There is now documentation, at /docs.
It covers connecting a repository and what that access actually grants, running your first review, reading a report — including why the coverage section matters as much as the findings — deciding what to fix first, and what happens to your source code while a review runs.
The page most worth reading is Security and your code. It sets out what we do and do not do with the repositories you connect, and why each of those statements is enforced by how the product is built rather than promised.