Privacy Policy
Diffr reviews code on your machine. This page lists every piece of data we hold, where it lives, and who else can see it.
Last updated 27 July 2026 · DEV360 LLC
The short version
Your code never reaches us. Repositories, diffs, file contents and file paths stay on your machine.
We hold an account record only if you sign in with GitHub, and billing records only if you buy a licence. The site records the limited pageview data described below. There is no advertising or cross-site tracking.
DEV360 LLC is the controller of that data. Contact: [email protected].
The desktop app
Diffr runs locally and needs no account. You can download it and review code without ever contacting us.
The application contacts releases.getdiffr.com after launch to check for an update. That request necessarily gives the update server your IP address and user-agent. The app also contacts GitHub when you start sign-in to attach a licence. After the first sign-in the licence is verified locally and works offline. There is no telemetry, crash reporting or usage analytics in the desktop app.
The usage counter behind the support request is a number stored on your own machine. It is never transmitted.
If you sign in with GitHub
Signing in creates an account record. It holds:
- Your GitHub username — this is what a licence is keyed to.
- Your name, email address and avatar URL, as GitHub reports them.
- An OAuth token from GitHub, so the sign-in can be completed and refreshed.
- Session records — a session token with its expiry, plus the IP address and browser user-agent the session was created from. These exist to keep you signed in and to make account abuse visible.
- If you link the desktop app, a short-lived device code used to complete that linking, which expires on its own.
We request only GitHub's basic profile scope. We do not request, receive or have any access to your repositories.
If you buy a licence
Payment is processed by Stripe. Your card details go directly to Stripe and are never sent to, seen by, or stored on our servers.
From the transaction we store:
- Your licence: GitHub username, plan, expiry date.
- Your subscription state: the Stripe customer and subscription identifiers, the status, and when the current period ends. This is what lets the account page show your billing state and open the billing portal.
Stripe holds the payment data itself under its own privacy policy, and acts as our processor for the transaction.
The website
On each page load, the site sends one pageview beacon to collect.metrikk.dev. It contains the site hostname, the full page path and query string, and a timestamp. The analytics server also receives your IP address and browser user-agent as part of the HTTP request. The beacon uses no cookies or fingerprinting and does not track you across sites or serve advertising.
getdiffr.com sets one kind of cookie: the session cookie that keeps you signed in. There is no advertising cookie and nothing that follows you to other sites.
The device-linking page also temporarily stores a pending device code in your browser's session storage. Our host keeps standard server request logs, which include IP addresses, for operational and security purposes.
Who else sees it
Three companies, each for one job:
- Stripe — payments, subscriptions and refunds.
- Cloudflare — hosts the site and the database that stores accounts and licences.
- GitHub — sign-in, and the source of the profile fields above.
That is the complete list. We do not sell your data, we do not share it for advertising, and no one buys access to it. We would disclose data if the law required it, and we would tell you unless we were prohibited from doing so.
How long we keep it
- Account and licence records — for as long as you have an account, so a lapsed licence can be renewed without starting over.
- Sessions and device codes — until they expire, then they are cleared.
- Billing records — kept as long as tax and accounting rules require, which is longer than the licence itself.
Your rights
Email [email protected] and we will action any of these. There is no form and no ticket queue.
- A copy of everything we hold about you.
- Correction of anything that is wrong.
- Deletion of your account and its data. Billing records we are legally required to keep are the exception, and we will say so explicitly.
- Revoking our GitHub access, which you can also do yourself from GitHub's settings at any time.
Depending on where you live you may have further rights under the GDPR, the UK GDPR or the CCPA, including the right to complain to your data protection authority. We will honour a request under any of them.
Changes
If what we collect changes, this page changes with it and the date at the top moves. We will email account holders before a material change takes effect.
Contact
Privacy questions and requests go to [email protected], read by one person. More detail on the contact page.