Privacy Policy
Last updated: June 2026 · Version 1.1
The data controller is Yehor Kaliberda, trading as CallMed AI, based in Aarhus, Denmark. Contact: [email protected]. This policy applies to callmedai.com and all services offered under the CallMed AI brand.
When you contact us via email, we receive your email address and the content of your message. We use this to respond to your enquiry and, where you become a customer, to administer the engagement. Legal basis: contract performance (Art. 6(1)(b) GDPR) and legitimate interest in responding to business communications (Art. 6(1)(f) GDPR).
We do not operate analytics tracking, advertising cookies, or any third-party data collection on this website. No cookies are set by callmedai.com.
Repository access granted for a Symbiote Mirror Pass engagement is used solely to perform the contracted work. File contents are passed to the Anthropic API (see Third-party processors below) to generate type annotations. Legal basis: contract performance (Art. 6(1)(b) GDPR). Source code is not retained beyond the duration of the engagement. Repository credentials are revoked and discarded at project close.
RepoMend runs entirely within your own infrastructure. Your source code is never transmitted to CallMed AI or any third-party service. The only external call is a structured fix prompt — containing the specific vulnerable code block and its surrounding context — sent to the Anthropic API to generate a candidate patch. Raw repository contents are never sent externally. CallMed AI does not receive, store, or process your source code under a RepoMend engagement. Credentials used to open pull requests are stored only in your local environment.
Anthropic, PBC (San Francisco, USA) — used as the inference provider for both Symbiote and RepoMend. Anthropic processes structured prompts containing file contents (Symbiote) or isolated code blocks (RepoMend). By default, Anthropic does not use API inputs or outputs to train its models. See Anthropic's Privacy Policy for full details. Data transits from the EU to the USA; Anthropic maintains appropriate transfer mechanisms.
No other third-party processors receive your data in the course of a CallMed AI engagement.
Email correspondence is retained for the duration of the engagement and for up to 24 months thereafter for legitimate business and legal purposes. For Symbiote engagements, repository credentials are revoked at project close; no source code is retained beyond delivery of the PR. For RepoMend, no repository data reaches our systems at any point. We do not maintain a database of customer code.
If you are located in the EU/EEA or another jurisdiction with applicable data protection law, you have the right to: access the personal data we hold about you; request correction or erasure; request restriction of processing; object to processing based on legitimate interests; request data portability; and lodge a complaint with your local supervisory authority (in Denmark: Datatilsynet). To exercise any of these rights, contact [email protected]. We aim to respond within 30 days.
We sign mutual NDAs before receiving access to any non-public repository under a Symbiote engagement. A Data Processing Agreement (DPA) under Art. 28 GDPR is available on request. RepoMend customers operating fully on-premise have no data processed by CallMed AI — contact us to confirm what agreements are appropriate for your situation.
Material changes to this policy will be reflected in an updated version number and date at the top of this page. For active customers, we will notify by email where the change affects how your data is processed.
Questions about this policy: [email protected]