How cleap handles your code
cleap reads your repository, keeps a map of it, and never writes anything back. Everything below is what actually happens, in the order it happens.
- A map
- not a copy of your code
- Never
- used to train a model
- Yours
- to delete, any time
Read-only. The GitHub App has no write permission of any kind.
A map, not a copy. Your source files are not stored in our database.
Never used for training. Not by us, and not by the model provider.
Yours to delete. Disconnect a repository and everything derived from it goes immediately.
1. What cleap reads
Read access to code, metadata, pull requests and Dependabot alerts. Nothing else, and no write permission of any kind.
You connect a repository through the cleap-ingest GitHub App, and you grant it on GitHub's own screen, for all repositories or only the ones you pick. You can change or revoke that on GitHub at any time.
Reads happen with short-lived tokens scoped to that one installation. cleap has no standing access to your account.
2. What cleap keeps
A map of your system, not a copy of your code.
What cleap reads
export async function getInvoice(id) {
const row = await db.invoices.find(id)
if (!row) throw new NotFound()
return serialise(row)
}Read on the way past, and not written to our database.
What cleap keeps
- Name
- getInvoice
- Kind
- Function, in an API file
- Calls
- db.invoices.find, serialise
- Plain label
- Invoice lookup
- Position
- where it sits on your map
From each read cleap stores what it worked out: the parts it found (files, modules, tables, services), how they connect, where they sit on the map, plain-language labels for them, and a few setup facts read off the repo: scripts, engine versions and the names of environment variables, never their values. It also keeps counts per sync so you can see how the map changed.
Your source files are not stored in cleap's database. When you open a part's code inside the map, that file is fetched from GitHub at that moment and shown to you; it isn't cached on our servers.
One exception, worth naming rather than leaving you to find it: when cleap draws a diagram of a file, each step cites the line it came from, and those short quoted lines are saved with the diagram so the citation still works later. A handful of lines per diagram, never the file. They go when the repository does.
While cleap reads a repository, a working copy is checked out on our ingest server. It stays there between syncs so the next sync only has to read what changed, and it is deleted the moment you disconnect the repository.
3. Where AI is involved
Anthropic's Claude models, given the relevant slice of the map. Never your whole repository.
Plain-language labels, Ask cleap answers, diagrams and generated documentation are the AI features. What gets sent is names, connections, a part's neighbours and, for a code-level question, the excerpt in question. Anthropic's API terms do not allow them to train on that data.
Each AI call is logged (which feature, which model, tokens, timing, and a truncated copy of the prompt and answer) so Ask cleap can show your history and so we can debug a bad answer. When you disconnect a repository, the text in those logs is blanked; only the timing and token counts remain.
If you paste a link as extra context for a document, that one page is fetched through Firecrawl to read it. Nothing from your repository goes there.
4. Who can see it
Members of your workspace, according to their role. Nobody outside it unless you share a document on purpose.
A shared document link exposes that one document and nothing else. The public showcase maps are well-known open source repositories we ingest ourselves; a customer repository is never listed there.
5. When it updates
When you connect a repository, when you press Sync, and when a commit lands on the default branch.
GitHub tells cleap about that commit through a webhook. Nothing is read on a timer.
6. How to remove it
Disconnect a source and everything derived from it is deleted right away. No waiting period, no support ticket.
Disconnect a source (Products page, or the source's own settings) and its map, labels, diagrams, documents and sync history go, the working copy is removed and the AI log text is blanked. Delete a workspace and its products, sources, members, invites and GitHub connections go with it. To close your account entirely, email hello@cleap.dev from the address you signed up with.
Revoking the GitHub App on GitHub stops all reads immediately, even before you disconnect anything here.
7. Where it lives
Supabase (Postgres, in AWS us-east-1) and Railway.
Accounts and maps are stored in Supabase; the service that reads repositories runs on Railway. The app itself runs no third-party analytics or tracking scripts.
8. What cleap never does
- Write to your repository, open pull requests, or change any setting on GitHub.
- Read a repository you didn't give the App access to.
- Train models on your code, or let anyone else.
- Sell or share your data.