Privacy Policy (GitGlow)
Last Updated: 28.08.2026
This Privacy Policy explains how GitGlow ("we", "us", "our") processes personal data when you use the GitGlow desktop application and related services (the "Service").
1. Data Controller
Stoyan Korudzhiev
Sofia, Bulgaria 1324
Email: skorudzhiev@gmail.com
2. What We Process
2.1 Local Repository Data (Processed on Your Device)
GitGlow analyzes Git repositories you select, which may include Git metadata such as:
- Commit hashes
- Author names (as recorded in commits)
- Commit dates and times
- Commit messages
- Branch names
- File change statistics (e.g., additions, deletions)
By default, this information is processed locally on your device.
Repository paths, source code, diffs, local action previews, and redacted local audit records remain on your device. GitGlow does not send them to analytics.
2.1.1 Agent Observatory data
Agent Observatory coordinates observed Codex and Claude clients, GitGlow-managed runs, existing MCP clients, and independent working-tree observation on your device. Its schema-3 run and Replay records contain structured operational metadata such as provider/client and connection type, opaque hashed session identity, opaque repository and checkout identifiers, relative paths, line counts and status classifications, hashes, event categories, timestamps, provenance, approval states and results, agent relationships, handoff metadata, redaction state, and outcomes.
For trusted repositories, rich safe recording is enabled by default. Sanitized provider-visible plans, commentary and readable summaries, commands, bounded output and test results, approvals and questions, provider-supplied collaboration, relative paths, diff statistics, and sanitized text diff hunks may be compressed into authenticated per-run frames encrypted with an installation key protected by macOS Keychain. Output is bounded to 256 KiB per event and a diff artifact to 1 MiB. Binary files and source or diff bodies for files larger than 1 MiB remain metadata-only.
Agent Observatory never retains raw user prompts, full conversational transcripts or final replies, hidden/raw reasoning, credentials, authorization headers, cookies, tokens, connection strings, capability tokens, private-key material, absolute paths, binary contents, or source/diff bodies from .env, credentials, certificates, private keys, authentication caches, and user-excluded paths. Redaction and truncation are shown in Event Detail.
GitGlow does not durably record agent prompts or responses, source contents, diff or patch bodies, command output, hidden reasoning, provider-supplied readable reasoning summaries, capability tokens, OpenAI or Anthropic credentials, GitHub pull-request bodies, commit messages, secrets, or absolute paths. Rich live details stay in a bounded in-memory cache, expire after completion, and clear when the application exits or restarts. A pending approval may temporarily contain the minimum typed arguments needed for local review. That short-lived envelope is deleted after denial, expiry, application, invalidation, or sidecar termination; only its hash and sanitized outcome remain.
Free retention is active state plus the most recent completed Replay for 24 hours. GitGlow Pro defaults to 30 days and a 2 GiB rich-recording soft cap, with 7, 30, 90 day, and Forever controls. Pinned Replays are exempt from age cleanup but still count toward displayed storage. Active runs are not evicted. If active and pinned data occupy the soft cap, new rich bodies pause while structured metadata continues. You can pause/resume recording, pin/unpin, delete individual Replays, or delete the completed archive from the app. Exported handoffs are files you choose to create and control.
2.1.2 Indie Log data
Indie Log is a separate schema-v2 store on your device. It retains source opt-in settings, managed generation status, editable report packs, legacy review candidates, accepted journal entries, evidence references, and export metadata until you delete or replace them. Manual entries may have no evidence; managed outcomes and MCP/AI candidates require evidence and remain drafts until you explicitly save or accept them.
Managed Indie Log generation sends the selected Codex or Claude provider an ephemeral, bounded bundle for the chosen repositories and range: commit/PR/tag/release/Mission metadata, commit bodies, tracked relative paths, change statistics, and short textual diff excerpts. It excludes untracked and ignored files, binaries, secret-prone paths, credential-like lines, absolute paths, author email, unrelated history, and unchanged raw source. The bundle is capped at 160 KiB and each excerpt at 4 KiB; truncation and partial GitHub sources are shown before generation. GitHub-only context passes through the authorized GitHub App without server-side retention. Raw prompts, provider transcripts, reasoning, and the ephemeral bundle are not stored in Replay or the Journal. The advanced MCP fallback remains metadata-only. GitGlow does not operate an Indie Log cloud database; the journal itself remains local.
2.2 GitHub Integration (Optional)
If you choose to install and connect the GitGlow GitHub App, the GitGlow API may process data retrieved through GitHub’s API for repositories you select, such as:
- Your GitHub username
- Repository metadata (e.g., repository name)
- Pull request, review, check, status, issue, and release metadata
- Repository contents needed for an action you explicitly preview and apply
GitHub user and installation tokens are encrypted by the GitGlow API. They are not placed in desktop deep links, the desktop webview, analytics, logs, or MCP responses. Desktop deep links contain only short-lived, single-use exchange codes.
You can revoke GitGlow’s access at any time via your GitHub account settings.
GitGlow is not affiliated with or endorsed by GitHub, Inc.
2.3 Payments (If Applicable)
If you purchase paid features, checkout, payment methods, invoices, and the customer portal are handled by Stripe.
We do not store:
- Full card numbers
- CVV codes
We may process or retain:
- Subscription status
- Transaction identifiers
- Billing email address (if provided)
- Records required for accounting and tax compliance
2.4 Technical Data (Limited)
We may process limited technical data necessary to operate and improve the Service, such as:
- App version
- Operating system
- Basic diagnostics or error logs (if enabled)
If analytics is enabled on a GitGlow web property or in a product surface, it may receive limited events such as page or feature usage. Those events must not include repository paths, source code, diffs, GitHub tokens, GitGlow session tokens, or action preview tokens.
Agent Observatory analytics are limited to aggregate view, demo, connection-kind, and locked-feature identifiers. They do not include provider-session identity, client names, run titles, repositories, paths, prompts, source, detailed activity, action details, approval decisions, or collision information.
3. Purposes of Processing
We process data to:
- Provide and operate the Service
- Enable optional GitHub integration (if you choose it)
- Provide paid features and manage subscriptions (if applicable)
- Improve stability, performance, and user experience
- Comply with legal obligations
4. Legal Bases (GDPR)
Where the GDPR applies, we rely on one or more of the following legal bases:
- Contract: to provide the Service you request
- Legitimate interests: to maintain, secure, and improve the Service
- Legal obligations: for compliance (e.g., tax/recordkeeping)
- Consent: where required, and only if you provide it
5. Data Retention
- Local repository data remains on your device unless you choose to export or share it
- Accepted Indie Log entries remain on your device until you delete or replace them; dismissed candidates are removed
- Agent Cockpit approval envelopes and stale desktop/client presence leases are removed independently of Replay retention
- GitGlow desktop session tokens are stored in the operating-system credential store; clean and signed-out installations do not access that store during startup, and any one-time restore of an older marker-less session is user initiated
- GitHub provider tokens are encrypted server-side and can be revoked by signing out or uninstalling the GitHub App
- Payment-related records are retained as required by applicable law
6. Sharing and Third Parties
We do not sell personal data.
We may share data with:
- GitHub, when you connect its optional integration
- Stripe, for checkout and subscription management
- Cloudflare, for GitGlow API infrastructure
- Analytics providers, only when enabled and subject to the limits described above
- Authorities where required by law
7. International Transfers
If personal data is transferred outside the EU/EEA (for example, through third-party providers), we rely on appropriate safeguards such as:
- Adequacy decisions, or
- Standard Contractual Clauses (SCCs), where applicable
8. Your Rights (EEA/UK Users)
If you are in the EEA/UK, you may have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion
- Restrict processing
- Object to processing
- Data portability
- Lodge a complaint with a supervisory authority
To exercise your rights, contact: skorudzhiev@gmail.com
9. Security
We implement reasonable technical and organizational measures to protect personal data. However, no method of transmission or storage is completely secure.
10. Children
The Service is not intended for individuals under 16 years of age, and we do not knowingly collect personal data from children.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date above. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.