fake idan

Public trust surface · Updated July 30, 2026

Privacy & data use

Fake Idan turns deliberately shared context into code-review output. This page separates what stays private, what reaches a processor, and what is published.

01 / ZERG SSO

One identity, bounded claims.

When you choose “Sign in with Zerg,” Fake Idan receives a stable Zerg account ID, verified email, display name, and—only when the client is granted that scope—whether the account is a Zerg platform superuser. Fake Idan never receives your Zerg password.

A verified email does not silently link an existing local account. Platform administration also requires both an allowlisted email in Fake Idan and the superuser claim from Zerg; neither condition grants access by itself. Platform authority is separate from workspace membership and does not bypass tenant boundaries.

02 / GITHUB

Repository access is selected by you.

During the personal-account beta, install the Fake Idan GitHub App using Only select repositories. Fake Idan uses the temporary GitHub user credential only in memory to prove that the installation belongs to the signed-in person, then discards it. Repository work uses short-lived installation credentials.

For a connected repository, Fake Idan can read pull-request metadata, changed-file patches, bounded candidate source windows, prior discussion, and check results. It can publish reviews and comments. It does not accept personal access tokens and does not clone the repository.

03 / KNOWLEDGE & MODELS

Private is the default, sharing is a choice.

Private knowledge is not sent to a review processor. A person owner must mark a source for review use before its content may be sent to the configured review and judge processors or shape a public comment. Trap documents are review-shared by design. Never store secrets in review-shared material.

The current review and judge processor is OpenAI. The running Settings trust ledger publishes the exact configured service, model, endpoint, input categories, limits, and operator-declared retention posture. Review the OpenAI API data-use policy.

04 / OUTPUT & RETENTION

Publication is an explicit boundary.

A published review is intentionally public on GitHub. Fake Idan labels that output with its fake-person identity and keeps the review run, evidence decisions, feedback, and publication checkpoint so the result can be audited and calibrated.

Account, workspace, knowledge, integration, and review records remain stored while the service needs them to provide the workspace and its audit trail. Session and API credentials are stored as one-way hashes; integration secrets are encrypted at rest. Fake Idan does not sell personal data.

05 / CONTACT

Questions or deletion requests.

Contact the operator at idan@zergai.com . Include the workspace name and account email, but never send a password, session credential, API token, or integration secret.