RepoQL Privacy Policy

Effective date: 11 September 2026

Last updated: 11 September 2026

RepoQL is operated by Clanker Gear Limited, a New Zealand company ("RepoQL", "we", "us" or "our"). This policy explains how we handle personal information through our websites, software, cloud services and related communications.

Address: 156 Stredwick Drive, Torbay, Auckland 0630, New Zealand

Privacy contact: [email protected]

1. Scope and responsibility

Personal information is information about an identifiable individual. This may include account details, online identifiers and information contained in repository material, queries or messages submitted through RepoQL. Hashing or converting information to an embedding does not necessarily make it anonymous.

We handle account, billing and service-administration information for the purposes described here. Where we process information solely on behalf of a customer organisation, the applicable customer agreement also governs that processing. Your organisation may have its own privacy notice and control your access to RepoQL.

Independently supplied agents and other services you connect have their own privacy arrangements. This policy does not govern their independent processing. Service eligibility restrictions do not limit privacy rights that apply to information we hold.

2. Local operation and cloud processing

Your local repositories and index remain on the infrastructure where you run RepoQL. Local processing does not itself give us access to them. When you are signed out, the software does not send us repository content or tool-usage telemetry. Download and update requests expose normal connection information, including IP addresses and request details.

When you use cloud features, we process the information needed to provide them. This includes repository text and queries for embeddings and reranking, prompts and relevant context for inference, and requests and results relayed through Uplink. Relevant inputs are shared with the providers described in section 7.

Cloud request payloads are processed for the request and then discarded. We do not retain copies of those payloads in application storage or logs. We use our embedding, reranking and inference providers under zero-retention, no-training configurations.

Embeddings, telemetry, error messages and feedback are separate retained records, as described below. They can contain or be derived from material supplied through RepoQL.

We do not use your data to train AI models, and require providers receiving that data from us not to use it for model training. This commitment does not govern providers you independently engage.

3. Information we collect and retain

Signed-in tool-usage telemetry is collected unless you opt out. Recorded parameters and error messages can contain code, credentials, personal information or other confidential material supplied by you or your agent. Telemetry does not separately attach repository files, your index or returned tool results. Disabling parameter collection does not remove information echoed in error messages.

Cached results may serve matching requests from different customers using the same source identity and content-derived cache keys. We treat content-derived cached embeddings as confidential and provide deletion on an authorised request as described in section 11. Any stricter restrictions in an applicable DPA continue to apply.

Your organisation can view activity recorded through its Uplink access. Feedback submissions include host diagnostics concerning performance, memory and index statistics, without attaching file contents. Feedback messages may contain anything you choose to include and also appear in operational logs.

4. Sources and purposes

We receive information from you, the software and browser you use, organisations administering your access, and providers involved in sign-in, payments and integrations you enable. Repository material and other submissions can include information about other people. We provide any notice required when collecting information indirectly, subject to applicable exceptions.

We use this information to:

You may choose not to provide information. If it is needed for an account, payment or requested feature, we may be unable to provide that service. Optional telemetry controls are described below. We obtain consent or provide additional notices where required by applicable law.

5. Your choices about the software

You can disable tool-usage telemetry or disable collection of parameter values through RepoQL's telemetry controls. Instructions are available in our Your data disclosure. Disabling parameter values leaves other telemetry, including error messages, enabled.

These controls do not disable records needed to operate cloud features and billing, Uplink audit records, update requests, feedback you submit, or website analytics. They do not delete information already received. You can avoid cloud-feature processing by not using those features and choose whether to submit feedback.

6. Websites, cookies and session replay

We use cookies and similar technologies to operate our websites and portal, support sign-in, understand usage and improve performance. Blocking functional cookies may prevent some features from working.

We use third-party analytics and session replay services to understand usage and diagnose problems. These services collect usage and performance information, device and browser details, and connection information such as IP addresses. Session replay can capture displayed page content and interactions to reconstruct a visit. For signed-in portal users, we associate this information with account and organisation information, including email address and role. Our providers are described in section 7.

You can manage cookies through your browser. Cookie controls may affect functionality and do not necessarily prevent all analytics collection. The software telemetry controls in section 5 do not control website analytics.

Our website analytics do not automatically switch off in response to browser Do Not Track or Global Privacy Control signals. To exercise privacy rights that apply to your information, contact [email protected]. This does not limit rights or obligations under applicable law.

7. Recipients of information

We share information with providers that support the following functions:

A provider's role and obligations depend on the service and applicable arrangements. Your organisation and its authorised administrators also receive membership, access and activity information relevant to the services they administer.

We may disclose relevant information to professional advisers under confidentiality obligations, in connection with a business sale or reorganisation subject to applicable privacy protections, or where required or permitted by law to meet a specific obligation, resolve a dispute or protect rights and safety. We may also disclose information at your direction or with any consent required by law.

8. Overseas processing

We are based in New Zealand and use infrastructure and providers outside New Zealand, including in the United States. Information may be processed in countries where those providers operate.

Where an overseas disclosure requires comparable safeguards or another legal basis, we comply with the applicable requirements. We remain responsible for our obligations when using providers to process information on our behalf. Contact [email protected] for information about arrangements relevant to your use.

9. Retention

We retain personal information only for as long as needed for the purposes described in this policy or another lawful purpose.

The telemetry periods do not apply to other categories. Cancelling a subscription or changing telemetry settings does not itself delete existing records. Retained information remains protected. You control the retention of information held only on your infrastructure.

10. Security

We take reasonable security safeguards appropriate to the information and risks involved. No security measure eliminates every risk. You are responsible for the security, credentials and access settings of infrastructure you operate.

We notify affected people, customer organisations and authorities of privacy breaches as required by applicable law and our agreements.

11. Access, correction, deletion and complaints

Contact [email protected] to request access to or correction of personal information, request deletion, or raise a concern. We may require proportionate verification of your identity and authority.

For access and correction requests under New Zealand law, we communicate our decision as soon as reasonably practicable and normally within 20 working days, subject to permitted extensions notified to you. Information we agree to provide is supplied without undue delay. If we decline a correction, you may ask us to attach a statement of the correction sought. We explain refusals and complaint rights as required by law.

We delete cached embeddings derived from repositories you control on request, after verifying your authority and locating the relevant entries, except where retention is required by law. Requests concerning other records are assessed against applicable rights, retention requirements and agreements. We cannot delete information held only on your infrastructure.

Where your organisation controls the relevant processing, we may coordinate with it or direct the relevant part of your request to it, while meeting our own obligations.

You may complain to the New Zealand Office of the Privacy Commissioner or another regulator with jurisdiction.

12. Additional privacy rights

Depending on the law that applies, you may have additional rights to obtain a copy of information, correct or delete it, restrict or object to processing, withdraw consent or opt out of particular uses or disclosures. Where applicable, you may use an authorised agent or appeal our decision. Contact [email protected] with your request or appeal. We apply the relevant deadlines, verification requirements and exceptions and do not unlawfully discriminate against people exercising privacy rights.

The information categories described above include identifiers, commercial information, internet and device activity, and submitted content. Submitted content may include sensitive personal information. Sources, purposes, recipients and retention are described in sections 3–9.

13. Children

RepoQL is a developer tool and is not directed at children. Contact [email protected] if you believe a child has supplied information in circumstances requiring protection that has not been provided. We take action required by applicable law.

14. Changes to this policy

We may update this policy and its date. We notify you of material changes through a website or account notice, or by email, before the change takes effect where required by law. We obtain consent where required. An update does not reduce mandatory rights or override an applicable customer agreement.

Contact [email protected], or write to Clanker Gear Limited at the address above, with questions about this policy.

Download this document (Markdown)