Skip to content

Privacy Policy

Fahid Digital Ventures LLC publishes GitAegis. This policy explains what personal data we collect, why, how long we keep it, and what you can do about it. We have written it to be read, not skimmed.

Last updated
29 September 2026

1.Scope

1.1 This policy covers:

  • the marketing website at gitaegis.com;
  • the account and cloud service at app.gitaegis.com;
  • the GitAegis desktop application on macOS.

1.2 This policy does not cover third-party services you connect to GitAegis, such as GitHub. Those services have their own privacy policies and their own relationship with you.

1.3 Where you use GitAegis on a seat bought by your employer under a Team or Enterprise plan, your employer is the controller of your account data and its own privacy notice applies alongside this one. Our processing on their behalf is governed by the Data Processing Addendum.

1.4 Related documents: Terms of Service · End User Licence Agreement · Cookie Policy · Subprocessors · Data Processing Addendum.

1.5 Operational status. The paid cloud editions described in this document are not in operation. GitAegis ships today for macOS with no cloud service running, so nothing described here is processing anyone's data yet. Two requests the application does make are outside that scope and are described where they belong: the update check, which carries no identifier, and the AI commit report, which runs on a signed-in account when the user asks for one. This document is published for review, not as a live notice.

2.What the desktop application sends

2.1 The desktop application collects no telemetry and transmits no local file contents. It has four bounded classes of request of its own, listed in 2.2. Each one is either a request you made or a request that carries nothing identifying you.

2.2 The four:

  • The update check. One fixed release manifest, read 30 seconds after launch and then once every 24 hours. The request carries no per-install identifier, no version parameter and no query string; the version comparison happens on your device. Nothing is installed until you press Restart to update.
  • The account gateway, if you sign in. Signing in is optional and never gates local Git or recovery. It is required for the AI commit report, browser-authorized provider connections, and the account features you choose to use.
  • The AI commit report, when you ask for one. It requires a signed-in account and an explicit consent you give once, and it sends a commit’s metadata, that commit’s relationship to your current branch, and changed file paths with added and deleted line counts. File contents and commit message bodies are never sent. Usage is recorded against your account as the feature, the model and token totals.
  • A provider connection you create. A local personal access token sends repository identity and read requests directly to the GitHub or GitLab HTTPS origin you configured. A browser-authorized connection sends those requests through the configured GitAegis gateway so the provider token stays server-side. Neither path uploads local file contents or diff content.

2.2.1 And what none of them involves:

  • no usage data, crash data, or telemetry is transmitted;
  • no licence check contacts a server;
  • recovery capsules, the Flight Recorder, the Operation Journal, and Doctor reports are written to your own disk and stay there;
  • your Git credentials stay in your operating system’s keychain, where they already were.

2.3 This section describes the edition that ships. The paid cloud editions described from section 3 onwards do considerably more with our servers, because that is what you would be paying them to do, and they are not in operation.

2.4 Downloading GitAegis from gitaegis.com does involve our website, and the website is covered by sections 3, 8 and 13 below.

3.What we collect in the paid cloud editions

3.1 We collect the following categories of personal data. For each we state the purpose and the legal basis under the UK GDPR and the EU GDPR. If you are outside those jurisdictions, treat the “legal basis” column as our statement of why we consider the processing justified.

Marketing website and planned cloud data categories, with their purposes and legal bases.
CategoryWhat it includesPurposeLegal basis
Account identifiersName, email address, password hash, organisation name, role, preferred languageCreating and running your account; authentication; supportPerformance of a contract
Device identifiersAn identifier generated per installation, operating system and version, application version, CPU architecture, and the device name you chooseBinding licences to devices, enforcing seat and device limits, multi-device capsule restorePerformance of a contract
Subscription and billing recordsPlan, seat count, renewal date, billing country, tax status, invoice historyTaking payment, issuing invoices, meeting tax obligationsPerformance of a contract; legal obligation
Encrypted capsule objectsRecovery capsule archives for repositories where you have explicitly enabled cloud backup. Encrypted on your device before uploadMulti-device restore and off-device recoveryPerformance of a contract
Provider OAuth tokensAccess and refresh tokens for browser-authorized GitHub.com or GitLab.com connections, plus the account and host they belong to. Local PAT connections stay in the Mac's Keychain and are not held by the websiteShowing pull requests, CI status, reviews and comments inside GitAegisPerformance of a contract
Audit recordsWho did what, when, in which workspace and repository, on Team and Enterprise plansGiving administrators an audit trail; security investigationPerformance of a contract; legitimate interests
Support correspondenceEmails, support bundles you choose to send, screenshots you attachAnswering your support requestPerformance of a contract; legitimate interests
Opt-in telemetryFeature usage counters, operation outcomes, error types, performance timingsUnderstanding which parts of the product work and which do notConsent: see section 6
Website dataWith consent: page URL, referrer, scrolls, outbound clicks, downloads, approximate location, device and browser information, and Google Analytics identifiersUnderstanding use of the marketing website through Google Analytics 4Consent

3.2 We do not buy personal data from data brokers, and we do not enrich your account with data from third-party sources.

3.3 Providing account identifiers and accepting the device binding is necessary to hold a paid seat. Telemetry is not: see section 6.

3.4 The payment processor that would hold your card token is not named here, because none has been engaged.

4.What we never collect

4.1 We never collect, and the product is built so that it cannot transmit:

  • the contents of your source code in telemetry or error reports;
  • diffs or patch content;
  • commit contents or commit messages, outside encrypted capsule objects that you have chosen to back up;
  • file paths or file names in telemetry;
  • branch names, tag names, remote URLs, or repository names in telemetry;
  • the contents of your Git configuration;
  • your SSH private keys, your Git credentials, or your keychain contents.

4.2 Telemetry events carry counters, enumerated outcome codes, and timings. They do not carry free text drawn from your repository.

4.3 Error reports carry a stack trace, the application version, the operating system, and an error type. Paths in stack traces are truncated to the application’s own module names. Repository paths are not included. No error reporting provider is named here, because none has been engaged.

4.4 Support bundles are the one exception, and we are explicit about it. A support bundle is generated locally, scanned for secrets, and can have paths redacted before you send it. Nothing is sent until you send it. If you choose to send an unredacted bundle, it may contain repository paths and branch names. How long we would hold it is a retention period this draft does not set.

5.Capsule encryption and what we cannot read

5.1 Cloud capsule backup is opt-in per repository. No capsule leaves your device unless you enable backup for that repository.

5.2 Capsules are encrypted on your device before upload. What we receive and store is ciphertext.

5.3 We do not hold the plaintext of your capsules, and we do not hold the key material needed to decrypt them. We cannot produce your source code, your diffs, or your commit contents from a backup, not for you, not for your employer, and not for a third party who asks us to.

5.4 The direct consequence: if you lose your key material, the backup is unreadable, including by us. We cannot reset it or recover it on your behalf. Key material is yours to keep safe.

5.5 We can see, and do process, the metadata needed to store and bill for objects: object size, object count, creation time, the repository identifier the object belongs to, and the account and device it came from.

6.Telemetry is off by default

6.1 Telemetry is opt-in. It is off until you turn it on.

6.2 When we ask for telemetry consent we show you the exact categories of events involved and a version number for the consent text. Your consent is recorded against that version.

6.3 If we change what telemetry covers, the consent version changes and we ask again. Old consent does not carry over to new categories.

6.4 You can withdraw consent at any time in the application’s privacy settings or in your account. Withdrawal stops collection immediately. How long already-collected events survive a withdrawal is a period this draft does not set.

6.5 Withdrawing telemetry consent does not degrade the product. No feature is gated behind telemetry.

7.How long we keep things

7.1 We retain the following classes of data:

  • Account identifiers, kept for the life of the account and deleted after closure
  • Device identifiers, kept for the life of the registered device
  • Subscription and billing records, kept for the statutory period the governing law requires
  • Encrypted capsule objects, kept per your plan's retention setting and deleted after you disable backup for a repository or close your account
  • Audit records, on Team and Enterprise plans, extended where a legal hold is in force
  • Support correspondence, and support bundles you chose to send
  • Telemetry events, held in identifying form and in aggregate non-identifying form thereafter
  • Error reports
  • Website analytics, aggregated and non-identifying

7.2 Provider credentials are the one class with a period this draft can state. A browser-authorized provider token is held until you disconnect; the provider must confirm revocation before GitAegis deletes the encrypted token envelope. A personal access token stored in your Keychain is deleted from this Mac when you disconnect, but remains valid at GitHub or GitLab until you revoke it there.

7.3 No other retention period in this document has been set. Each one is a number the company must choose and then honour, and publishing a guess would be worse than publishing nothing. They are settled before this policy takes effect.

7.4 A deletion request is applied to live systems immediately and works through to backups within the backup retention window.

7.5 A legal hold suspends deletion for the records it covers, and only for as long as the hold is in force.

8.Who we share data with

8.1 We share personal data with service providers who process it on our behalf, under written contracts that restrict what they may do with it. The categories are cloud and edge hosting, object storage, transactional email, payment processing, error monitoring, product analytics, customer support, and status communications.

8.2 The list, with vendor names, locations, and links to each provider’s own data protection terms, is at Subprocessors. That page is the authoritative list and is updated before a new subprocessor starts processing. No vendor is named on it yet.

8.3 We also disclose personal data:

  • to your organisation’s administrators, if you use a Team or Enterprise seat that your organisation controls;
  • where we are legally required to, after checking that the request is valid and narrowing it where we can;
  • to a buyer or successor if the business is sold or merged, in which case we will tell you before your data moves and this policy will continue to apply until it is replaced by one that is no less protective.

8.4 We do not sell personal data, and we do not share it for cross-context behavioural advertising.

9.International transfers

9.1 The infrastructure the paid cloud editions would run on has not been chosen, so this draft names no hosting provider and no processing region. Both are needed before the transfer analysis below means anything concrete.

9.2 If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal data may be transferred outside your region to us or to our subprocessors.

9.3 Where that happens, we rely on:

  • an adequacy decision covering the destination, where one exists; or
  • the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where UK data is involved; and
  • a transfer impact assessment covering the destination and the provider.

9.4 You may ask for a copy of the relevant transfer safeguards by writing to privacy@gitaegis.com. We will redact commercial terms.

9.5 There is no data residency mechanism. We cannot bind an account to a region, and this policy does not offer to.

10.Your rights and how to exercise them

10.1 Depending on where you live, you have some or all of the following rights:

  1. Access: a copy of the personal data we hold about you.
  2. Rectification: correction of data that is wrong or incomplete.
  3. Erasure: deletion of your data, where we have no overriding obligation to keep it.
  4. Portability: your data in a structured, commonly used, machine-readable format.
  5. Restriction: a pause on processing while a dispute is resolved.
  6. Objection: an objection to processing we base on legitimate interests.
  7. Withdrawal of consent, for anything we do on the basis of consent, including telemetry, with no effect on processing carried out before withdrawal.
  8. Freedom from automated decision-making. We do not make decisions about you by automated means that produce legal or similarly significant effects.

10.2 The self-service privacy tooling the pack describes (export, profile correction, telemetry consent review, device listing and removal, account deletion) is not built. Until it is, write to privacy@gitaegis.com and a person will do it.

10.3 We will ask you to verify your identity before acting on a request, using the email address on the account. We do not require identity documents. The time we take to answer is a commitment this draft does not state.

10.4 We do not charge for these requests and we do not treat you differently for making one.

10.5 One limit, stated plainly: an erasure request removes your account and the objects attached to it, but we cannot decrypt your capsule objects in order to extract or amend their contents, because we do not hold the key material (section 5). We delete them whole.

10.6 If you are unhappy with how we handled a request you can complain to your local supervisory authority. In the UK that is the Information Commissioner’s Office. In the EEA it is the authority in your country of residence.

11.GDPR and UK GDPR

11.1 Controller. For account, billing, website, telemetry and support data, the controller is Fahid Digital Ventures LLC. Its registered address and registration number are not stated in this draft.

11.2 Processor. Where you use GitAegis under a Team or Enterprise plan bought by your employer, your employer is the controller and we are the processor. Our obligations in that role are set out in the Data Processing Addendum.

11.3 Data protection contact. Reachable at privacy@gitaegis.com. Whether a named data protection officer is required, and who it is, is not settled in this draft.

11.4 Article 27 representatives. Whether Article 27 of the EU GDPR or the UK GDPR applies to us, and who would represent us if it does, is a question for counsel and is not answered here.

11.5 Legal bases. These are set out per category in the table in section 3. Where we rely on legitimate interests, we have carried out a balancing test and can describe its outcome on request.

11.6 Automated decision-making and profiling. We do neither.

11.7 We do not hold any special category data as defined by Article 9, and we ask you not to send any to us.

12.California: CCPA and CPRA

12.1 This section applies to California residents and uses the definitions in the California Consumer Privacy Act as amended by the California Privacy Rights Act.

12.2 We do not sell personal information and we do not share personal information for cross-context behavioural advertising. We have not done so in the preceding twelve months. We do not sell or share the personal information of minors under 16.

12.3 Categories collected in the preceding twelve months:

CCPA categories of personal information collected, their source, and the business purpose for each.
CCPA categoryCollectedSourceBusiness purpose
Identifiers (name, email, account ID, device identifier)YesFrom you; from your deviceProviding the service; security
Commercial information (subscriptions, purchases)YesFrom youBilling and tax
Internet or network activity (feature usage, error events)Only with consentFrom your deviceProduct improvement
Geolocation (country level, from IP)Yes, coarseFrom your connectionTax determination; fraud prevention; security logging
Professional information (employer, role)If you provide itFrom youTeam plan administration
Sensitive personal informationAccount credentials onlyFrom youAuthentication
Biometric, audio, visual, education, inferencesNoNot applicableNot applicable

12.4 Sensitive personal information. The only sensitive personal information we handle is your account log-in credentials, and we use them to log you in. We do not use or disclose sensitive personal information for purposes beyond those permitted under section 7027(m) of the CCPA regulations, so the right to limit its use does not arise.

12.5 Your California rights: to know, to access, to delete, to correct, to opt out of sale or sharing (not applicable: we do neither), to limit use of sensitive personal information (not applicable: see 12.4), and to be free from retaliation for exercising any of them.

12.6 Exercise them by emailing privacy@gitaegis.com. We respond within 45 days and may extend once by a further 45 days where the request is complex, telling you first.

12.7 Authorised agents may submit requests on your behalf with written permission signed by you. We will contact you to confirm.

13.Cookies

13.1 The marketing site at gitaegis.com offers optional Google Analytics 4. Google Tag Manager and Analytics load only after you accept analytics. The site stores your choice locally and you can change it from Analytics preferences in the footer. The analytics tag is absent from UAT, localhost and app.gitaegis.com.

13.2 The application at app.gitaegis.com sets strictly necessary cookies only: session, CSRF protection, and interface preferences.

13.3 The full list, with names, purposes and durations, is in the Cookie Policy.

14.Children

14.1 GitAegis is a professional development tool. It is not directed at children.

14.2 We do not knowingly collect personal data from anyone under 16. You must be at least 16 to create an account, or older where your country sets a higher age for digital services.

14.3 If you believe a child has given us personal data, write to privacy@gitaegis.com and we will delete it.

15.Security

15.1 We describe our security practices rather than claim certifications we do not hold. The practices are set out on the Security page.

15.2 In summary: capsule objects are encrypted on your device before upload; data in transit uses TLS; data at rest is encrypted; access to production is limited to named staff, requires multi-factor authentication, and is logged.

15.3 No system is perfectly secure. If you find a vulnerability, our Vulnerability Disclosure Policy explains how to report it and what we commit to in return.

15.4 If a personal data breach affecting you occurs, we will notify the relevant supervisory authority within 72 hours where the law requires it, and notify you without undue delay where the breach is likely to result in a high risk to your rights. Notification to business customers is governed by the Data Processing Addendum.

16.Changes to this policy

16.1 We will update this policy when the product changes or the law changes.

16.2 For material changes we will give notice by email to account holders and by a notice on the site before the change takes effect. How much notice is a period this draft does not set.

16.3 Every version carries the date it was last updated at the top of this page. Previous versions are available on request from privacy@gitaegis.com.

16.4 A change to this policy never retroactively broadens what we may do with data already collected under consent. That requires fresh consent.

17.Contact

17.1 Privacy questions and rights requests: privacy@gitaegis.com

17.2 Security reports: security@gitaegis.com: see the Vulnerability Disclosure Policy.

17.3 A postal address for Fahid Digital Ventures LLC is not published in this draft. It is supplied with the registration details before this policy takes effect.

30-day trial · No card required

A recovery capsule before every risky Git operation.

You see the exact commands before they run, and the operation is refused if the capsule cannot be written.

Requires Git 2.38.0 or newer, already installed.

Every risky operation, in this order

  1. Previewthe exact commands, shown before anything runs
  2. Capsulerefs, index, staged and working changes, untracked files, operation state: written to disk first
  3. Executethe commands as shown, or not at all
  4. Journalplan, commands, capsule id, outcome
No capsule, no operation. Restore plans, previews, and takes its own capsule.