AI Policy
Last updated
Rebase is built to work alongside AI coding tools. This policy explains how AI features work, how your data is treated, and the commitments we make.
1. Our core commitments
- We do not train AI models on your data. Customer Data — tickets, feedback, screenshots, and diagnostic context — is never used to train or fine-tune Rebase’s or any third party’s models.
- Built-in AI is disclosed and controllable. AI-assisted triage is part of the service on paid plans and enabled by default (see §3); it uses the AI provider listed on our Subprocessors page, and you can ask us to disable it for your projects. Connecting an external agent is always your action.
- You stay in control. You decide which agents and integrations to connect and what ticket context they can access.
2. Connecting your own AI agents (MCP)
Rebase exposes ticket context through the Model Context Protocol (MCP) so that an AI agent you connect — such as Claude or Cursor — can read a ticket and help draft a fix. When you connect an agent:
- The agent and its underlying model provider are chosen and controlled by you;
- Ticket context you authorize is shared with that agent under the provider’s terms;
- Beyond the built-in triage described in §3, Rebase does not send your data to model providers on your behalf.
Because the model provider is your choice, that provider acts as your subprocessor for the data you route to it, not Rebase’s. Review your provider’s data and retention policies before connecting.
3. AI-assisted features within Rebase
AI-assisted triage — classifying, titling, and summarizing incoming tickets — is part of the service and is enabled by default on paid plans (the Free plan has no AI features). It operates only on a minimized, scrubbed slice of the relevant ticket’s text; screenshots are never sent. Triage output is an aid with a human in the loop, and is not used to make decisions producing legal or similarly significant effects without human review. The third-party model provider powering it is listed on our Subprocessors page, does not train on your data, and — if you’d rather not use AI at all — can be disabled for your projects by emailing [email protected].
4. Data minimization & masking
The same privacy protections that apply to capture apply to AI features: password, payment, hidden, and customer-marked fields are masked, and secrets are scrubbed, before data is stored or shared. You remain responsible for configuring masking for sensitive fields on your site.
5. Accuracy
AI output can be incomplete or incorrect. Suggestions are aids, not professional advice, and should be reviewed by a person before you rely on them.
6. Changes & contact
We’ll update this policy as our AI features evolve. Questions? Email [email protected].