response bodies.

3. How we use your information

  • To provide the Pelcrow service: indexing your documentation, validating drafts, and serving MCP tool calls.
  • To authenticate and authorize access to your workspace.
  • To detect abuse and enforce rate limits.
  • To improve the service based on aggregate, anonymized usage patterns.

4. Third-party services

GitHub. Repository content is accessed via the GitHub App API using the installation grant you authorize. We do not access repositories beyond those you select during installation.

OpenAI / Anthropic (optional). If you configure your own OpenAI or Anthropic API key in Pelcrow’s settings, document content may be sent to that provider when you use AI generation features. Your keys are encrypted at rest. We do not share your keys or content with these providers on your behalf unless you have explicitly configured them.

Embeddings. Semantic search embeddings are computed locally on our servers using an on-device ONNX model. No document content is transmitted to external embedding APIs.

Stripe. Payment processing is handled by Stripe. We do not store full credit card numbers. Stripe’s privacy policy governs data you provide during checkout.

5. Data retention

Your indexed content is retained for as long as your account is active. You may delete your account and all associated data at any time by contacting us at privacy@pelcrow.com. We will complete deletion within 30 days.

6. Data security

All data is transmitted over TLS. API tokens are hashed before storage and never logged in plaintext. Each tenant’s data is isolated at the database level via row-level security policies.

7. Your rights

Depending on your location, you may have the right to access, correct, or delete your personal data, or to object to or restrict certain processing. To exercise these rights, contact us at privacy@pelcrow.com.

8. Children

Pelcrow is not directed at children under 13. We do not knowingly collect personal information from children under 13.

9. Changes to this policy

We may update this policy from time to time. We will post the updated policy here with a new effective date. Continued use of the service after changes constitutes acceptance of the updated policy.

10. Contact

Questions about this policy: privacy@pelcrow.com