Last modified: September 5, 2026.

Privacy Policy

Privacy Policy Overview

Scitor (scitor.io / scitorapp.com) is owned and operated by MindByte. Scitor ("we", "us" or "our") applies this policy to the Subscriber (the "Subscriber", "user", "you" or "your") — the organisation or person who installs Scitor on a GitHub repository — and describes how we handle the personal data of the Subscriber's own customers ("End Customers") that passes through the service. We process Subscriber data to perform our contract with you and on the basis of our legitimate interest in running, securing and improving the service; where the law requires consent (for example for non-essential cookies) we ask for it.

We collect minimal information when you install Scitor: the name of the repositories, the owner organisation, and the GitHub user who initiates the installation. We also collect aggregate information on what pages visitors access on our website. The information we collect is used to improve the content of our web pages and the quality of our service, and is not shared with or sold to other organisations for commercial purposes, except to provide products or services you have requested, when we have your permission, or under the following circumstances: it is necessary to share information in order to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, or as otherwise required by law. We transfer information about you if Scitor is acquired by or merged with another company. In this event, Scitor will notify you before information about you is transferred and becomes subject to a different privacy policy.

Our Role: Controller and Processor

Scitor handles two kinds of personal data, and our role differs for each.

For Subscriber data — your GitHub account and organisation details, installation and configuration data, billing records, and how you use the app dashboard and our website — MindByte, operating as Scitor, is the data controller.

For End Customer data — the emails, names, message content, attachments, satisfaction survey answers and support conversations of the people who contact you through Scitor — you, the Subscriber, are the data controller and Scitor acts as your data processor, handling that data only to provide the service and on your instructions. You are responsible for having a lawful basis to process your End Customers' data and for informing them as your own privacy notice requires. A Data Processing Agreement covering this processing is available on request at support@scitor.io.

Platform Scope

Scitor is designed exclusively for use with GitHub.com. We do not support GitHub Enterprise Server, self-hosted GitHub instances, or other source code hosting platforms. By using Scitor, you acknowledge that your data flows through GitHub.com and is subject to GitHub's privacy policy in addition to this policy.

Information Gathering and Usage

You may provide personal information to Scitor when you sign up to use the service. Scitor uses collected information for the following general purposes: product and service provision, identification and authentication, service improvement, contact, and research.

Incoming email is processed to create GitHub Issues or Discussions, where the message then lives in your repository under GitHub's policies. Scitor itself does not retain message content except where a feature you have enabled requires it:

  • Public Ticket Portal (opt-in per repository): a copy of each message in the conversation — inbound and outbound — is stored so your End Customer can view and reply to it in a browser, together with their email address and name. These are deleted 30 days after the ticket is closed; you can change this window in your configuration.
  • Contact management (Enterprise, opt-in): contact details — email address, name, company, tags and your agents' notes — are stored for your use and retained for up to two years after the last interaction.
  • Satisfaction surveys: the rating and any comment an End Customer submits are stored against a one-way hash of their email address.

Email addresses used for sender blocking and for satisfaction surveys are stored only as one-way hashes and cannot be reversed. Replies are matched to the right ticket using those hashes together with the delivery records described under Email Delivery. Our operational logs have email addresses redacted.

AI Processing

AI features are off by default. If you enable them — an explicit ai: true in your configuration — incoming messages may be processed by AI to generate summaries, detect sentiment, classify request types, and suggest matching saved replies. This processing runs on Cloudflare Workers AI — the same edge infrastructure as the rest of the service. AI processing is used solely to apply labels, metadata, and agent-facing suggestions to the resulting GitHub Issue or Discussion. Message content is not stored, logged, or used for model training by Scitor. Cloudflare's Workers AI processes data in accordance with Cloudflare's privacy policy and does not use customer data for model training.

If you enable the hosted documentation site and AI assistant, your documentation is indexed with Cloudflare AI Search so the assistant can answer your End Customers' questions from it. Questions are processed by Workers AI via Cloudflare AI Gateway with log collection disabled, so they are not stored as conversations. Answers to frequently asked questions are cached for up to 7 days, keyed by a hash of the question with personal data removed; questions the assistant could not answer are recorded, with personal data removed, for up to 90 days so you can improve your documentation.

Analytics

The Scitor marketing website (scitor.io) uses Statsig for conversion funnel analytics. Statsig records anonymised interaction events — such as which call-to-action buttons were clicked or whether the pricing section was viewed — to help us understand how visitors engage with the site. No personally identifiable information (name, email address, or GitHub username) is included in these events. Statsig processes data in the United States. See Statsig's privacy policy.

The Scitor app dashboard (app.scitor.io) uses PostHog for product analytics and session replay. PostHog records page views and feature interactions — such as AI draft usage and billing upgrade attempts — and session recordings to help us identify usability issues and improve the product. Users are identified by their GitHub user ID and GitHub username, together with their plan and installation; no email address is sent. PostHog is configured to run on their EU cloud (eu.i.posthog.com), meaning all data is stored and processed within the European Union under GDPR-compliant infrastructure. See PostHog's privacy policy.

The Public Ticket Portal (the per-ticket page linked from our emails, used by your End Customers) records anonymous usage events — that a page was viewed, whether a reply was submitted or failed and why, and coarse facts such as device type, browser family, country and whether the link was opened from a webmail client — so we can see how the portal is used and where it fails. These events are not linked to a person profile. Visitors are represented by a one-way hash of their email address, never the address itself, and no message content, IP address, user agent or portal link is included. Country is determined by Cloudflare at the edge; the IP address is not sent to PostHog. Events are processed by PostHog on their EU cloud. The portal sets no analytics cookies.

These tools are used solely for our own product improvement. We do not sell or share analytics data with advertisers or other third parties.

Cookies

The Scitor marketing website sets a session-level cookie via Statsig for analytics purposes. The app dashboard sets cookies and uses local storage via PostHog for product analytics and session replay. Neither service sets advertising or cross-site tracking cookies. You may disable non-essential cookies through your browser settings.

The Public Ticket Portal and hosted documentation sites set no analytics cookies. The portal's reply form and our web forms use Cloudflare Turnstile to verify that a visitor is not a bot; Turnstile may set a cookie for that purpose and processes visitor signals in accordance with Cloudflare's privacy policy.

Data Storage

Scitor runs on Cloudflare's global edge network. Cloudflare acts as a data processor on behalf of Scitor. Account and service data (installation details, configuration, aggregate metrics, delivery events, portal conversations, contact records and survey answers where those features are enabled) is stored in Cloudflare D1; our primary database is located in the European Union (Amsterdam). Email attachments and, if enabled, your hosted documentation are stored in Cloudflare R2. Temporary data such as cached configuration, authentication tokens and cached assistant answers is stored in Cloudflare Workers KV. All data is encrypted in transit and at rest. Although Scitor owns the code, databases, and all rights to the application, you retain all rights to your data.

Data Retention

We keep data only as long as the feature it serves needs it. Unless you ask us to delete it sooner, retention is as follows:

Data Retained for
Portal conversation copies and End Customer contact details (portal enabled)30 days after the ticket is closed (configurable)
Email attachmentsAttachments on the opening message are deleted when its GitHub Issue or Discussion is deleted; all remaining attachments are deleted when Scitor is uninstalled from your GitHub account
Email delivery events (recipient, status)30 days; bounce and spam-complaint records for the life of the account, to protect deliverability
Ticket lifecycle events, reply-threading hashes, sent follow-ups90 days
Contact records and interaction history (Enterprise)2 years after the last interaction
SLA records2 years
Cached AI assistant answers / unanswered questions7 days / 90 days
Aggregate usage metrics (counts only, no personal data)For the life of the account
Operational logs (email addresses redacted)Up to 7 days

When you uninstall Scitor, your installation is deactivated and its data becomes eligible for deletion under the windows above. You can request earlier deletion at any time at support@scitor.io.

Saved Replies & Configuration Data

Saved reply templates and configuration files (e.g. .github/scitor.yaml) are read from your GitHub repository via the GitHub API and cached at the edge (Cloudflare Workers KV) for up to 5 minutes for performance. These files are not permanently stored outside of your GitHub repository. Cache entries are automatically invalidated when you push changes to the relevant files.

Source Code

Scitor does not store any of your private source code unless given explicit, written permission to access it in order to provide support. Scitor does not store GitHub credentials. As a GitHub App, Scitor uses certificate authentication to obtain temporary tokens scoped to the permissions you grant during installation. You can revoke access at any time from your GitHub settings.

Email Delivery

Outbound emails (replies sent via slash commands, scheduled follow-ups and satisfaction surveys) are delivered through Twilio SendGrid, which processes message content solely for the purpose of delivery and is subject to Twilio's privacy policy; data may be processed in the United States. Scitor keeps delivery metadata (recipient address, delivery status, bounce reason) for 30 days to detect delivery problems and to thread End Customer replies onto the right ticket. Scitor does not retain outbound message content after delivery, except as a portal conversation copy when the Public Ticket Portal is enabled (see Information Gathering).

Billing

Paid subscriptions are processed by Stripe. Scitor stores your Stripe customer identifier and subscription status so we can associate your plan with your installation. Card details are entered directly with Stripe and are never stored by, or accessible to, Scitor. See Stripe's privacy policy.

Sub-processors

We use the following third parties to provide the service. Each processes data only for the purpose stated.

  • Cloudflare, Inc. — hosting, database, storage, AI processing, bot protection (Turnstile). Global edge network for request processing; primary database (Western Europe), email attachment storage (Western North America), and knowledge-base storage (Eastern North America) each sit in a fixed location, though none is bound there by a jurisdiction restriction — see scitor.io/security for the full breakdown, including how this compares to where your support conversations themselves live (in your own GitHub repository).
  • GitHub, Inc. — the Issues and Discussions your tickets live in, and app authentication. United States.
  • Twilio Inc. (SendGrid) — outbound email delivery and inbound email receipt. United States.
  • PostHog, Inc. — product analytics for the app dashboard and Public Ticket Portal. EU cloud.
  • Stripe, Inc. — subscription billing. United States / EU.
  • Statsig, Inc. — marketing-website analytics only. United States.

Where a sub-processor processes personal data outside the European Economic Area — including Scitor's own attachment and knowledge-base storage, both operated by Cloudflare in North America — our basis today is Cloudflare's own data processing terms, which Scitor is bound by as a Cloudflare customer. If you need more detail for a vendor-security review, contact security@scitor.io. We will update this list when a sub-processor is added or replaced.

Your Rights

If you are in the European Economic Area, the United Kingdom or another jurisdiction with similar protections, you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. To exercise these rights, contact support@scitor.io; we respond within one month. You also have the right to lodge a complaint with the supervisory authority in your country — in the Netherlands, the Autoriteit Persoonsgegevens.

If you are an End Customer of one of our Subscribers, the Subscriber is the controller of your data and your request should go to them in the first instance; we will assist them in responding, and will pass on any request we receive directly.

GitHub Actions & Workflows

Scitor triggers GitHub events (Issues, Discussions, labels) that may in turn trigger GitHub Actions workflows configured in your repository. Any data processing performed by your own GitHub Actions workflows is outside the scope of this policy and is your responsibility. Scitor does not control, monitor, or have access to the execution environment of your GitHub Actions.

Data Security

We always put security at the forefront of our services. All webhook payloads are verified using cryptographic signatures before processing. GitHub API access uses short-lived, scoped tokens. We cannot, however, ensure or warrant the security of any information you transmit to Scitor, and you do so at your own risk. We make industry-reasonable efforts to ensure the security of our systems. If you find a vulnerability, please report it to us immediately at info@scitor.io. We ask that you do not publicly share the issue until it has been resolved.

Disclosure

Scitor may disclose personally identifiable information under special circumstances, such as to comply with subpoenas or when your actions violate the Terms of Service.

Changes

Scitor may update this policy from time to time. Changes are reflected by the "last modified" date above. We will announce material changes in how we treat personal information with a prominent notice on our site before they take effect. Your continued use of the Service after a change takes effect constitutes acceptance of the updated policy.

Questions

Any questions about the Privacy Policy should be addressed to support@scitor.io.