Bito AI
Bito · Coding agent · US · bito.ai
services/bito-ai.yamlVendor data-handling terms
The policy classes code, code artifacts, and connected Jira and Confluence data as Confidential Customer Business Data and states AI requests are not retained. It does not separately state whether that data is excluded from model training.
“AI requests are neither retained nor viewed by Bito.”
“AI requests are neither retained nor viewed by Bito. / This data is terminated 90 days after the end of the business relationship with Bito. / This category of data is retained indefinitely for ongoing service improvement and customer support.”
“Our Services are hosted in the United States and information we collect will be stored and processed on our servers in the United States.”
Domains and endpoints
observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.
| Host | Role | Source |
|---|---|---|
| bito.ai | app | observed |
Assessment
Reasoning: An AI code-review agent that reads repositories and connected Jira and Confluence content. Not retaining AI requests is the key commitment; the absence of an explicit no-training statement for code is a gap. Processing is in the United States. The exposure is source code and internal documentation crossing the Atlantic at review time.
Flags: GDPR Chapter V (US hosting) · Training use of code not explicitly stated · Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.
Changelog
- 2026-09-16Documented. Retention and hosting terms verified against the Bito privacy policy.
- 2026-09-15Listed from the Unseen catalogue with observed domains.
Corrections
Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.