Privacy Policy
1 · Introduction
This Policy is issued by Alexandria Limited, a private limited company incorporated in England and Wales (company number 17019665), trading as “Abloh”. It describes how we process personal data in connection with the website at abloh.dev (the “Site”), the Abloh GitHub App and the associated dashboards, reports and release certificates (the “Service”), and our related business operations. Enquiries should be directed to info@alexandrialabs.uk.
2 · Data we process as a processor: runs on your repositories
Where the Abloh GitHub App is installed on a repository and a run executes, we process the following on the documented instructions of the customer:
Run execution On a pull request, and on a run you start on your own machine, test execution, coverage instrumentation and mutation analysis run entirely in your own CI environment or on your own machine. Abloh orchestrates each run through the GitHub App and receives the results. No clone of the repository is made on our infrastructure, and we do not hold source code at rest.
Deep audits The overnight deep audit is the single exception to the clause above, and runs only where you enable it. It makes a checkout of the branch on Abloh-operated infrastructure, reads it and writes nothing back into it, and keeps that working copy only for the audit it was made for. Evidence the audit derives from it is retained under the window in section 8, sixty days by default and adjustable between seven and ninety, is deletable by you at any time, and is purged when your account closes.
Evidence Test results, diff coverage, mutation outcomes, catch rates, timings, findings, suggested tests and release certificates. Findings may include the changed span of an affected source line and the text a run substituted for it; whole files are not transmitted to us and we do not hold source code at rest. Where a run generates a test and proves that it passes on your code and fails on the planted change, that proven test body is transmitted with the run and stored with it; candidates the run did not prove remain in the protected CI artifact and are not transmitted.
Triage context Short source context for surviving mutants is transmitted over encrypted connections to our model gateway, which calls frontier models hosted on Microsoft Azure, solely to produce triage verdicts and suggested tests. The models are used as published by their providers and are not fine-tuned by us. Your content is not used to train or fine-tune any model.
Commit & PR metadata Commit hashes, branch and pull request identifiers, commit messages, and author names and email addresses as recorded in Git history.
Ticket metadata Where an issue tracker is connected: ticket identifiers, titles and status, used for ticket matching.
Approval records Where your team records approvals or risk acceptances on a certificate: the approver’s name, work email address, role, decision and timestamp.
For all of the above, the customer that installed Abloh is the controller and we act as its processor under our Data Processing Agreement. Individuals whose personal data appears in a customer’s repositories, approvals or certificates should direct privacy requests to that customer first; we assist the customer in responding.
3 · Data we process as a controller: accounts and the Site
Account data — name, email address, GitHub username and organisation, plan and settings. Billing data — payments are processed by Stripe; we receive limited billing metadata (plan, invoice status, last four digits of the card) and never store full card numbers. Usage and log data — pages viewed, features used, IP address, browser and device information, and service logs used for security and debugging. Communications — messages sent to support, sales or email. Marketing data — email address and preferences, where you opt in to product updates.
4 · Purposes and legal bases
We process personal data under the UK GDPR and, where applicable, the EU GDPR on the following bases:
Purpose Legal basis (Art. 6 UK GDPR)
Providing the Service — executing runs, producing reports and certificates, managing accounts and billing Performance of a contract — 6(1)(b)
Securing and improving the Service, preventing abuse, aggregate usage analysis, reasonable business communications Legitimate interests — 6(1)(f)
Marketing communications and non-essential cookies, where consent is required Consent — 6(1)(a), withdrawable at any time
Retaining records we must keep, including tax and accounting records Legal obligation — 6(1)(c)
5 · AI features and model training
Abloh calls frontier models through its own gateway to triage mutation results and to propose faults and tests. The models are used as published by their providers and are not fine-tuned by us on any data. The only customer content transmitted to a model is the triage context described in section 2, sent to our model endpoint on Microsoft Azure. We do not use customer code, evidence data or any other customer content to train or fine-tune models, and our model hosting provider is contractually prohibited from doing so.
6 · Disclosures
We disclose personal data to subprocessors that host and support the Service (the current list is the table immediately below); to professional advisers where necessary; to competent authorities where required by law; and to a purchaser or successor in a merger, acquisition or sale of assets, in which case this Policy continues to apply. We do not sell personal data and we do not share it for third-party advertising.
Subprocessor Function
Amazon Web Services Application hosting, database and evidence store
Microsoft Azure Model inference
GitHub App platform, check runs and pull request comments
Stripe Payment processing
PostHog Product analytics
7 · International transfers
We are established in the United Kingdom and use service providers in the UK, the EEA and the United States. Where personal data leaves the UK or EEA we rely on adequacy regulations or appropriate safeguards, including the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses.
8 · Retention
Category Retention period
Customer repository contents Not stored by Abloh
Evidence, reports and certificates 60 days from the run, by default. An organisation administrator can set any window between 7 and 90 days in Settings, and changing it moves evidence already stored onto the new window. An administrator can delete a single run’s evidence, or all of an organisation’s evidence, at any time and whatever the window says. Deletion is immediate and cannot be undone.
Evidence on account or organisation closure Deleted in the same act. Closing an organisation purges every run record, deep audit result and reviewer label held for it.
Account data Duration of the account, then deleted or anonymised within 30 days of closure unless longer retention is required
Service logs 90 days
Billing and tax records Up to 7 years, as required by law
9 · Security
We protect personal data through encryption in transit and at rest, least-privilege access controls, signed evidence attestations, and logging and monitoring. Because pull-request and local runs execute in your own environment, your code remains within your infrastructure for them. Where you enable the overnight deep audit, it works from a checkout on our own infrastructure kept only for that audit, as described in section 2. No system is perfectly secure; if a breach affects personal data, we will notify affected individuals and the relevant regulators as required by law.
10 · Your rights
Depending on your location, you may have rights to access, correct, delete or receive a copy of your personal data, to restrict or object to our processing, and to withdraw consent — exercisable by email to info@alexandrialabs.uk (we may need to verify identity first). You may also complain to a supervisory authority: in the UK, the Information Commissioner’s Office (ico.org.uk); in the EEA, your local data protection authority. Where your personal data appears in a customer’s repositories, approvals or certificates, that customer is the controller — we will refer requests to them and assist as processor.
11 · US residents
We do not sell personal information and do not share it for cross-context behavioural advertising. Depending on your state of residence, rights to know, correct, delete and port personal information may apply, exercisable by email to info@alexandrialabs.uk. We will not discriminate against you for exercising these rights.
12 · Cookies, children and changes
We use essential cookies to operate the Site and, with consent where required, PostHog analytics to understand usage — details in our Cookie Policy at abloh.dev/cookies. The Service is a business tool and is not directed at children under 16; if you believe a child has provided us personal data, contact us and we will delete it. We may update this Policy from time to time: changes are posted here with an updated effective date, and material changes are notified by email or in-product.
This Policy is governed by the laws of England and Wales, without prejudice to mandatory rights under applicable data protection law. Contact: Alexandria Limited (trading as Abloh) · info@alexandrialabs.uk
abloh Docs Privacy Terms © 2026 Abloh