Last updated: April 15, 2026
Privacy Policy
BlueAI Solutions Ltda., registered under CNPJ nº XX.XXX.XXX/0001-XX ("BlueAI", "we", "our"), is the controller of the personal data processed by the BlueAI Akira service, under the terms of Lei nº 13.709/2018 (LGPD). Here you'll find, straightforwardly, what we collect, why we collect it, and how we keep it all secure.
BlueAI Solutions' Data Protection Officer (DPO) can be reached by e-mail at contato.akira@blueaisolutions.com.br, under the terms of Art. 41 da LGPD.
1. Data we collect
When you create an account or connect your GitHub, we collect only what's necessary for the service to work:
- Account: your name, e-mail, and GitHub profile picture.
- Repositories: repo names, pull requests, and code snippets (diffs) sent for review.
- Service usage: pages visited, actions taken, and performance metrics.
- Payment: processed directly by Stripe. No card number ever passes through our servers.
2. Legal bases and purposes
Your data exists to make Akira work for you — nothing beyond that. Each processing activity has a specific legal basis under LGPD:
- Contract performance (Art. 7º, V): analyzing your pull requests, displaying metrics on the dashboard, and processing payments.
- Consent (Art. 7º, I): sending promotional communications — which you can cancel at any time.
- Legitimate interest (Art. 7º, IX): usage data to improve the quality and stability of the service.
- Legal obligation (Art. 7º, II): billing records kept in accordance with Brazilian tax requirements.
3. Code analysis and AI
We know your code is your work — and we treat it with respect. Only the diffs from your PRs are sent to AI models (Google Gemini or Anthropic Claude), exclusively for security and quality analysis. We do not send entire repositories, commit history, credentials, or environment variables.
Your code is never used to train AI models. The analysis happens on demand, at the moment of review, and the results are stored only for display on your dashboard. No code snippet is retained, shared, or reused for any other purpose.
Both providers (Google LLC and Anthropic PBC) are based in the USA. Sending the diffs constitutes an international data transfer under Art. 33 da LGPD, carried out on the basis of contractual clauses that guarantee an adequate level of protection. According to the providers' current policies, input data may be temporarily retained (for up to 30 days) for abuse detection, and automatically deleted after that period.
4. Sharing and international transfer
We do not sell your data. Period. We only share it with the technical partners necessary for the service to work:
- Stripe, Inc. (USA): processes your payments securely. PCI-DSS Level 1 certified — the industry's highest standard.
- Supabase, Inc. (USA): handles authentication and storage of your data, with encryption at rest.
- Google LLC and Anthropic PBC (USA): receive only the diffs for code analysis, as described in Section 3.
- Vercel, Inc. (USA): hosts the site and collects anonymous performance analytics.
- Contabo GmbH (Germany): hosts the backend infrastructure (API and services) on dedicated servers.
All the providers above are located outside Brazil, constituting an international data transfer (Art. 33 da LGPD). These transfers are carried out through contractual clauses that guarantee a level of protection compatible with Brazilian legislation.
5. Security
We protect your data with the same practices you'd expect from any serious development tool — technical and administrative measures designed to protect against unauthorized access, loss, or any inappropriate processing:
- Encryption in transit (TLS/HTTPS) across all communications.
- Secure authentication via GitHub OAuth 2.0, with sessions managed by Supabase Auth.
- Row Level Security (RLS) in the database — each user only accesses what's theirs.
- Credentials and environment variables securely managed via Infisical.
- Access to production servers restricted to the authorized technical team.
- Periodic review of security practices and access policies.
No system is 100% secure. If you identify any vulnerability or suspect an incident, contact us immediately at contato.akira@blueaisolutions.com.br.
6. Data retention and deletion
We keep your data only for as long as necessary. Here are the retention periods by category:
- Account data (name, e-mail, avatar): for as long as the account is active. Deleted within 30 days after account deletion.
- Review data (diffs and results): for as long as the account exists. Deleted within 30 days after deletion.
- Payment and billing: kept for 5 years in accordance with tax legislation (Art. 174 do CTN).
- Access records (logs): kept for 6 months in accordance with the Marco Civil da Internet (Art. 15, Lei nº 12.965/2014).
- Analytics: collected anonymously by Vercel Analytics, with no personal identification.
After processing ends, data is deleted — except in the retention scenarios provided for in Art. 16 da LGPD (legal obligation, research, or the controller's exclusive use with anonymization).
7. Your rights as a data subject
LGPD ensures you're in control. Under the terms of Art. 18, you may at any time:
- Confirm whether we process your personal data.
- Access the data we hold about you.
- Correct incomplete, inaccurate, or outdated data.
- Request anonymization, blocking, or deletion of unnecessary or excessive data.
- Request the portability of your data to another service.
- Request deletion of data processed based on consent.
- Know exactly who your data is shared with.
- Be informed about the consequences of not providing consent — in this case, being unable to use the code review service.
- Withdraw your consent at any time.
To exercise any of these rights, send an e-mail to contato.akira@blueaisolutions.com.br with the subject line "Direitos LGPD". We will respond within 15 business days. If you're not satisfied with our response, you may file a complaint with the ANPD (Autoridade Nacional de Proteção de Dados).
8. Cookies and analytics
We only use essential cookies — the ones that keep you logged in and your preferences saved. No surprises:
- Session cookies (Supabase Auth): necessary for authentication. They cannot be disabled.
- Vercel Analytics: collects anonymous, aggregated data about site performance. It does not use cross-site tracking cookies and does not personally identify you.
We do not use advertising, remarketing, or behavioral tracking cookies. Zero.
9. Children and minors
BlueAI Akira is not directed at anyone under 18 and we do not intentionally collect data from children or minors. If we become aware that a minor's data was collected without the legal guardian's consent, we will take the necessary steps to delete it immediately.
10. Security incidents
In the event of an incident that may pose a risk or harm to data subjects, we will notify the ANPD and the affected data subjects within a reasonable timeframe, in accordance with Art. 48 da LGPD, informing the nature of the affected data, the risks involved, and the measures taken to mitigate the effects.
11. Changes to this policy
We may update this policy to reflect changes to the service or the law. Significant changes will be communicated at least 15 days in advance by e-mail or notice within the service. When changes affect processing based on consent, we will request new consent. The date of the last update will always be shown at the top of this page.
12. Get in touch
For privacy questions, to exercise your rights, or to report any concern, write to: contato.akira@blueaisolutions.com.br