Privacy Policy
What Haunt collects when it reviews and tests your pull requests, why we need it, and how long we keep it.
Last updated August 25, 2026
Overview
Haunt connects to your GitHub repositories, reviews each pull request, boots the app in a disposable sandbox, tests it like a real user, and posts a report and a recorded demo back on the pull request. Doing that requires access to your code and to the running app, so this policy explains exactly what we touch.
This policy covers the Haunt website, dashboard, GitHub App, and the reports we generate. It does not cover third-party services you reach from Haunt, such as GitHub or Vercel, which have their own policies.
Information we collect
Account information
Your email address, name, avatar, and sign-in identifiers, handled by our authentication provider. If you sign in with GitHub, we receive your GitHub username and account id. We never receive or store your password.
Repository content
When you connect a repository, our GitHub App receives the permissions you grant it. To review a pull request we read its diff, and to test your app we clone the repository into a short-lived sandbox and run it there. We store:
- Pull request metadata: repository name, PR number, title, description, author, and commit SHAs.
- The excerpts of the diff quoted in review findings and comments.
- Artifacts produced by a run: the recorded video, screenshots, the demo script, action timelines, and the written report.
We do not keep a persistent copy of your source tree. The sandbox that holds the clone is destroyed when the run finishes.
Application data seen during a test
Haunt drives your running app, so anything visible on screen during a test can appear in the recorded video and screenshots. If you point Haunt at an environment containing real customer data, that data may end up in a review artifact. Use seeded or synthetic data in the environments you let Haunt test.
Billing information
Plan, credit balance, and usage are stored by us. Card details are collected and stored by our payment processor; they never reach Haunt's servers.
Usage and device data
Standard web analytics (page views, referrer, coarse geography, browser and device type), plus server logs containing IP address and request metadata. We use privacy-friendly analytics and do not sell this data or use it for cross-site advertising.
How we use information
- To run reviews and tests, and to deliver the resulting report and video.
- To authenticate you and keep your workspace and repositories separate from others'.
- To meter credits, bill your plan, and enforce plan limits.
- To operate, debug, and secure the service.
- To respond when you contact us.
We do not use your repository content or review artifacts to train machine learning models, and we do not sell personal information.
AI processing
Haunt's review, planning, and scripting steps send pull request diffs, page snapshots, and run context to large language models through an AI gateway. Our model providers process this content only to return a response, under agreements that prohibit training on it. Model prompts and completions are retained only as long as needed to produce and debug the run.
Service providers
We rely on these categories of subprocessor to run Haunt:
- Hosting, sandboxes, blob storage, and AI gateway: Vercel.
- Model inference: the model providers reachable through that gateway.
- Database: a managed Postgres provider for job and account records.
- Authentication: Clerk.
- Payments: Stripe.
- Source control integration: GitHub.
Each subprocessor receives only what it needs to perform its function and is bound by confidentiality and data-protection terms.
Retention
- Sandboxes: destroyed when the run ends; the repository clone goes with them.
- Reports and artifacts: kept while your account is active, so you can revisit past runs. You can delete a run at any time from the dashboard.
- Account and billing records: kept while your account is open, and afterwards only as long as tax and accounting rules require.
- Logs: rotated on a short cycle.
Sharing a report
Reports are private to your workspace by default. If you mark one public, anyone with the link can view it, including the video, screenshots, and any application content they captured. Check what a report shows before you share it.
Security
Data is encrypted in transit and at rest. Repository access uses short-lived GitHub App installation tokens rather than personal access tokens. Sandboxes are isolated per run and are not reused across repositories. Access to production systems is limited to the people who need it.
Your choices and rights
You can access and correct your account details in your dashboard, delete individual runs and their artifacts, disconnect a repository at any time, and uninstall the GitHub App to revoke our access entirely. To request a copy of your data or full deletion of your account, email hello@haunt.sh. Depending on where you live, you may have additional rights under the GDPR, UK GDPR, or CCPA, including the right to object to processing and to lodge a complaint with your supervisory authority. We honour these requests regardless of where you are.
International transfers
Haunt and its subprocessors operate in the United States and other regions. Where personal data is transferred out of the EEA or UK, we rely on Standard Contractual Clauses or another approved transfer mechanism.
Children
Haunt is a developer tool and is not directed at anyone under 16. We do not knowingly collect information from children.
Changes to this policy
We will update this page and the date above when this policy changes. For material changes we will also notify you by email or in the dashboard before they take effect.
Contact
Questions or privacy requests: hello@haunt.sh. See also our Terms of Service.