← Back to Gomes

Privacy & support

Gomes is a public beta maintained by Priyankar.

What the service stores

Your GitHub identity (if connected), encrypted GitHub access tokens, repository links, repair run evidence, username, password hash, recovery-key hash, session records, project URLs, audit results, task models, usage counts and subscription status are stored in Supabase PostgreSQL. Authentication rate limits store hashed network identifiers for short-lived counters. Vercel hosts the application and may retain request and operational logs under its service settings.

Reports are private to your account. Submitted pages are loaded by temporary browser workers on Vercel. Reports can contain URLs, selectors and observations from those pages. Submit only public pages you own or have permission to test; avoid URLs containing credentials or sensitive query parameters. Automated results do not establish accessibility conformance or replace research with users.

Repository repairs

When you start a repair run, the selected repository is copied into a temporary Vercel sandbox. Source excerpts, tool output and audit evidence are sent to OpenAI to generate changes. The service verifies those changes and can open a draft GitHub pull request. It never merges a PR automatically. The sandbox receives no database, payment, or GitHub write credentials. Runs are capped at 20 minutes and 24 model requests. GitHub access is limited to the repositories you select when installing the app.

Payments

Dodo Payments hosts checkout and handles payment details. We store subscription identifiers and entitlement status; we do not receive card numbers. Studio costs US$19 per month plus applicable tax. Checkout shows the final amount and renewal terms. Manage or cancel your subscription through Plans & billing. Community includes three static audit runs total. Studio includes 200 static audits and five repair runs per calendar month. Admitted runs count toward their allowance, including partial or failed runs.

Retention and deletion

Account data and reports are retained to provide your workspace until you request deletion. Operational logs and backups follow the hosting providers' retention settings. Deletion from active storage may take time to propagate through backups. Keep your recovery key: this service does not send password-reset emails.

Support, refunds and data requests

Use the maintainer contact details on the maintainer's profile for account, deletion or refund requests. For payment questions you can also use the support route in your Dodo receipt. Never post passwords, recovery keys, payment details or private reports in a public issue.

The hosted service is a beta; measurements and availability can vary. The MCP packages are published under open-source licenses; the application repository is currently private.