Privacy Policy

Last updated July 18, 2026

This page explains what Fragments collects, why we collect it, who processes it, and the choices you have. The short version: we store the governance results you ask us to produce, not a copy of your codebase, and we never sell your data.

1. What we collect

Account data: your name, email address, and organization membership, handled by our authentication provider (Clerk).

Repository data: when you connect a repository, we read the content needed to verify governance results and store findings, component and token metadata, contract definitions, and scan summaries. CI reports can contain offending literals and structured source-derived facts, but they do not upload whole files, whole source lines, or function bodies.

Usage and diagnostics: product analytics on our marketing pages, and error reports (Sentry) that help us fix failures.

Waitlist and updates: if you give us your email for product updates we store it with your submission details.

2. What we use it for

To run the service you asked for: scanning repositories, reporting findings, creating the check runs and pull-request comments you configure, and serving your design-system data to the tools you connect.

To operate the business: billing through Stripe, transactional email through Resend, support, and security.

We do not sell personal data, and we do not use your code to train machine-learning models.

3. Who processes it

We use a small set of processors to run the service: Clerk (authentication), Convex (data storage and functions), GitHub (repository access via the GitHub App you install), Stripe (payments), Sentry (error reporting), Resend (email), and our hosting providers. Each receives only what its role requires.

4. Retention and deletion

We keep data while your account is active. Disconnecting a repository stops new collection for it, and deleting your account removes your stored account and repository data from the live service within a reasonable period, after which it also ages out of backups.

You can request access to, correction of, or deletion of your personal data at any time by emailing hello@usefragments.com.

5. Cookies

The sites use cookies needed for sign-in and session state. Marketing analytics are kept minimal; we do not run third-party advertising trackers.

6. International transfers and legal bases

We operate from the United Kingdom and use processors in other countries, relying on standard contractual protections for transfers. Where UK and EU data-protection law applies, we process personal data to perform our contract with you, to meet legal obligations, and for legitimate interests such as securing the service.

7. Changes

If this policy changes materially we will update this page and its date. Continued use of the service after a change means the new policy applies.

Questions about this document: hello@usefragments.com