AI policy

We do not train on your code, period.

Not on private repositories, not on public ones, not on your issues, your review comments or your commit messages. Not for a model of our own, not by selling a corpus, not through a research partnership, and not under a setting that quietly defaults on. There is no tier where this changes and no checkbox that reverses it.

The word doing the work in that paragraph is period. A commitment with an exception in it is a roadmap, and the industry has spent two years teaching people to read them that way. So the exceptions are enumerated below rather than left for you to discover: there are none, and here is what we do instead.

The commitment, spelled out

Public does not mean ours

A public repository is public so people can read, clone and build on it under the licence its author chose. That is not the same as consenting to be training data, and treating the two as equivalent is the specific move that cost the incumbent its goodwill. We host your code; we do not acquire it.

Nobody else gets a corpus either

We do not sell, licence or otherwise hand your repositories to a model provider, a data broker or an academic partner. If that ever changed it would be a breaking change to the product, announced as one, and not a line in a revised privacy policy.

No model call sits in the write path

Nothing in the push path, the review path or the intake worker makes an outbound call to a model. It is a design constraint before it is a policy: every gate has to be testable without a network, so an outbound call could not have shipped even if we had wanted one.

Triage runs where you can see it

If a project wants a model to summarise incoming contributions, it runs that model itself and posts the summary in through an ordinary API endpoint with an agent-flagged token. The summary is attributable to a principal you configured, which is the only version of this we know how to make honest.

The one thing we do read your repositories for is serving them: packing, verifying, indexing names and descriptions for search, and computing the metrics your dashboard shows you. That work happens inside your namespace and produces nothing that leaves it.

Agents are labeled, not banned

The other half of neutrality is the half most policies skip. Refusing to train on code is easy to say; deciding what happens when a machine opens a pull request is where a forge actually takes a position. Ours is that agents are legitimate contributors, that they must be identifiable as such, and that each project decides for itself whether it wants them.

Identity

Its own principal, always

An agent is an account of its own kind, holding its own credentials. It never borrows a human’s name to make its work look hand-written, and its own activity is its operator’s audit trail rather than someone’s résumé.

Attribution

Labeled where it lands

Agent-authored commits are detected from the trailers they already carry and render distinctly on changes and in history. They never inflate a human’s contribution graph, which keeps the graph meaning what it says.

Policy

Per project, three settings

welcome, labeled (the default) or human-only. A human-only repository refuses an agent principal at both doors, with a sentence naming the policy — a maintainer who wants no machine contributions gets a rule, not a norm.

We do not have an opinion about which of the three is correct for your project, and we will not pick a default that drifts. Enterprises want the same control for the same reason maintainers do: a policy stated in a file beats a norm stated in a CONTRIBUTING section that nobody reads.

Neutrality is not indifference

Being neutral about machine-written code does not mean accepting an unbounded volume of it. The problem a maintainer actually has is not that a model wrote the patch; it is that reading it costs the same hour whether it was going to land or not.

So we spend machine time first. A contribution has to apply, pass the project’s own checks, not duplicate five others already open, and obey the rules the repository declares — before it becomes a notification. That is a volume answer, not a provenance one, and it works exactly as well on a careless human as on a careless agent.

How the maintainer firewall works →

What we would have to tell you

Two things could make this page out of date, and both would be announced rather than edited in.

The first is a lawful order. We would say what we can, when we can, and publish the fact of it; nobody can promise more than that honestly.

The second is a feature that needs a model. If we ever want one, it ships as something you turn on, scoped to the repository you turn it on for, with the provider named — and the no-training commitment above still holds for the code it reads. A default-on version of that feature is the thing this page exists to promise you will not wake up to.

Weft for open sourceWhat moves when you migratePrincipals, tokens and scopes