Technical data disclosure · updated 28 August 2026
Privacy depends on the analysis path.
This page describes the system's designed data flows without using “nothing leaves your machine” as a blanket promise. It is a technical preview disclosure, not a substitute for the independently reviewed privacy notice required before general commercial availability.
Path 01
Public GitHub repository
A shallow temporary clone is created on Explain My Build analysis infrastructure. Temporary source and generated working files are removed when the job finishes, including failure cleanup.
A derived, de-identified evidence digest may be sent to the configured remote AI provider. The hosted preview must identify that provider before confirmation; raw source is not intentionally sent as the model prompt.
Repository identifier, request IP, user-agent, timestamps, job state and runtime may be recorded for abuse prevention and reliability. A defined retention-and-deletion schedule is a production release gate.
Only public GitHub repositories are accepted. The person starting a run must confirm they are authorised to analyse the repository.
Path 02
Private GitHub through the read-only App
The default connection is the fine-grained GitHub App with repository contents read permission and repository selection controlled by the installer. Requested permissions must be displayed before connection.
GitHub authentication material and encrypted Git responses transit the same-origin Explain My Build relay so browser-based Git can work. The relay streams the response and does not intentionally persist source or tokens.
Source is analysed in browser memory after relay. Derived evidence may go to the AI provider selected at confirmation. This path is not appropriate when any source transit through Explain My Build is prohibited.
Use a local folder, local ZIP or CLI when source must remain off Explain My Build infrastructure.
Path 03
Local folder or ZIP in the browser
Files are read in browser memory and are not uploaded to Explain My Build. ZIP input is validated for path traversal, entry count, nesting, total expanded size and compression ratio before extraction.
A remote provider selected by the user may receive a derived evidence digest directly or through the Explain My Build gateway, depending on configuration. A local provider keeps that provider step on-device.
API keys are session-scoped and should be cleared when the tab closes. Long-lived account authentication must use HttpOnly secure sessions rather than browser-readable bearer storage.
Path 04
CLI or desktop
Repository analysis runs on the user's machine. The CLI does not upload raw source to Explain My Build as part of local analysis.
A configured remote model may receive a derived evidence digest. Local-model configuration keeps the model step on the local network or device; users must verify the provider endpoint they configure.
The desktop build is not offered as a production download until release signing, notarisation, update verification and clean-machine install testing are complete.
Accounts and service records
What the service may hold
- Email address and verification state.
- Secure session records, including issue time, last use, approximate client information and revocation status.
- Repository-connection metadata and project history chosen for the workspace.
- Payment-provider identifiers only after commercial activation; card numbers are handled by the payment provider, not stored by Explain My Build.
- Waitlist email, request IP, user-agent and submission time when a person voluntarily joins the waitlist.
Production account controls must include session listing and revocation, sign out everywhere, repository disconnect, security activity, data export and account deletion.
Sensitive information
Do not treat de-identification as a universal guarantee.
The analysis layer classifies evidence as none, personal, health, financial, authentication, customer-confidential or unknown-sensitive. Sensitive runtime attachments require encryption and access control. Unknown-sensitive is handled conservatively. Explain My Build is not currently offered as a compliance-certified processor for regulated data.
Questions and requests
Contact and legal status
Technical privacy questions can be sent to [email protected]. The operator identity, jurisdiction-specific rights, subprocessors, final retention periods and international-transfer language require independent legal approval before general availability. They are not filled with invented placeholders here.