Skip to content

Privacy Policy

Last updated

LGTM is a dashboard for reviewing GitHub pull requests. This policy explains what LGTM collects when you use looksgoodtome.dev and the LGTM GitHub App, why it needs that data, and how to have it removed. If you have a question, email [email protected].

What LGTM collects

Your GitHub account. When you sign in with GitHub, LGTM receives and keeps your GitHub user ID, username, name, email address and avatar. You sign in on GitHub, so LGTM never sees your GitHub password.

Repositories you install the LGTM app on. For each repository: its name, owner, description, homepage, main language, default branch and whether it's private. For each pull request:

  • its title, description, branch names, state and dates
  • the author, the people and teams asked to review it, and their review states
  • labels, milestone, and the number of comments, commits and changed lines
  • the names of changed files, with lines added and removed in each, which LGTM uses to score the pull request

LGTM does not keep file contents, diffs, or the text of comments and reviews.

What you add in LGTM. Team names, team members and their roles, starred repositories, and the email addresses you send team invitations to. LGTM also keeps a log of workspace and team changes, such as a member joining or a role changing, with who made the change.

Technical data. LGTM uses your IP address to limit repeated requests, such as sign-in attempts. It also records errors and request timings so problems can be found and fixed.

How LGTM uses it

Only to run the service: to show your pull request lists and dashboard, score pull requests, control who can see which repositories, send the invitations you ask it to send, and keep the service secure and working. LGTM doesn't sell your data, and doesn't use it for advertising.

Cookies

LGTM sets only the cookies it needs to work:

  • a session cookie and a remember-me cookie that keep you signed in
  • a security token that protects forms from being submitted by other sites
  • your light or dark mode choice, and whether the sidebar is open

There are no analytics or advertising cookies.

Services that help run LGTM

  • GitHub handles sign-in and is where all repository data comes from.
  • Laravel Cloud hosts the app, its database and its cache.
  • Laravel Nightwatch receives error reports and performance data.
  • SendLayer sends team invitations.
  • Bunny Fonts serves the fonts these pages use.

Keeping and deleting your data

LGTM keeps your data while you use it. You can delete your account in your profile settings. That deletes your user account and closes your personal workspace.

When you uninstall the LGTM app on GitHub, LGTM loses access to those repositories and stops syncing them. When a workspace is deleted, everyone loses access to it right away. To have a workspace's synced data erased as well, or to get a copy of your data, email [email protected].

Changes to this policy

When this policy changes, the date at the top of this page changes with it. Changes to how LGTM handles data are also listed in the changelog. The terms of service cover the rest of your use of LGTM.