gitcafe / legal
Privacy Policy
Effective August 6, 2026
This policy explains how GitCafe handles personal information when you use our hosted service. It does not govern independently operated deployments of GitCafe software.
1. Information we collect
We collect information in the following categories:
- Account and profile: email address, password hash, handle, display name, avatar, and optional profile fields.
- Authentication and security: passkey metadata, public SSH and GPG keys, access-token and device authorization metadata, MFA state, sessions, IP addresses, user agents, and security and authorization audit events.
- Content: repositories and Git metadata, including commit author names and emails; issues, pull requests, reviews, comments, attachments, releases, LFS objects, CI configuration, logs, and artifacts.
- Organizations and integrations: memberships, roles, invitations, webhook and integration configuration, event payloads, and delivery diagnostics.
- Billing: plan, subscription, usage, and Stripe customer and subscription identifiers. Stripe collects and processes payment-card details under its own privacy policy.
- Operational data: requested paths, timestamps, device and network information, performance measurements, error reports, and rate-limit identifiers.
2. How we use information
- Provide, maintain, and administer the Service.
- Authenticate users, enforce permissions, and secure accounts.
- Store and render repositories and collaboration content.
- Operate integrations, webhooks, automation, and CI features.
- Send verification, recovery, invitation, and security email.
- Measure reliability, diagnose errors, and improve performance.
- Administer plans, subscriptions, usage, and payments.
- Prevent abuse, enforce our policies, comply with law, and resolve disputes.
3. Visibility and organizations
Public profiles and public repositories are available to anyone and may be indexed, scraped, cloned, cached, forked, or redistributed by others. Removing content from GitCafe cannot remove copies other people already made. Git author information and durable attribution may remain in repository history after an account changes or closes.
Private content is available to authorized collaborators, organization administrators, and the limited GitCafe personnel and providers described in these policies. Organization administrators may manage memberships, access, integrations, and audit information.
4. Service providers and disclosure
We currently use the following providers to operate GitCafe:
- Latitude for compute and infrastructure.
- Amazon Web Services for infrastructure and object storage.
- PlanetScale for database services.
- Vercel for web and landing-page hosting.
- Axiom for operational telemetry and error diagnostics.
- Resend for transactional email.
- Stripe for subscriptions and payment processing.
We also disclose information according to repository visibility and organization permissions; to integrations and webhook destinations you select; to comply with valid legal process; to protect GitCafe, our users, or the public; and in connection with a merger, financing, acquisition, or sale of assets subject to appropriate confidentiality protections.
We do not sell personal information, share it for cross-context behavioral advertising, or use repository content to train generative AI models.
6. Retention and deletion
We retain information while needed to provide the Service and for security, fraud prevention, dispute resolution, legal compliance, and legitimate business records. Short-lived authentication records expire automatically. Operational telemetry and access logs are retained for limited periods appropriate to troubleshooting and security. Billing records may be retained for legally required accounting periods.
Account or content deletion removes information from active use, but may not immediately remove encrypted backups, legal holds, security records, audit history, stable attribution, or copies held by other users. We retain only the information reasonably necessary for those purposes and delete or de-identify it when the purpose ends.
7. Your choices and rights
You may update most profile and account information through the Service. Depending on your location, you may also request access, correction, export, deletion, restriction, or objection concerning your personal information. Email privacy@git.cafe. We may verify your identity and may retain information where permitted or required by law. We will not discriminate against you for exercising a privacy right.
8. International use and transfers
GitCafe is operated from the United States. You understand that information may be processed in the United States and other countries where our providers operate. Where applicable law requires additional safeguards for an international transfer, we will use an appropriate legal mechanism.
9. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, credential protection, and security logging. No system can guarantee absolute security. Please report suspected vulnerabilities or account compromise promptly.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect their personal information. Contact privacy@git.cafe if you believe a child under 13 has provided personal information so we can investigate and take appropriate action.
11. Changes and contact
We will update the effective date and provide reasonable advance notice of material changes. Questions, complaints, and privacy requests may be sent to privacy@git.cafe. GitCafe has not appointed a Data Protection Officer; this address is monitored by the team responsible for privacy matters.