Sourcery
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
“continue to improve the Sourcery product and offer better suggestions in the future. You can opt out of our collection of this data by disabling telemetry in your IDE settings.”
Watch: Privacy and data use
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Establishes procedural conditions under which Sourcery may verify identity before complying with data subject requests and carves out exceptions where full compliance may not be possible, such as when another person's data would be revealed or conflicting legal obligations exist.
This segment grants users explicit permission to use the Services for commercial purposes including resale and building competing goods, while imposing a restriction that prohibits using the Services to create products materially similar to or directly competitive with Sourcery's offerings.
Discloses that data may be stored on third-party infrastructure, affirms user retention of full rights to their data, and states that personal data is retained only as long as necessary for the purpose collected, establishing a data retention obligation and security obligation tied to third-party subprocessors.
Scores derived from 38 enriched findings — same verbatim citations as below. AI-generated, not legal advice.
- Sourcery's terms explicitly protect your inputs from training use — the policy is affirmatively favorable on this point.
- Your outputs and prompts are explicitly yours — Sourcery's terms include affirmatively protective IP language.
- Data handling is conditional — 4 privacy or retention clauses warrant review before using Sourcery at scale.
Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.
How to read this page: Overall risk rates what Sourcery's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredBased on 73 verified, verbatim-cited findings below — read the citations.
Based on 79 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Fully verified — complete core corpus captured and read in full.
- Privacy PolicyVerified - read in full - 39 citationsstaticLast captured 2026-07-29
- Terms of ServiceVerified - read in full - 19 citationsstaticLast captured 2026-06-08
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
This segment grants Free Tier users a limited, revocable, non-exclusive license to access the Application and explicitly vests ownership of input code, messages, and output code generated by Sourcery in the user, with Sourcery expressly disclaiming any IP claim to output from the Coding Assistant or Code Review, establishing user output ownership.
" Subject to these Terms, we grant to you a single limited, revocable, non-exclusive license to access the Application content, subject to the feature set described as available for the Free Tier of Sourcery, for the limited purpose of facil..."
This segment grants Pro Tier users a fixed number of paid, limited, revocable, non-exclusive licenses tied to the number of developers in the account, and explicitly vests ownership of input code, messages, and output code in the user, with Sourcery disclaiming any IP claim to generated output, establishing user output ownership for paid subscribers.
" Subject to these Terms, we grant to you a fixed number of limited, revocable, non-exclusive, paid license to access the Application content, subject to the feature set described as available for the Pro Tier of Sourcery, for the limited pu..."
Asserts that all LLM providers do not use code or messages to train their models and do not store data for more than 30 days; notes zero-retention options available for Pro license holders, imposing a contractual standard on subprocessors and creating a tiered access right for users.
"store any of your code. All LLM providers we work with do not use any of your code or messages to train their models and do not store any of your data for more than 30 days. Zero retention options are available as needed (provided by LLM pr..."
Describes the token-based authentication procedure for verifying account tier (Open Source, Pro, or Team) and explains the two-week verification cadence, defining tier-based feature access.
" You need to enter a token to verify that you have a Sourcery account with the right level of feature access (Open Source, Pro, or Team). You can get your token from your dashboard. Sourcery checks your token every 2 weeks, otherwise you ca..."
Provides a comprehensive 'as is, as available' warranty disclaimer, specifically disclaiming implied warranties of title, merchantability, non-infringement, and fitness for a particular purpose, placing all risk of use on the user.
" We provide the Application and Services “as is, as available”, without any warranty or condition of any kind (express, implied or statutory) and your access of the application and services is at your own risk. We do not warrant that the ap..."
Identifies Stripe as a payment subprocessor and restricts the information shared with Stripe to only what is necessary for invoice, payment, and subscription management, limiting permissible data disclosure.
" Sourcery uses payment services from Stripe to process payments for Sourcery Pro and Team services. No additional information is shared with Stripe outside of the information required to create and manage invoices, payments, and subscriptio..."
Discloses that GitHub/GitLab Code Review analysis uses third-party LLM providers, that LLM providers do not use data for training and retain data no more than 30 days, and that zero-retention options (via Anthropic) are available for Pro license holders — establishing subprocessor training restrictions and tier-based retention rights.
" For GitHub Cloud, GitLab Cloud, & GitLab self hosted Code Review our analyis is conducted on our servers and using third-party Large Language Model (LLM) providers (such as OpenAI, Anthropic, etc) using their APIs. This data passes through..."
Clause A implies user code content is not collected or sent to third-party LLMs, while Clause B explicitly states that 'code context' is sent to these models for functionality.
" We will only collect information surrounding usage and errors and messages you send to the Coding Assistant but will not collect content of your code. We collect the messages you send to the Coding Assistant to help us improve the quality of responses we can provide you with. You can opt out of us collecting this information by disabling telemetry in your IDE, however, in order to use the Coding Assistant you must opt into this information being sent to third party Large Language Model providers. Full details are available in our Privacy Policy."
" The Sourcery Coding Assistant is our AI powered pair programmer which looks to assist you with tasks such as code reviews, troubleshooting code problems, generating docstrings or test, explaining code, etc. The Sourcery Coding Assistant uses third party Large Language Models to provide its functionality and requires us to be able to send messages and code context to those models to function. We collect message data (but not your code) to allow us to improve the quality of our responses."
Across documentsClause A explicitly states that the content of user code will not be collected, while Clause B states that code sections are sent to third-party Large Language Model providers.
" We will only collect information surrounding usage and errors and messages you send to the Coding Assistant but will not collect content of your code. We collect the messages you send to the Coding Assistant to help us improve the quality of responses we can provide you with. You can opt out of us collecting this information by disabling telemetry in your IDE, however, in order to use the Coding Assistant you must opt into this information being sent to third party Large Language Model providers. Full details are available in our Privacy Policy."
" For the Sourcery Coding Assistant code sections and messages are sent to third-party Large Language Model (LLM) providers (such as OpenAI, Anthropic,"
Across documents
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" Depending on the circumstances, we may need to verify your identity before complying with your request and we may not always be able to comply with your request in full (for example when producing your information may reveal another person’s personal data or when there is an overriding interest or conflicting legal obligation)."
Establishes procedural conditions under which Sourcery may verify identity before complying with data subject requests and carves out exceptions where full compliance may not be possible, such as when another person's data would be revealed or conflicting legal obligations exist.
AI-generated interpretation, not legal advice.
" You are fully permitted to use our Application and Services for commercial purposes as a means to resell or build goods and services which you offer commercially, except for the case in which your product is materially similar or aims to compete with the Services offered by Sourcery."
This segment grants users explicit permission to use the Services for commercial purposes including resale and building competing goods, while imposing a restriction that prohibits using the Services to create products materially similar to or directly competitive with Sourcery's offerings.
AI-generated interpretation, not legal advice.
" Although most changes are likely to be minor, Sourcery may change its Privacy Policy from time to time, and in Sourcery’s sole discretion. Sourcery encourages visitors to frequently check this page for any changes to its Privacy Policy. Your continued use of this site after any change in this Privacy Policy will constitute your acceptance of such change."
Establishes Sourcery's unilateral right to amend the Privacy Policy at its sole discretion and deems continued use of the service after changes as acceptance, defining the procedure for policy updates and the mechanism by which user consent to changes is implied.
AI-generated interpretation, not legal advice.
" While we strive for accuracy from our code reviews we cannot guarantee the validity of their results. It is the responsiblity of the end user to review any Sourcery suggestions or approval decisions and decide whether they make sense for their project."
Disclaims any guarantee of validity for code review results and places responsibility on the end user to evaluate Sourcery's suggestions or approval decisions, limiting the platform's liability for output quality.
AI-generated interpretation, not legal advice.
" The Sourcery Coding Assistant is our AI powered pair programmer which looks to assist you with tasks such as code reviews, troubleshooting code problems, generating docstrings or test, explaining code, etc. The Sourcery Coding Assistant uses third party Large Language Models to provide its functionality and requires us to be able to send messages and code context to those models to function. We collect message data (but not your code) to allow us to improve the quality of our responses."
Defines the Sourcery Coding Assistant product and discloses that it sends messages and code context to third-party LLMs, and that Sourcery collects message data (but not code) to improve response quality — establishing the training/use basis for collected data.
AI-generated interpretation, not legal advice.
" We will only collect information surrounding usage and errors and messages you send to the Coding Assistant but will not collect content of your code. We collect the messages you send to the Coding Assistant to help us improve the quality of responses we can provide you with. You can opt out of us collecting this information by disabling telemetry in your IDE, however, in order to use the Coding Assistant you must opt into this information being sent to third party Large Language Model providers. Full details are available in our Privacy Policy."
This segment specifies the scope of data collection (usage, errors, and Coding Assistant messages but not code content), grants an opt-out mechanism for telemetry, but imposes an obligation that use of the Coding Assistant requires consent to data sharing with third-party LLM providers, making such sharing a condition of service access and implicating subprocessor data sharing.
AI-generated interpretation, not legal advice.
"continue to improve the Sourcery product and offer better suggestions in the future. You can opt out of our collection of this data by disabling telemetry in your IDE settings."
Grants users the right to opt out of usage data collection by disabling telemetry in IDE settings, establishing a user right to limit data collection.
AI-generated interpretation, not legal advice.
" Sourcery collects information to provide a better service to all our users and visitors. We use the information to provide, maintain, protect and improve our website and services. If you have signed up to receive updates from us we will use your information to periodically contact you with information about our products and services. Our legal basis for processing the information we are the data controller for, is the implicit consent that you provide when submitting your information through a website form or emailing us. In some circumstances, we may also process information on the basis of our legitimate interest in improving our service."
Establishes the legal basis (implicit consent) for Sourcery's processing of personal data and enumerates the purposes for which user information is collected and used, creating an obligation to process data only on stated grounds.
AI-generated interpretation, not legal advice.
" We retain the right to cancel and terminate the account of any user who is violating these Terms or is in any way using the Sourcery service for any illegal activities or is attempting to reverse engineer any of the Sourcery Products or Services."
This segment reserves to Sourcery the right to cancel and terminate accounts of users who violate the Terms, engage in illegal activities, or attempt to reverse engineer Sourcery's products, establishing enforceable grounds for platform-level account termination.
AI-generated interpretation, not legal advice.
" Sourcery uses third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to run the Service. You understand that although you retain full rights to your data, it may be stored on third-party storage and transmitted through third-party networks. We take careful technical measures to ensure that your information is secure and inaccessible to unauthorized parties. We also continuously work on new features to improve security. We retain personal data for as long as necessary for the purpose for which the personal data was collected, or for such longer period required by law or otherwise necessary to defend or exercise our legal rights. At the end of this period (or expiry of our backup archive retention period if later), we will either delete or anonymise the personal data."
Discloses that data may be stored on third-party infrastructure, affirms user retention of full rights to their data, and states that personal data is retained only as long as necessary for the purpose collected, establishing a data retention obligation and security obligation tied to third-party subprocessors.
AI-generated interpretation, not legal advice.
" You may be provided links to other websites or resources through the Services. Because we have no control over such sites and resources, you acknowledge and agree that we are not responsible for the availability of such external sites or resources, and do not endorse and are not responsible or liable for any content, advertising, products or other materials on or available from such sites or resources. You further acknowledge and agree that we shall not be responsible or liable, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of, or reliance upon, any such content, goods or services available on or through any such site or resource."
Disclaims responsibility and liability for third-party websites or resources linked through the Services, including their content, availability, and any damage or loss arising from their use, requiring user acknowledgment of this limitation.
AI-generated interpretation, not legal advice.
" We have no special relationship with or fiduciary duty to you. You acknowledge that we have no control over, and no duty to take any action regarding:"
This segment disclaims any special relationship or fiduciary duty between Sourcery and the user, and begins enumerating matters over which Sourcery has no control or duty to act, limiting Sourcery's legal obligations and potential liability to users.
AI-generated interpretation, not legal advice.
" We provide the Application and Services “as is, as available”, without any warranty or condition of any kind (express, implied or statutory) and your access of the application and services is at your own risk. We do not warrant that the application will meet your requirements or result in any particular outcome, or that the operation will be uninterrupted or error-free. To the fullest extent allowed by law, we specifically disclaim any implied warranties of titles, merchantability, non infringement and fitness for a particular purpose, some states do not allow the disclaimer of implied warranties, so the foregoing disclaimer may not apply to you."
Provides a comprehensive 'as is, as available' warranty disclaimer, specifically disclaiming implied warranties of title, merchantability, non-infringement, and fitness for a particular purpose, placing all risk of use on the user.
AI-generated interpretation, not legal advice.
" You agree to indemnify and hold us, our subsidiaries, affiliates, officers, agents, and other partners and employees, harmless from any loss, liability, claim, or demand, including reasonable attorney’s fees, made by any third party due to or arising out of your use of the Services in violation of these Terms and/or arising from a breach of these Terms and/or any breach of your representations and warranties set forth above."
Imposes an obligation on the user to indemnify and hold harmless the company, its affiliates, officers, agents, and employees from third-party claims, losses, liabilities, and reasonable attorney's fees arising from the user's violation of or breach of these Terms.
AI-generated interpretation, not legal advice.
" Sourcery Code Review is our GitHub and GitLab integration to provide automatic code review on every pull request or merge request you make. Sourcery Code Review uses third party Large Language Models to provide its functionality and requires us to be able to send messages and code context to those models to function."
Defines Sourcery Code Review and discloses that it sends messages and code context to third-party LLM providers, identifying subprocessors involved in data processing.
AI-generated interpretation, not legal advice.
" For the Sourcery Coding Assistant code sections and messages are sent to third-party Large Language Model (LLM) providers (such as OpenAI, Anthropic,"
Discloses that code sections and messages from the Coding Assistant are sent to third-party LLM providers (OpenAI, Anthropic, etc.) via their APIs, identifying subprocessors who receive user data.
AI-generated interpretation, not legal advice.
" You acknowledge and agree that we have the right to disclose information your provide, if required to do so by law at the request of a third party, or if we, in our sole discretion, believe that such disclosure is: 1) reasonable to comply with the law, request or orders from law enforcement, or any legal process (whether or not such disclosure is required by applicable law); 2) protect or defend our, or a third party’s, rights or property; or 3) protect someone’s health or safety"
This segment grants Sourcery the right to disclose user-provided information to third parties in specified circumstances including legal compulsion, law enforcement requests, protection of rights or property, and health or safety concerns, limiting any confidentiality expectation users might have.
AI-generated interpretation, not legal advice.
" These Terms are ruled by the law of the United Kingdom. In case of a dispute arrisingout of the Services, by using the Services you expressly agree that any such dispute shall be litigated in London."
Establishes United Kingdom law as governing law and obligates users to litigate any disputes arising from the Services exclusively in London, constituting a mandatory forum selection clause.
AI-generated interpretation, not legal advice.
Common questions about Sourcery's policies
- Does Sourcery train its AI models on your data?
- Training possible — conditions or opt-outs apply — based on 3 verified findings from Sourcery's published policy. Informational only, not legal advice.
- Who owns the content you create with Sourcery?
- You own your outputs — based on 2 verified findings from Sourcery's published policy. Informational only, not legal advice.
- Can you use Sourcery's output commercially?
- Commercial use allowed — with conditions — based on 1 verified finding from Sourcery's published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Sourcery's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
23 verified clausesClauses in Sourcery's policies that work in your favour — commitments the platform made to you.
- Subprocessors & data sharingdata shared with other AI providers
“For GitHub Cloud, GitLab Cloud, & GitLab self hosted Code Review our analyis is conducted on our servers and using third-party Large Language Model (LLM) providers (such as OpenAI, Anthropic, etc) using their APIs. This data passes through our servers but we d…”
Discloses that GitHub/GitLab Code Review analysis uses third-party LLM providers, that LLM providers do not use data for training and retain data no more than 30 days, and that zero-retention options (via Anthropic) are…
📍 Privacy Policy › “In GitHub”Jump to exact text → - Output ownership
“Subject to these Terms, we grant to you a fixed number of limited, revocable, non-exclusive, paid license to access the Application content, subject to the feature set described as available for the Pro Tier of Sourcery, for the limited purpose of facilitating…”
This segment grants Pro Tier users a fixed number of paid, limited, revocable, non-exclusive licenses tied to the number of developers in the account, and explicitly vests ownership of input code, messages, and output co…
📍 § 4.3 (Use License - Pro Usage)Jump to exact text → - Output ownership
“Subject to these Terms, we grant to you a single limited, revocable, non-exclusive license to access the Application content, subject to the feature set described as available for the Free Tier of Sourcery, for the limited purpose of facilitating your use of t…”
This segment grants Free Tier users a limited, revocable, non-exclusive license to access the Application and explicitly vests ownership of input code, messages, and output code generated by Sourcery in the user, with So…
📍 § 4.2 (Use License - Free Usage)Jump to exact text → - Indemnity & liability
“infringe, (ii) code suggestions were modified, transformed, or used in combination with products or services not provided by Sourcery, (iii) users did not have the right to use the input code to generate the allegedly infringing code suggestions, (iv) the clai…”
Continues listing exceptions to Sourcery's IP indemnity obligation, excluding coverage for modified or combined code, unauthorized input code, and trademark-related claims arising from use of code in trade or commerce.
📍 § 9.2 (IP Indemnity)Jump to exact text → - Model trainingdoes-not-train
“store any of your code. All LLM providers we work with do not use any of your code or messages to train their models and do not store any of your data for more than 30 days. Zero retention options are available as needed (provided by LLM providers). These requ…”
Asserts that all LLM providers do not use code or messages to train their models and do not store data for more than 30 days; notes zero-retention options available for Pro license holders, imposing a contractual standar…
- Designated security contact: teams@sourcery.ai
📍 Privacy Policy › “In your IDE & with the Sourcery CLI”Jump to exact text → - Prompt ownership
“No code will ever be sent off of your device unless you trigger a Sourcery interaction such as messaging through the Sourcery chat, choosing a recipe such as Generate Tests, or triggering a code review. Applying the in-line suggestions does not result in any L…”
Restricts when code is transmitted off the user's device to only Sourcery-triggered interactions, and confirms that applying inline suggestions does not send code — limiting the scope of data collection.
📍 Privacy Policy › “In your IDE & with the Sourcery CLI”Jump to exact text →
+ 17 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
1 verified clauseWhat Sourcery requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
- Prompt ownership
“We and our licensors own and retain all proprietary rights in the Services. The Services may contain the copyrighted material, trademarks, and other proprietary information of us and our licensors (the “Code”). Except for code that is in the public domain or f…”
This segment asserts that Sourcery and its licensors retain all proprietary rights in the Services and the Code contained therein, and restricts users from copying, modifying, publishing, transmitting, distributing, perf…
📍 § 4.1 (Ownership)Jump to exact text →
What the policies actually cover
12 topics- Product telemetry & usage tracking1 protective4 clauses
- Advertising & tracking2 clauses
- Children's data1 clause
- Government & law-enforcement disclosure1 clause
- Data shared with other AI providers2 protective6 clauses
- Does not train on your content2 protective2 clauses
- Trains by default, opt-out available1 clause
- Damages & liability cap4 clauses
- Indemnity direction1 protective2 clauses
- Terms can change at any time1 clause
- Deletion rights & post-termination survival2 protective2 clauses
- Conduct restrictions1 clause
31 further verified clauses are cited on this page but not yet assigned a topic.
Cross-clause notes
Two verified clauses intersect on the same subject matter: the Privacy Policy, Privacy Policy › “Storage and security” addresses how long content is retained, and the Privacy Policy, Privacy Policy › “In your IDE & with the Sourcery CLI” addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause allows indefinite, perpetual, or necessity-based retention.
“Sourcery uses third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to run the Service. You understand that although you retain full rights to your data, it may be stored on third-party storage and transmitted through third-party networks. We take careful technical measures to ensure that your information is secure and inaccessibl...”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“Sourcery uses third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to run the Service. You understand that although you retain full rights to your data, it may be stored on third-party storage and transmitted through third-party networks. We take careful technical measures to ensure that your information is secure and inaccessibl...”Open source citation
The clause allows indefinite, perpetual, or necessity-based retention.
“Sourcery uses third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to run the Service. You understand that although you retain full rights to your data, it may be stored on third-party storage and transmitted through third-party networks. We take careful technical measures to ensure that your information is secure and inaccessibl...”Open source citation
The clause grants a broad content license.
“Subject to these Terms, we grant to you a fixed number of limited, revocable, non-exclusive, paid license to access the Application content, subject to the feature set described as available for the Pro Tier of Sourcery, for the limited purpose of facilitating your use of the Services. The number of licenses is equal to the number of developers paid for within your account. Your input code and messages and any out...”Open source citation
The clause grants a broad content license.
“Subject to these Terms, we grant to you a single limited, revocable, non-exclusive license to access the Application content, subject to the feature set described as available for the Free Tier of Sourcery, for the limited purpose of facilitating your use of the Services. Your input code and messages and any output code generated by Sourcery remain your IP. Sourcery does not have a claim to any of the output code ...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | confidentiality | conditional | MEDIUM | 1 |
| All applicable tiers | data retention | conditional | MEDIUM | 11 |
| All applicable tiers | moderation enforcement | worsens | HIGH | 2 |
| All applicable tiers | privacy data use | conditional | MEDIUM | 1 |
| All applicable tiers | subprocessors data sharing | conditional | MEDIUM | 4 |
| Free | indemnity liability | conditional | MEDIUM | 1 |
| Free | output ownership | conditional | MEDIUM | 1 |
| Free | prompt ownership | conditional | MEDIUM | 1 |
| Pro / Paid | output ownership | conditional | MEDIUM | 1 |
| Pro / Paid | prompt ownership | conditional | MEDIUM | 1 |
| Pro / Paid | tier differences | conditional | MEDIUM | 1 |
| Pro / Paid | training use | improves | LOW | 6 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: no training claim on training use
“For the Sourcery Coding Assistant code sections and messages are sent to third-party Large Language Model (LLM) providers (Microsoft Azure OpenAI, Anthropic, and OpenAI) using their APIs. This data passes through our servers but we do not store any of your code. All LLM providers we work with do not use any of your code or messages to train their models and do not store any of your data for more than 30 days. Zero retention options are available as needed (provided by LLM providers). These require a Sourcery Pro license and can be requested by contacting teams@sourcery.ai .”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“We do not share the information with any external third parties, except as detailed in this document.”Open timeline citation
Latest stance: user retains rights on data retention
“Sourcery uses third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to run the Service. You understand that although you retain full rights to your data, it may be stored on third-party storage and transmitted through third-party networks. We take careful technical measures to ensure that your information is secure and inaccessible to unauthorized parties. We also continuously work on new features to improve security. We retain personal data for as long as necessary for the purpose for which the personal data was collected, or for such longer period required by law or otherwise necessary to defend or exercise our legal rights. At the end of this period (or expiry of our backup archive retention period if later), we will either delete or anonymise the personal data.”Open timeline citation
Latest stance: platform claims or reserves rights on data retention
“Sourcery uses third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to run the Service. You understand that although you retain full rights to your data, it may be stored on third-party storage and transmitted through third-party networks. We take careful technical measures to ensure that your information is secure and inaccessible to unauthorized parties. We also continuously work on new features to improve security. We retain personal data for as long as necessary for the purpose for which the personal data was collected, or for such longer period required by law or otherwise necessary to defend or exercise our legal rights. At the end of this period (or expiry of our backup archive retention period if later), we will either delete or anonymise the personal data.”Open timeline citation
Latest stance: indefinite or necessity based on data retention
“Sourcery uses third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to run the Service. You understand that although you retain full rights to your data, it may be stored on third-party storage and transmitted through third-party networks. We take careful technical measures to ensure that your information is secure and inaccessible to unauthorized parties. We also continuously work on new features to improve security. We retain personal data for as long as necessary for the purpose for which the personal data was collected, or for such longer period required by law or otherwise necessary to defend or exercise our legal rights. At the end of this period (or expiry of our backup archive retention period if later), we will either delete or anonymise the personal data.”Open timeline citation
Latest stance: no training claim on training use
“For GitHub Cloud, GitLab Cloud, & GitLab self hosted Code Review our analysis is conducted on our servers and using third-party Large Language Model (LLM) providers (Microsoft Azure OpenAI, Anthropic, and OpenAI) using their APIs. This data passes through our servers but we do not store any of your code. All LLM providers we work with do not use any of your code or messages to train their models and do not store any of your data for more than 30 days. Zero retention options are available as needed (provided via Anthropic). These require a Sourcery Pro license and can be requested by contacting teams@sourcery.ai .”Open timeline citation
Latest stance: user retains rights on data retention
“Sourcery uses third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to run the Service. You understand that although you retain full rights to your data, it may be stored on third-party storage and transmitted through third-party networks. We take careful technical measures to ensure that your information is secure and inaccessible to unauthorized parties. We also continuously work on new features to improve security. We retain personal data for as long as necessary for the purpose for which the personal data was collected, or for such longer period required by law or otherwise necessary to defend or exercise our legal rights. At the end of this period (or expiry of our backup archive retention period if later), we will either delete or anonymise the personal data.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“We do not share the information with any external third parties, except as detailed in this document.”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-29· verified 2026-07-29
- Terms of Service:Last captured 2026-06-08· verified 2026-06-08verified once — no re-scan in 94 days
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↑ 68 more findings this quarter vs last (135 vs 67). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Sourcery's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Every finding above is a verbatim quote from Sourcery's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.