Privacy Policy
Fahid Digital Ventures LLC publishes GitAegis. This policy explains what personal data we collect, why, how long we keep it, and what you can do about it. We have written it to be read, not skimmed.
- Last updated
- 29 September 2026
1.Scope
1.1 This policy covers:
- the marketing website at gitaegis.com;
- the account and cloud service at app.gitaegis.com;
- the GitAegis desktop application on macOS.
1.2 This policy does not cover third-party services you connect to GitAegis, such as GitHub. Those services have their own privacy policies and their own relationship with you.
1.3 Where you use GitAegis on a seat bought by your employer under a Team or Enterprise plan, your employer is the controller of your account data and its own privacy notice applies alongside this one. Our processing on their behalf is governed by the Data Processing Addendum.
1.4 Related documents: Terms of Service · End User Licence Agreement · Cookie Policy · Subprocessors · Data Processing Addendum.
1.5 Operational status. The paid cloud editions described in this document are not in operation. GitAegis ships today for macOS with no cloud service running, so nothing described here is processing anyone's data yet. Two requests the application does make are outside that scope and are described where they belong: the update check, which carries no identifier, and the AI commit report, which runs on a signed-in account when the user asks for one. This document is published for review, not as a live notice.
2.What the desktop application sends
2.1 The desktop application collects no telemetry and transmits no local file contents. It has four bounded classes of request of its own, listed in 2.2. Each one is either a request you made or a request that carries nothing identifying you.
2.2 The four:
- The update check. One fixed release manifest, read 30 seconds after launch and then once every 24 hours. The request carries no per-install identifier, no version parameter and no query string; the version comparison happens on your device. Nothing is installed until you press Restart to update.
- The account gateway, if you sign in. Signing in is optional and never gates local Git or recovery. It is required for the AI commit report, browser-authorized provider connections, and the account features you choose to use.
- The AI commit report, when you ask for one. It requires a signed-in account and an explicit consent you give once, and it sends a commit’s metadata, that commit’s relationship to your current branch, and changed file paths with added and deleted line counts. File contents and commit message bodies are never sent. Usage is recorded against your account as the feature, the model and token totals.
- A provider connection you create. A local personal access token sends repository identity and read requests directly to the GitHub or GitLab HTTPS origin you configured. A browser-authorized connection sends those requests through the configured GitAegis gateway so the provider token stays server-side. Neither path uploads local file contents or diff content.
2.2.1 And what none of them involves:
- no usage data, crash data, or telemetry is transmitted;
- no licence check contacts a server;
- recovery capsules, the Flight Recorder, the Operation Journal, and Doctor reports are written to your own disk and stay there;
- your Git credentials stay in your operating system’s keychain, where they already were.
2.3 This section describes the edition that ships. The paid cloud editions described from section 3 onwards do considerably more with our servers, because that is what you would be paying them to do, and they are not in operation.
2.4 Downloading GitAegis from gitaegis.com does involve our website, and the website is covered by sections 3, 8 and 13 below.
3.What we collect in the paid cloud editions
3.1 We collect the following categories of personal data. For each we state the purpose and the legal basis under the UK GDPR and the EU GDPR. If you are outside those jurisdictions, treat the “legal basis” column as our statement of why we consider the processing justified.
| Category | What it includes | Purpose | Legal basis |
|---|---|---|---|
| Account identifiers | Name, email address, password hash, organisation name, role, preferred language | Creating and running your account; authentication; support | Performance of a contract |
| Device identifiers | An identifier generated per installation, operating system and version, application version, CPU architecture, and the device name you choose | Binding licences to devices, enforcing seat and device limits, multi-device capsule restore | Performance of a contract |
| Subscription and billing records | Plan, seat count, renewal date, billing country, tax status, invoice history | Taking payment, issuing invoices, meeting tax obligations | Performance of a contract; legal obligation |
| Encrypted capsule objects | Recovery capsule archives for repositories where you have explicitly enabled cloud backup. Encrypted on your device before upload | Multi-device restore and off-device recovery | Performance of a contract |
| Provider OAuth tokens | Access and refresh tokens for browser-authorized GitHub.com or GitLab.com connections, plus the account and host they belong to. Local PAT connections stay in the Mac's Keychain and are not held by the website | Showing pull requests, CI status, reviews and comments inside GitAegis | Performance of a contract |
| Audit records | Who did what, when, in which workspace and repository, on Team and Enterprise plans | Giving administrators an audit trail; security investigation | Performance of a contract; legitimate interests |
| Support correspondence | Emails, support bundles you choose to send, screenshots you attach | Answering your support request | Performance of a contract; legitimate interests |
| Opt-in telemetry | Feature usage counters, operation outcomes, error types, performance timings | Understanding which parts of the product work and which do not | Consent: see section 6 |
| Website data | With consent: page URL, referrer, scrolls, outbound clicks, downloads, approximate location, device and browser information, and Google Analytics identifiers | Understanding use of the marketing website through Google Analytics 4 | Consent |
3.2 We do not buy personal data from data brokers, and we do not enrich your account with data from third-party sources.
3.3 Providing account identifiers and accepting the device binding is necessary to hold a paid seat. Telemetry is not: see section 6.
3.4 The payment processor that would hold your card token is not named here, because none has been engaged.
4.What we never collect
4.1 We never collect, and the product is built so that it cannot transmit:
- the contents of your source code in telemetry or error reports;
- diffs or patch content;
- commit contents or commit messages, outside encrypted capsule objects that you have chosen to back up;
- file paths or file names in telemetry;
- branch names, tag names, remote URLs, or repository names in telemetry;
- the contents of your Git configuration;
- your SSH private keys, your Git credentials, or your keychain contents.
4.2 Telemetry events carry counters, enumerated outcome codes, and timings. They do not carry free text drawn from your repository.
4.3 Error reports carry a stack trace, the application version, the operating system, and an error type. Paths in stack traces are truncated to the application’s own module names. Repository paths are not included. No error reporting provider is named here, because none has been engaged.
4.4 Support bundles are the one exception, and we are explicit about it. A support bundle is generated locally, scanned for secrets, and can have paths redacted before you send it. Nothing is sent until you send it. If you choose to send an unredacted bundle, it may contain repository paths and branch names. How long we would hold it is a retention period this draft does not set.
5.Capsule encryption and what we cannot read
5.1 Cloud capsule backup is opt-in per repository. No capsule leaves your device unless you enable backup for that repository.
5.2 Capsules are encrypted on your device before upload. What we receive and store is ciphertext.
5.3 We do not hold the plaintext of your capsules, and we do not hold the key material needed to decrypt them. We cannot produce your source code, your diffs, or your commit contents from a backup, not for you, not for your employer, and not for a third party who asks us to.
5.4 The direct consequence: if you lose your key material, the backup is unreadable, including by us. We cannot reset it or recover it on your behalf. Key material is yours to keep safe.
5.5 We can see, and do process, the metadata needed to store and bill for objects: object size, object count, creation time, the repository identifier the object belongs to, and the account and device it came from.
6.Telemetry is off by default
6.1 Telemetry is opt-in. It is off until you turn it on.
6.2 When we ask for telemetry consent we show you the exact categories of events involved and a version number for the consent text. Your consent is recorded against that version.
6.3 If we change what telemetry covers, the consent version changes and we ask again. Old consent does not carry over to new categories.
6.4 You can withdraw consent at any time in the application’s privacy settings or in your account. Withdrawal stops collection immediately. How long already-collected events survive a withdrawal is a period this draft does not set.
6.5 Withdrawing telemetry consent does not degrade the product. No feature is gated behind telemetry.
7.How long we keep things
7.1 We retain the following classes of data:
- Account identifiers, kept for the life of the account and deleted after closure
- Device identifiers, kept for the life of the registered device
- Subscription and billing records, kept for the statutory period the governing law requires
- Encrypted capsule objects, kept per your plan's retention setting and deleted after you disable backup for a repository or close your account
- Audit records, on Team and Enterprise plans, extended where a legal hold is in force
- Support correspondence, and support bundles you chose to send
- Telemetry events, held in identifying form and in aggregate non-identifying form thereafter
- Error reports
- Website analytics, aggregated and non-identifying
7.2 Provider credentials are the one class with a period this draft can state. A browser-authorized provider token is held until you disconnect; the provider must confirm revocation before GitAegis deletes the encrypted token envelope. A personal access token stored in your Keychain is deleted from this Mac when you disconnect, but remains valid at GitHub or GitLab until you revoke it there.
7.3 No other retention period in this document has been set. Each one is a number the company must choose and then honour, and publishing a guess would be worse than publishing nothing. They are settled before this policy takes effect.
7.4 A deletion request is applied to live systems immediately and works through to backups within the backup retention window.
7.5 A legal hold suspends deletion for the records it covers, and only for as long as the hold is in force.
9.International transfers
9.1 The infrastructure the paid cloud editions would run on has not been chosen, so this draft names no hosting provider and no processing region. Both are needed before the transfer analysis below means anything concrete.
9.2 If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal data may be transferred outside your region to us or to our subprocessors.
9.3 Where that happens, we rely on:
- an adequacy decision covering the destination, where one exists; or
- the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where UK data is involved; and
- a transfer impact assessment covering the destination and the provider.
9.4 You may ask for a copy of the relevant transfer safeguards by writing to privacy@gitaegis.com. We will redact commercial terms.
9.5 There is no data residency mechanism. We cannot bind an account to a region, and this policy does not offer to.
10.Your rights and how to exercise them
10.1 Depending on where you live, you have some or all of the following rights:
- Access: a copy of the personal data we hold about you.
- Rectification: correction of data that is wrong or incomplete.
- Erasure: deletion of your data, where we have no overriding obligation to keep it.
- Portability: your data in a structured, commonly used, machine-readable format.
- Restriction: a pause on processing while a dispute is resolved.
- Objection: an objection to processing we base on legitimate interests.
- Withdrawal of consent, for anything we do on the basis of consent, including telemetry, with no effect on processing carried out before withdrawal.
- Freedom from automated decision-making. We do not make decisions about you by automated means that produce legal or similarly significant effects.
10.2 The self-service privacy tooling the pack describes (export, profile correction, telemetry consent review, device listing and removal, account deletion) is not built. Until it is, write to privacy@gitaegis.com and a person will do it.
10.3 We will ask you to verify your identity before acting on a request, using the email address on the account. We do not require identity documents. The time we take to answer is a commitment this draft does not state.
10.4 We do not charge for these requests and we do not treat you differently for making one.
10.5 One limit, stated plainly: an erasure request removes your account and the objects attached to it, but we cannot decrypt your capsule objects in order to extract or amend their contents, because we do not hold the key material (section 5). We delete them whole.
10.6 If you are unhappy with how we handled a request you can complain to your local supervisory authority. In the UK that is the Information Commissioner’s Office. In the EEA it is the authority in your country of residence.
11.GDPR and UK GDPR
11.1 Controller. For account, billing, website, telemetry and support data, the controller is Fahid Digital Ventures LLC. Its registered address and registration number are not stated in this draft.
11.2 Processor. Where you use GitAegis under a Team or Enterprise plan bought by your employer, your employer is the controller and we are the processor. Our obligations in that role are set out in the Data Processing Addendum.
11.3 Data protection contact. Reachable at privacy@gitaegis.com. Whether a named data protection officer is required, and who it is, is not settled in this draft.
11.4 Article 27 representatives. Whether Article 27 of the EU GDPR or the UK GDPR applies to us, and who would represent us if it does, is a question for counsel and is not answered here.
11.5 Legal bases. These are set out per category in the table in section 3. Where we rely on legitimate interests, we have carried out a balancing test and can describe its outcome on request.
11.6 Automated decision-making and profiling. We do neither.
11.7 We do not hold any special category data as defined by Article 9, and we ask you not to send any to us.
12.California: CCPA and CPRA
12.1 This section applies to California residents and uses the definitions in the California Consumer Privacy Act as amended by the California Privacy Rights Act.
12.2 We do not sell personal information and we do not share personal information for cross-context behavioural advertising. We have not done so in the preceding twelve months. We do not sell or share the personal information of minors under 16.
12.3 Categories collected in the preceding twelve months:
| CCPA category | Collected | Source | Business purpose |
|---|---|---|---|
| Identifiers (name, email, account ID, device identifier) | Yes | From you; from your device | Providing the service; security |
| Commercial information (subscriptions, purchases) | Yes | From you | Billing and tax |
| Internet or network activity (feature usage, error events) | Only with consent | From your device | Product improvement |
| Geolocation (country level, from IP) | Yes, coarse | From your connection | Tax determination; fraud prevention; security logging |
| Professional information (employer, role) | If you provide it | From you | Team plan administration |
| Sensitive personal information | Account credentials only | From you | Authentication |
| Biometric, audio, visual, education, inferences | No | Not applicable | Not applicable |
12.4 Sensitive personal information. The only sensitive personal information we handle is your account log-in credentials, and we use them to log you in. We do not use or disclose sensitive personal information for purposes beyond those permitted under section 7027(m) of the CCPA regulations, so the right to limit its use does not arise.
12.5 Your California rights: to know, to access, to delete, to correct, to opt out of sale or sharing (not applicable: we do neither), to limit use of sensitive personal information (not applicable: see 12.4), and to be free from retaliation for exercising any of them.
12.6 Exercise them by emailing privacy@gitaegis.com. We respond within 45 days and may extend once by a further 45 days where the request is complex, telling you first.
12.7 Authorised agents may submit requests on your behalf with written permission signed by you. We will contact you to confirm.
14.Children
14.1 GitAegis is a professional development tool. It is not directed at children.
14.2 We do not knowingly collect personal data from anyone under 16. You must be at least 16 to create an account, or older where your country sets a higher age for digital services.
14.3 If you believe a child has given us personal data, write to privacy@gitaegis.com and we will delete it.
15.Security
15.1 We describe our security practices rather than claim certifications we do not hold. The practices are set out on the Security page.
15.2 In summary: capsule objects are encrypted on your device before upload; data in transit uses TLS; data at rest is encrypted; access to production is limited to named staff, requires multi-factor authentication, and is logged.
15.3 No system is perfectly secure. If you find a vulnerability, our Vulnerability Disclosure Policy explains how to report it and what we commit to in return.
15.4 If a personal data breach affecting you occurs, we will notify the relevant supervisory authority within 72 hours where the law requires it, and notify you without undue delay where the breach is likely to result in a high risk to your rights. Notification to business customers is governed by the Data Processing Addendum.
16.Changes to this policy
16.1 We will update this policy when the product changes or the law changes.
16.2 For material changes we will give notice by email to account holders and by a notice on the site before the change takes effect. How much notice is a period this draft does not set.
16.3 Every version carries the date it was last updated at the top of this page. Previous versions are available on request from privacy@gitaegis.com.
16.4 A change to this policy never retroactively broadens what we may do with data already collected under consent. That requires fresh consent.
17.Contact
17.1 Privacy questions and rights requests: privacy@gitaegis.com
17.2 Security reports: security@gitaegis.com: see the Vulnerability Disclosure Policy.
17.3 A postal address for Fahid Digital Ventures LLC is not published in this draft. It is supplied with the registration details before this policy takes effect.