Skip to content

Data types

How do I de-identify code reviews and pull requests for AI training?

By SourceX Editorial · Updated

Short answer

To de-identify code reviews and pull requests, remove or replace reviewer names and emails, secrets in diffs and customer-owned code, check free text and attachments for hidden details, review samples by hand and exclude anything doubtful. Your company then approves the prepared copy before it leaves.

What code reviews and pull requests usually contain#

Typically pull requests, review comments and approvals. The work itself is what buyers value; the identities are not.

What to remove or replace#

At minimum: reviewer names and emails, secrets in diffs and customer-owned code. Names are often swapped for consistent placeholders so conversations still make sense.

How to check it worked#

Automated tools catch most details, but not all. Reviewers spot-check samples, look for rare facts that could point to a person, and drop records they are unsure about. Buyers are also contractually barred from trying to identify anyone.

How SourceX handles it#

SourceX starts with a short fit check that shares no data. If it fits, rights are reviewed, a copy is prepared with personal and confidential details removed, and your company approves exactly what leaves before anything is delivered under a signed license.

Frequently asked questions

Can I do the de-identification myself?

You can, but SourceX or an approved preparation partner normally does it and you review the result.

Is this legal advice?

No. It is general information; your counsel should review any specific deal.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify