Last updated: September 8, 2026
Privacy Policy
This Privacy Policy explains how Boson (“Boson,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with the Boson website, the Boson dashboard, and the Boson GitHub App (together, the “Service”). Boson is operated by Sakib Sadman Shajib, an individual based in Canada who runs Boson as a sole proprietorship under that name, so the party responsible for the information described here is that individual rather than a company. By installing the GitHub App, creating an account, or otherwise using the Service, you agree to the collection and use of information as described here.
1. Scope
This policy covers the public marketing site, the authenticated dashboard, and the Boson GitHub App. It does not cover third-party sites we link to or third-party services you connect to Boson, which are governed by their own privacy policies.
2. Information We Collect
Account and sign-in information. When you create a Boson account you provide an email address and password through our authentication provider (Amazon Cognito). If you sign in with Google instead, we receive the basic profile information Google shares under the email, openid, and profile scopes: your name, email address, and Google account identifier. We do not request, and Google does not share, anything beyond that basic profile under this integration.
GitHub account and installation information. When your GitHub account or organization installs the Boson GitHub App, we receive your GitHub account or organization identifier, login name, and the list of repositories you chose to install the App on. We link this installation to your dashboard account so you can see reviews for repositories you have access to.
Pull request and code content. When a review is requested on a pull request in a repository where the App is installed, we process the changed files, diff content, and related repository context needed to produce that review. Section 4 explains how this content is handled.
Payment information. Paid plans are billed through Stripe. Stripe collects your payment card or other payment details directly; we do not receive or store your full card number on our own servers. We receive limited billing metadata from Stripe, such as your subscription status and the last four digits of your payment method, to reconcile invoices and manage your account.
Log and usage data. Our infrastructure automatically records request metadata (such as timestamps, endpoint, and status code) for operating and securing the Service, and we record which repositories requested reviews, when, and at what cost for billing and quota enforcement.
3. How We Use Information
- To operate, maintain, and secure the Service.
- To produce the review posted back to your pull request.
- To authenticate you, link your account to the correct GitHub tenant, and enforce per-account access.
- To process payments, calculate usage-based charges, and send billing communications.
- To enforce input limits and daily quotas before a review is ever queued.
- To provide support, respond to enquiries, and communicate service-related notices.
- To comply with legal obligations.
4. How Pull Request and Code Content Is Processed
A review runs only when explicitly requested, by commenting @boson review on a pull request or triggering a review from the dashboard. The relevant diff and repository context are processed in an isolated review environment. To generate the review, Boson sends the relevant code and diff content to our large-language-model relay, OpenRouter, which routes the request to an underlying model provider.
Boson does not train its own models on your code, because Boson does not train models at all: it calls a third-party relay for each review. We do not currently offer a contractual zero-data-retention guarantee covering every model we route through; retention of content sent through OpenRouter is governed by OpenRouter’s and the relevant underlying model provider’s own policies, which can vary by model and change over time. If your organization requires a specific data-handling commitment for LLM processing, contact us before enabling the Service on a repository.
Boson posts findings back to the pull request as a single comment. Boson never approves a pull request and never requests changes on your behalf; a human always makes the merge decision.
5. Data Retention
We retain account, billing, and installation records for as long as your account is active and afterward as needed to comply with legal, tax, and accounting obligations. Operational infrastructure logs are retained for a short, fixed window (currently approximately seven days) and then deleted. We retain pull request and diff content only as long as needed to produce, deliver, and support a given review, and to enforce quotas and billing; we do not use it for any purpose beyond operating and improving the Service.
6. Subprocessors and Third-Party Service Providers
We share information with the following categories of service providers, each acting under its own terms and only to the extent needed to provide the Service:
- OpenRouter: large-language-model relay used to generate review findings from pull request content.
- Stripe: payment processing and billing.
- Amazon Web Services: hosting, authentication (Amazon Cognito), and supporting infrastructure.
- Cloudflare: content delivery and DNS for our public website.
- GitHub: the platform through which the GitHub App reads pull requests and posts review comments.
This list reflects the providers we use as of the date above and may change; material changes will be reflected in an updated version of this policy.
7. GitHub App Access and Permissions
Installing the Boson GitHub App grants Boson access, scoped to the repositories you select, to read pull request content needed to review it and to post a single comment back to that pull request. Boson does not approve pull requests or request changes. The exact permission grant is configured on the App and is always visible to you, and revocable by you, from your GitHub account or organization’s installed-App settings. Uninstalling the App immediately stops any future access to your repositories.
8. Cookies and Tracking
This website does not currently use third-party advertising or analytics tracking cookies. The dashboard uses only the session tokens required to keep you signed in.
9. Data Security
We use encryption in transit for all Service traffic, signature verification on incoming webhooks, and least-privilege access controls that scope each internal service to only the data it needs. Tenants are isolated by installation, and every query is scoped to the requesting account. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your Rights and Choices
- You can update your account information from the dashboard.
- You can uninstall the GitHub App at any time from your GitHub settings to stop all further repository access.
- You can request access to, correction of, or deletion of your personal information by contacting us using the details in Section 14.
- Depending on where you live, you may have additional rights under applicable data protection law; we will honour valid requests as required by that law.
11. International Data Transfers and Hosting Location
Boson is operated by an individual based in Canada. The control plane, authentication, and supporting infrastructure currently run on Amazon Web Services in the United States (US East region), so information you provide is transferred to and processed in the United States regardless of where you or the operator are located.
12. Children’s Privacy
The Service is intended for business and professional use and is not directed to children. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, contact us and we will delete it.
13. Changes to This Policy
We may update this policy from time to time. We will post the revised policy here and update the “Last updated” date above. If a change is material, we will make reasonable efforts to notify account holders. Continued use of the Service after a change takes effect constitutes acceptance of the revised policy.
14. Contact Us
Questions about this policy, or requests regarding your information, can be sent to [email protected]. This policy is published by Sakib Sadman Shajib, the individual who operates Boson as a sole proprietorship in Canada.