Information we handle
What Fettl handles depends on the part of the product you choose to use.
Access requests
The request form asks for a work email, a GitHub username or organization, team size, primary languages, coding agents you use, and an optional note. We use this information to evaluate fit, plan onboarding, and contact you about the request you submitted.
GitHub and hosted product data
When hosted features are enabled, Fettl may handle GitHub identity, organization, installation, repository, pull-request, and commit metadata needed to provide the selected workflow. Hosted findings may include rule identifiers, severity, file locations, redacted evidence, status, and assessment history.
Billing
Paid Pro billing runs through Stripe-hosted checkout and the Stripe billing portal. Hard Mode Labs does not receive full payment-card numbers from Stripe. Fettl does receive the customer, subscription, invoice, billing interval, tax, and entitlement status metadata needed to operate the paid plan.
Local and hosted processing
Free CLI checks run locally. Running those checks does not require an account and does not upload source code merely to analyze a change or resolve identity.
Hosted processing begins only when you enable a managed workflow or sign in to use a hosted feature. Fettl names four privacy modes for that boundary: LocalOnly, MetadataOnly, RedactedFindings, and FullSourceOptIn. LocalOnly keeps source and findings on the machine running Fettl. MetadataOnly permits operational metadata without source or finding content. RedactedFindings allows hosted finding records after redaction. FullSourceOptIn requires an explicit source-bearing opt-in and is not implied by installing the CLI, signing in, or running local checks.
Max Local and Max Hosted model-provider repair flows are not available. There is no live hosted model provider for Fettl repair today.
Service providers
The current hosted providers and infrastructure in this codebase are GitHub for linked repository, installation, and account metadata when you enable GitHub-connected features; Stripe for checkout, subscription, invoice, tax, and billing-portal handling; and Codex Sites / OpenAI-hosted application infrastructure backed by Cloudflare Workers and D1 for the public site and control-plane runtime.
Hard Mode Labs may also rely on provider-side logging, backups, and abuse-prevention controls that are part of those services. No separate live model-provider or hosted repair processor is enabled for public Fettl use today.
Retention and deletion
Free CLI source analysis stays local by default, so Hard Mode Labs does not receive your source merely because you ran Free checks. For hosted records, Fettl's current privacy-operations contract uses record-class retention windows of 30, 90, 180, 365, or 730 days where that class is enabled. The applicable window depends on the record type and whether the data is operational, product, billing, audit, or security-sensitive.
Provider-side backups, GitHub-side records, Stripe-side financial records, and data that Hard Mode Labs must keep for legal, accounting, fraud-prevention, or security reasons can outlast the nominal product retention window. Deletion requests cover the records Hard Mode Labs controls, subject to those exceptions.
Access-request records may be kept while Hard Mode Labs evaluates fit, schedules onboarding, or follows up on the request. If you withdraw the request or ask for deletion before onboarding, Hard Mode Labs will delete those request records unless a legal or security reason requires temporary retention.
Questions and requests
Current beta questions can be submitted through the private-beta access form. Start the optional note with “Privacy request” and do not include secrets or sensitive source content. A dedicated privacy mailbox will be published when business email is operational.