GitHub App privacy
How Zens AI handles GitHub data
Last updated: August 15, 2026
This notice applies to the Zens AI GitHub App and supplements the general Zens AI Privacy Policy. Privacy questions and data requests can be sent to hello@zens.ai.
Data received from GitHub
During installation and authorization, GitHub provides the installation ID, account ID and login, account type, installing user ID and login, repository selection, approved permissions, subscribed events, and the repositories made available to the installation. Repository records include the repository ID, owner, name, visibility, and public GitHub URL.
When Zens creates a GitHub issue, GitHub returns the issue ID, number, title, URL, and open or closed state. Signed webhook events notify Zens when an installation or repository selection changes and when a linked issue is edited, closed, or reopened. Marketplace purchase events provide the account and selected Marketplace plan.
Permissions and data Zens sends
The GitHub App requests Issues read and write plus read-only Metadata. Zens does not request source-code Contents, pull request, Actions, deployment, secret, administration, organization member, or email permissions. Zens sends data to GitHub only when an authorized Zens teammate creates an issue.
A created issue can include the saved support summary, selected source messages, issue type, reported product path, limited plan or account context for a private repository, and a link to the authorized Zens workspace. Customer email addresses and external user identifiers are intentionally omitted. Public repositories require an explicit confirmation before evidence is posted.
Use, storage, and security
GitHub data is used to verify the installer, show approved repositories, create requested issues, prevent duplicate exports, synchronize linked issue status, operate the free Marketplace plan, and troubleshoot deliveries. Zens does not sell GitHub data, use it for advertising, or use private repository metadata to train AI models.
GitHub App private keys, client secrets, and webhook secrets remain in backend secret storage. Installation access tokens are generated on demand, expire after one hour, and are not persisted. Webhooks require a valid HMAC-SHA256 signature, and delivery IDs are recorded to make retries idempotent. OAuth user tokens are used only to verify that the authorizing user can access the claimed installation and are not stored.
Retention and deletion
Installation and repository metadata is retained while the integration is installed or needed to maintain linked issue records. Uninstalling the GitHub App marks the installation inactive, disables repositories, and stops token creation and synchronization. GitHub issues already created remain in the repository under that repository’s retention and access rules.
An authorized GitHub account owner or Zens account owner may request access, export, correction, or deletion by emailing hello@zens.ai. Include the GitHub account login and the Zens account email, but never send credentials, private keys, tokens, passwords, or sensitive customer evidence by email. We verify authority before acting on a request.
Providers and contact
GitHub processes GitHub account and repository data under its own terms. Zens uses Cloudflare infrastructure for application hosting and database storage. For installation help, see GitHub App support or email hello@zens.ai.