RuleGapBack to RuleGap

Trust boundary

Privacy Notice

Last updated July 21, 2026

What RuleGap processes

RuleGap processes account identity, workspace membership, billing state, repository metadata, bounded source evidence, scan results, product rules, findings, proof artifacts, feedback, and operational audit records needed to provide the service.

For GitHub sources, RuleGap reads the exact selected commit and stores an eligible-file inventory plus bounded evidence excerpts. It does not retain a full Git clone. User-uploaded ZIP sources remain private and are removed under the workspace retention policy.

Why we process it

We use this data to authenticate users, enforce workspace isolation, inventory repositories, perform requested product-logic analysis, run explicitly authorized proofs, publish configured GitHub checks, meter Logic Credits, prevent duplicate charges, secure the service, and support users.

Model-provider disclosure

A scan sends a bounded, redacted evidence packet—not repository credentials or an unrestricted repository—to the model providers shown before confirmation. Automated GitHub scans require a workspace administrator to accept the same disclosure. Provider credentials stay server-side.

OAuth and connected clients

When you authorize ChatGPT or another MCP client, that client receives a short-lived, audience-bound access token representing your RuleGap account. Existing row-level security and plan capabilities still apply. You can revoke a grant from Workspace Settings; revocation invalidates its refresh access.

Retention and deletion

Evidence and uploaded sources follow the workspace retention period. Billing, security, consent, and audit records may be retained longer when reasonably necessary for fraud prevention, accounting, dispute handling, and legal obligations. Workspace owners can request account or workspace deletion by contacting support@rulegap.cloud.

Service providers and transfers

RuleGap relies on infrastructure and service providers including Supabase, Vercel, Stripe, GitHub, and the model providers disclosed for a scan. They process data under their own agreements and security controls. Data may be processed where those providers operate.

Your choices

You can disconnect repositories, revoke OAuth grants, change eligible retention settings, decline a scan or proof, and request access, correction, export, or deletion. Legal rights vary by location. Contact privacy@rulegap.cloud for a privacy request.

Security and changes

RuleGap uses scoped authorization, row-level security, signed webhooks, bounded uploads, encrypted transport, idempotent billing and job admission, and isolated proof execution. No service is risk-free. Material changes to this notice will be dated here and, when appropriate, communicated in the product.