Privacy Policy

Last updated September 12, 2026

1. Introduction

RepoContext (“we”, “our”) turns GitHub repositories into AI-readable context. This policy explains what personal data we collect, why we collect it, how long we keep it and what you can ask us to do with it.

2. Information You Give Us

  • Account data: your email address and a hashed password, managed by Supabase.
  • Support messages: the message you type into the support widget and, if you provide one, your email address so we can reply.
  • Waitlist signups: the email address you submit to hear about new features.
  • Payment data: we never receive or store your card number — Creem handles the transaction and has its own privacy policy.

3. Information We Collect Automatically

  • Analysis data: repository URLs you analyse, the resulting quality score and generated files, stored with your account when you are signed in.
  • API usage: per-minute request counts used to enforce rate limits, and the last time each key was used.
  • Log data: IP address, browser and device information, and the pages you visit.
  • Error reports: crashes and exceptions are sent to Sentry so we can diagnose faults.

4. Cookies and Local Storage

We use a small number of strictly necessary cookies and no advertising or cross-site tracking cookies.

  • Session cookie — keeps you signed in.
  • Language preference — remembers the language you picked.
  • Trial counter — tracks how many free analyses you have used this month.
  • Cookie consent — remembers your choice in the consent banner.
  • Local storage — your most recent analyses are cached in your own browser so results survive a refresh. This data never leaves your device unless you explicitly create a share link.

5. GitHub Repository Data

We read repository metadata and configuration files through the GitHub API. We do not clone or store your full source tree.

For private repositories we only read what your OAuth grant allows, and only after you connect your account.

6. Shared Analysis Links

When you create a share link, a snapshot of that analysis — repository name, quality score and generated context files — becomes publicly readable at an unguessable URL. Anyone with the link can view it.

Do not create a share link for sensitive content. To have one removed, email [email protected] with the URL and we will delete it.

7. Third-Party Processors

We share data with these providers only to run the Service:

  • GitHub — reads repository metadata and files.
  • OpenAI — generates the context files. Repository metadata and file excerpts are sent for processing.
  • Creem — processes payments and subscriptions.
  • Supabase — hosts the database and authentication.
  • Resend — sends transactional email (welcome, receipts, support).
  • Sentry — collects error and performance reports.
  • Vercel — hosts and serves the application.

8. Why We Process Your Data

  • To provide the Service you asked for, including running analyses and enforcing quotas.
  • To keep the Service reliable and secure, and to investigate abuse.
  • To send service messages you cannot opt out of while you hold an account, such as receipts and security notices.
  • To comply with legal and tax obligations.

9. How Long We Keep Data

  • Account and analysis history: kept while your account is open, and deleted within 30 days of you deleting the account.
  • Support messages and waitlist entries: kept until you ask us to remove them.
  • Shared analyses: retained until removed on request.
  • API rate-limit counters: discarded after roughly two hours.
  • Server logs: rotated on a short cycle.

10. Your Rights

Depending on where you live you may have the right to access, correct, delete, export or restrict the processing of your personal data, and to object to processing based on our legitimate interests. You also have the right to complain to your local data protection authority.

  • Delete your account and its data directly from the dashboard.
  • Ask us for a copy of your data, or ask us to correct or erase it, by emailing [email protected].
  • We answer requests within 30 days.

11. Security

We use HTTPS everywhere, hash API keys with SHA-256 so the plaintext is never stored, and keep privileged credentials on the server only. No method of transmission over the internet is completely secure, so please protect your own credentials too.

12. International Transfers

Our providers operate globally, so your data may be processed outside your country. We rely on standard contractual clauses and equivalent safeguards where required.

13. Children's Privacy

The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us data, email [email protected] and we will delete it.

14. Changes to This Policy

We may update this policy. Material changes are announced on this page and, for signed-in users, by email at least 14 days before they take effect.

15. Contact

Questions about this policy or about your data? Email [email protected].

About these translations

These documents were written in English and translated for convenience. If a translated version conflicts with the English version, the English version governs.

⚠️ Disclaimer: These documents are templates that have not been reviewed by a qualified lawyer. They are provided for information only and do not constitute legal advice.

Contact

Questions about these documents? Write to [email protected].

Related documents