Sredify
Privacy policy
Last updated October 4, 2026
Sredify is made by Danihel Group. It helps companies prepare Canadian SR&ED tax credit claims from their GitHub and Jira work. This page explains what the app collects, where it is kept, and who it is shared with. In short: your sign-in, team and claim work are kept in our database, only the people in your company can see your company's work, and we never sell data.
Your account and team (kept on our server)
You sign in with Google. We ask Google only for your name, email address and profile photo (the standard openid, email and profile permissions), never your password, Gmail, Drive or anything else. We keep, in our database:
- Your Google name, email, photo and Google account ID, and your sign-in sessions.
- The companies you create or join, who is a member and each member's role (Admin, Editor or View only).
- Invites: the email invited, the role, who sent it and when. The invite link itself is stored only as a scrambled code that cannot be turned back into the link.
- A log of team changes (who invited, joined, changed a role or left, and when).
- API keys an Admin creates (name, permissions, who created it, last used). The key itself is stored only as a scrambled code. Each API request is logged (which key or app, which address, the result and when) and kept for 90 days.
- Outside apps an Admin approves: which app, which permissions, who approved it and when. App sign-in codes and tokens are stored only as scrambled codes. Developers who register an app give us its name, website, privacy policy and return addresses.
We do not keep the access tokens Google returns at sign-in. The database is hosted by Neon (Postgres) through Vercel. Other members of a company can see the name, email and photo of everyone in that company.
Your company's work (kept on our server)
What you enter or generate for a company is saved in our database, under that company. Only its members can see it, and only Admins and Editors can change it. This includes:
- Company details (name, Business Number, addresses, fiscal year, tax profile).
- People you add (name, email, role, pay, time on R&D, qualifications, and the GitHub author and Jira user you link them to).
- Projects, the repos and Jira projects linked to them, and your settings.
- Assessments, reports, narratives and claim packages the app generates.
- Recorded time, notes and links you add as evidence, with who added them (or which app), and who removed them and why.
Deleted items are hidden from the app but kept in the company's history, so a claim stays traceable for an audit. Ask us at the address below to erase a company's data completely. Your browser keeps only small settings (theme, tutorial progress) and the tutorial's sample project, which is never sent to us.
To fight spam and abuse, a small number of Sredify staff can look at a company's work read only. They can't change anything and pay amounts are hidden from them. Every look is recorded on our side. Staff can also suspend or delete accounts and companies that break the rules; a suspended account or company is told why and how to reach support.
GitHub
A company Admin connects GitHub once for the company: they sign in with GitHub, and install our GitHub App on the repositories they choose (or pick an existing installation they manage). The app gets read only access to those repositories: code, commit history, authors and dates. We store which installation belongs to the company and the GitHub account name, never your GitHub password. Our server reads repositories only while an assessment is running and does not keep a copy of the code. An Admin can disconnect at any time; to remove the app completely, uninstall it in your GitHub settings.
Jira (Atlassian)
Connecting Jira is optional. A company Admin connects one Jira site for the company: they sign in with Atlassian and pick the site. Everyone in the company then works through that connection, with the Admin's Jira access. The app asks for read only access (the read:jira-work and read:jira-user permissions) and can then read:
- Your Jira projects (names and keys).
- Tickets in the projects you link: title, description, type, status, dates, status history, comments and logged time.
- People on those projects: Atlassian account ID, display name, and email where your Jira settings allow it.
The Atlassian sign-in tokens are kept encrypted in our database, for that company only. Our server uses them only to talk to Jira for the company; they are never sent to a browser. The Jira details the app uses (for example the Jira user linked to a person, or tickets attached to a report) are saved with your company's work. The app never changes anything in Jira.
To disconnect, an Admin uses Disconnect Jira in the app (the tokens are deleted). You can also remove the app from your Atlassian account under Profile, Connected apps. Once you disconnect, the app can no longer read your Jira.
About once a week the app tells Atlassian which Jira account IDs it holds, as Atlassian requires. If Atlassian reports that someone has closed their account, the app removes that person's Jira name, comments and link from your company's data.
AI processing
To write assessments, reports and narratives, the app sends the relevant material (for example code samples, commit messages, ticket text and the project details you entered) to an AI model through OpenRouter, which passes it to the model provider (by default Anthropic). They process it to produce the answer. We do not ask them to keep it, and their own privacy policies apply. Pay details are used by the app to calculate the claim and are not needed for the AI steps.
Who else is involved
- Vercel hosts the app. Like any web host it keeps short-lived technical logs (such as IP address and pages requested) to run and secure the service.
- Neon hosts our database (your account, team and company work, described above).
- Google, for signing in, under its own terms.
- GitHub and Atlassian, when you connect them, under their own terms.
- OpenRouter and the AI model provider, as described above.
- Outside apps your Admin approves. They get only the permissions approved, under their own privacy policy (shown on the approval screen).
We do not sell or rent data, we do not use it for advertising, and the app has no analytics or tracking scripts.
Your choices
- See, change or delete anything you entered, directly in the app.
- Admins can disconnect GitHub or Jira at any time.
- Admins can revoke an outside app or an API key at any time; it stops on its next request.
- Leave a company from Account, Members. Admins can remove members and cancel invites.
- Sign out at any time from your photo at the top of the app.
- Delete projects, assessments and claims in the app (they stay in the company history unless you ask us to erase them).
- Ask us anything about your data, or ask us to delete your account or something else, at privacy@danihelgroup.com.
Changes
If we change how the app handles data, we will update this page and the date at the top.
Contact
Danihel Group, privacy@danihelgroup.com