abloh
How it worksPricingDocs
Sign up

Privacy Policy

Contents
  1. 1 · Introduction
  2. 2 · Data we process as a processor: runs on your repositories
  3. 3 · Data we process as a controller: accounts and the Site
  4. 4 · Purposes and legal bases
  5. 5 · AI features and model training
  6. 6 · Disclosures
  7. 7 · International transfers
  8. 8 · Retention
  9. 9 · Security
  10. 10 · Your rights
  11. 11 · US residents
  12. 12 · Cookies, children and changes

1 · Introduction

This Policy is issued by Alexandria Limited, a private limited company incorporated in England and Wales (company number 17019665), trading as “Abloh”. It describes how we process personal data in connection with the website at abloh.dev (the “Site”), the Abloh GitHub App and the associated dashboards, reports and release certificates (the “Service”), and our related business operations. Enquiries should be directed to info@alexandrialabs.uk.

2 · Data we process as a processor: runs on your repositories

Where the Abloh GitHub App is installed on a repository and a run executes, we process the following on the documented instructions of the customer:

Run execution Test execution, coverage instrumentation and mutation analysis run in your own CI environment or on your own machine. Abloh orchestrates each run through the GitHub App and receives the results. We do not clone repositories to our infrastructure and do not hold source code at rest.

Evidence Test results, diff coverage, mutation outcomes, catch rates, timings, findings, suggested tests and release certificates. Depending on the evidence tier your administrators configure, findings may include short excerpts of affected code; on Tier 1, only structural data leaves your environment and exact diffs remain in the protected CI artifact.

Triage context Short source context for surviving mutants is transmitted over encrypted connections to our fine-tuned model endpoint, hosted on Microsoft Azure, solely to produce triage verdicts and suggested tests. It is not used to train models.

Commit & PR metadata Commit hashes, branch and pull request identifiers, commit messages, and author names and email addresses as recorded in Git history.

Ticket metadata Where an issue tracker is connected: ticket identifiers, titles and status, used for ticket matching.

Approval records Where your team records approvals or risk acceptances on a certificate: the approver’s name, work email address, role, decision and timestamp.

For all of the above, the customer that installed Abloh is the controller and we act as its processor under our Data Processing Agreement. Individuals whose personal data appears in a customer’s repositories, approvals or certificates should direct privacy requests to that customer first; we assist the customer in responding.

3 · Data we process as a controller: accounts and the Site

Account data — name, email address, GitHub username and organisation, plan and settings. Billing data — payments are processed by Stripe; we receive limited billing metadata (plan, invoice status, last four digits of the card) and never store full card numbers. Usage and log data — pages viewed, features used, IP address, browser and device information, and service logs used for security and debugging. Communications — messages sent to support, sales or email. Marketing data — email address and preferences, where you opt in to product updates.

4 · Purposes and legal bases

We process personal data under the UK GDPR and, where applicable, the EU GDPR on the following bases:

Purpose Legal basis (Art. 6 UK GDPR)

Providing the Service — executing runs, producing reports and certificates, managing accounts and billing Performance of a contract — 6(1)(b)

Securing and improving the Service, preventing abuse, aggregate usage analysis, reasonable business communications Legitimate interests — 6(1)(f)

Marketing communications and non-essential cookies, where consent is required Consent — 6(1)(a), withdrawable at any time

Retaining records we must keep, including tax and accounting records Legal obligation — 6(1)(c)

5 · AI features and model training

Abloh uses a fine-tuned model to triage mutation results and to propose faults and tests. The only customer content transmitted to the model is the triage context described in section 2, sent to our model endpoint on Microsoft Azure. We do not use customer code, evidence data or any other customer content to train or fine-tune models, and our model hosting provider is contractually prohibited from doing so.

6 · Disclosures

We disclose personal data to subprocessors that host and support the Service (current list at abloh.dev/subprocessors); to professional advisers where necessary; to competent authorities where required by law; and to a purchaser or successor in a merger, acquisition or sale of assets, in which case this Policy continues to apply. We do not sell personal data and we do not share it for third-party advertising.

Subprocessor Function

Amazon Web Services Application hosting, database and evidence store

Microsoft Azure Model inference

GitHub App platform, check runs and pull request comments

Stripe Payment processing

PostHog Product analytics

7 · International transfers

We are established in the United Kingdom and use service providers in the UK, the EEA and the United States. Where personal data leaves the UK or EEA we rely on adequacy regulations or appropriate safeguards, including the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses.

8 · Retention

Category Retention period

Customer repository contents Not stored by Abloh

Evidence, reports and certificates Life of the account, or until deleted by an administrator

Account data Duration of the account, then deleted or anonymised within 30 days of closure unless longer retention is required

Service logs 90 days

Billing and tax records Up to 7 years, as required by law

9 · Security

We protect personal data through encryption in transit and at rest, least-privilege access controls, signed evidence attestations, and logging and monitoring. Because runs execute in your own environment, your code remains within your infrastructure. No system is perfectly secure; if a breach affects personal data, we will notify affected individuals and the relevant regulators as required by law.

10 · Your rights

Depending on your location, you may have rights to access, correct, delete or receive a copy of your personal data, to restrict or object to our processing, and to withdraw consent — exercisable by email to info@alexandrialabs.uk (we may need to verify identity first). You may also complain to a supervisory authority: in the UK, the Information Commissioner’s Office (ico.org.uk); in the EEA, your local data protection authority. Where your personal data appears in a customer’s repositories, approvals or certificates, that customer is the controller — we will refer requests to them and assist as processor.

11 · US residents

We do not sell personal information and do not share it for cross-context behavioural advertising. Depending on your state of residence, rights to know, correct, delete and port personal information may apply, exercisable by email to info@alexandrialabs.uk. We will not discriminate against you for exercising these rights.

12 · Cookies, children and changes

We use essential cookies to operate the Site and, with consent where required, PostHog analytics to understand usage — details in our Cookie Policy at abloh.dev/cookies. The Service is a business tool and is not directed at children under 16; if you believe a child has provided us personal data, contact us and we will delete it. We may update this Policy from time to time: changes are posted here with an updated effective date, and material changes are notified by email or in-product.

This Policy is governed by the laws of England and Wales, without prejudice to mandatory rights under applicable data protection law. Contact: Alexandria Limited (trading as Abloh) · info@alexandrialabs.uk

abloh Docs Privacy Terms © 2026 Abloh

abloh
DocsPrivacyTermsCookies© 2026 abloh