Skip to main content

Privacy notice

Plain-language privacy for a code-review product.

This notice explains how Qohere Private Limited processes personal data and authorized repository information when providing Qedix.

Who operates Qedix

The organization responsible for this notice.

Qedix by Qohere

Qedix is operated by Qohere Private Limited. The public contact location is HSR Layout, Bengaluru, Karnataka 560102, India.

Privacy questions and requests may be sent to info@qohere.in.

Information Qedix processes

The categories depend on how a person or organization uses the service.

GitHub identity

GitHub account identifiers, username, name, available email address, avatar, authentication provider, and sign-in activity.

Workspace and installation

Organization, membership, GitHub App installation, selected repository, and repository-access information.

Pull-request context

Repository and pull-request metadata, branches, commit identifiers, changed files, and relevant code context from repositories authorized for Qedix.

Reports and evidence

Analysis status, recommendations, evidence, affected file paths, relevant code snippets, report history, and GitHub check information.

Support information

Name, email address, message content, and related correspondence when someone contacts Qohere for support.

Operational information

Service events, request timestamps, error information, usage counts, webhook-delivery records, and security or diagnostic logs needed to operate Qedix.

Where information comes from

Qedix receives information directly and through authorized integrations.

From users

Sign-in actions, support messages, privacy requests, and choices made while using the Qedix interface.

From GitHub

Identity, installation, repository, pull-request, code-context, webhook, and check information made available through authorized GitHub access.

From service operation

Reports, evidence, usage records, errors, security events, and diagnostics generated while operating Qedix.

How information is used

Qedix uses information for defined product and operational purposes.

  • 01

    Authenticate users and maintain their Qedix workspace.

  • 02

    Connect authorized GitHub installations and selected repositories.

  • 03

    Analyze supported pull-request changes and generate advisory reports.

  • 04

    Publish or update Qedix check results in GitHub.

  • 05

    Display report history, repository context, and usage information.

  • 06

    Respond to support, privacy, and security requests.

  • 07

    Protect the service, investigate failures, prevent abuse, and maintain reliability.

  • 08

    Comply with applicable legal obligations and enforce service terms.

When information is shared

Qedix does not sell personal data or share it for targeted advertising.

GitHub

GitHub provides authorized account and repository information and receives Qedix check results or related report output in the customer’s GitHub workflow.

Cloud service providers

Contracted cloud service providers process information as needed to host, secure, and operate Qedix.

Email delivery

An email delivery provider processes support, privacy, or security correspondence when someone contacts Qohere.

Legal and organizational events

Information may be disclosed when required by law, to protect rights or security, or as part of a merger, financing, reorganization, or sale subject to appropriate protections.

Service providers may process information only for the services they provide to Qohere and under applicable contractual and legal requirements.

Browser storage and analytics

Technologies used by the current public beta.

Necessary browser storage

Qedix uses browser storage for authentication state and interface preferences such as a selected repository. Clearing browser data or signing out may remove this local state.

No advertising analytics

Qedix does not currently use advertising trackers, targeted advertising, session-replay tools, or a website analytics provider.

Data retention

Retention depends on the information category and operational purpose.

Account information

While the account is active. Verified deletion requests are completed within 30 days, subject to legal obligations.

Temporary repository working copy

Used during analysis and designed for deletion when processing ends. Remnants from interrupted runs are subject to automated cleanup.

Repository and pull-request metadata

While the account is active. Verified deletion requests are completed within 30 days, subject to legal obligations.

Analysis reports and evidence

While the account is active. Verified deletion requests are completed within 30 days, subject to legal obligations.

Support correspondence

12 months after the request is resolved, unless longer retention is legally required.

Security and operational logs

90 days, except where specific records must be preserved for an active security investigation or legal obligation.

Backup rotation

Deleted information may remain for up to 30 additional days in backup rotation unless longer retention is legally required.

Customer choices and controls

Administrators and users retain important control over access.

Repository access

GitHub administrators select repositories during installation and may later change access or uninstall the GitHub App.

Account and data deletion

Qedix does not currently provide self-service account deletion. A verified deletion request may be submitted to info@qohere.in.

Uninstalling the GitHub App stops future App access but does not by itself delete information previously stored by Qedix. Submit a separate verified deletion request when deletion is required.

Privacy rights

Available rights depend on the person’s location and applicable law.

A person may have rights to request access, correction, updating, deletion, or information about the processing of their personal data, and may have the right to withdraw consent or raise a grievance where applicable.

Requests should be sent to info@qohere.in. Qohere may request information needed to verify identity and authority. The target response time is within 30 days after identity verification, subject to applicable law.

International processing

Cloud services may operate across national borders.

Qohere and its service providers may process information in countries outside the user’s location. Where required, Qohere applies relevant contractual and legal requirements to international processing. Exact infrastructure locations are not published for security reasons.

Security and changes

Privacy and security controls evolve with the service.

Security

Qohere uses technical and organizational measures intended to protect information. No method of storage or transmission can guarantee absolute security.

Read the security overview

Notice changes

Qohere may update this notice as Qedix changes. Material updates will be reflected by revising the effective date and providing additional notice where required.

Effective date: July 14, 2026. This notice may be updated as Qedix and applicable requirements evolve.