Privacy Policy
What we collect, why we collect it, who processes it and how you can delete it.
Effective date: September 23, 2026
This policy explains how GitBrand ("GitBrand", "we", "us"), available at gitbrand.com, handles personal data. It applies to visitors of public brand pages, people who create an account, and anyone who uses our public API.
The short version
- We collect what is needed to run the service: your account details, the brand assets you upload, and aggregate usage of the pages you publish.
- Public brand pages are public. Private and password-protected ones are visible only to members or people you share access with.
- We never sell personal data and we do not show ads.
- Visitor statistics are anonymous: we store a daily hash of the visitor's network address, not the address itself, and nobody is identified by name.
- You can delete your account and everything in it from your profile at any time.
What we collect
Account information
When you sign in with Google or GitHub we receive your name, email address and profile picture from that provider. When you create an account with an email address and password we store the email, your name and a one-way hash of the password. We never store the password itself.
Content you add
Repository names, descriptions, logos, colors, fonts, files, questions and answers, brand voice text, the members you invite (their email address and role), and every published version of a repository. Repository passwords are stored as one-way hashes.
Usage of published pages and the API
For each view of a brand page and each download, share, unlock, copy or API request we record the repository, the time, the kind of event, the asset involved, the country (from the network address), the referring website, the type of device (desktop, mobile, tablet) and an anonymous visitor hash. The hash is derived from the network address, the browser identifier, a secret and the current day; it cannot be turned back into an address and changes every day.
Messages you send us
Contact form submissions (name, email, subject, message) and reports about a repository (message, repository, and your name and email if you are signed in).
Technical logs
Our hosting provider keeps standard request logs (network address, user agent, path, timestamp) for a short period to operate and secure the service.
How we use it
- To provide the service: sign you in, store and serve your repositories, deliver files through the asset API, and send transactional emails (confirmation, password reset, invitations, notifications).
- To show repository members how their brand page is used (Insights).
- To keep the service safe: rate limiting, abuse reports, fraud and spam prevention.
- To understand how the product is used as a whole, using Google Analytics for our internal team only.
- To send optional onboarding tips, only if you turn them on in your profile. Every such email has an unsubscribe link.
Where data-protection law requires a legal basis, we rely on the performance of our contract with you (running your account), our legitimate interest in operating, securing and improving the service, and your consent for optional emails and analytics cookies.
Public and private content
A public repository can be viewed by anyone with the link, appears in search engines, and is available to AI assistants and other tools through our public endpoints (brand.json, llms.txt, the REST API, MCP and the asset API). Its content is served from a public storage bucket.
A password-protected repository shows its content only after the password is entered. A private repository is visible only to its members. Neither is listed publicly or served to AI tools. Files of these repositories are still stored under unguessable addresses in the same bucket; do not upload material that must stay confidential even if a direct file link were shared.
Owners can create API tokens that give programmatic access to a private repository. Tokens are stored as hashes and can be revoked at any time.
Statistics and tracking
Insights shown to repository members are aggregates: views over time, unique visitors, referrers, countries and download counts per asset. They do not identify individual visitors. If you are signed in and a member of the repository, your own visits are marked as member visits.
Google Analytics is used to measure overall product usage. It sets its own cookies and processes data under Google's privacy policy. You can block it with a browser extension or by disabling cookies; the service works without it.
Cookies and local storage
- Session: your sign-in session is kept in your browser's local storage so you stay signed in.
- Preferences: a small number of interface preferences (such as the selected theme) are stored locally.
- Analytics: Google Analytics cookies, as described above.
We do not use advertising cookies or cross-site tracking.
Service providers
We rely on a small number of providers who process data on our behalf under their own security and privacy commitments:
- Supabase: database, authentication and file storage.
- Vercel: hosting, content delivery and request logs.
- Resend: transactional email delivery.
- Google and GitHub: sign-in providers, when you choose them.
- Google Analytics: internal product analytics.
These providers may store data outside your country. We do not sell personal data and we only disclose it when required by law or to protect the service and its users.
Retention and deletion
- Account and repository data are kept while your account exists.
- Deleting a repository removes its content, versions, members, statistics and files. Deleting your account (Profile → Account → Delete account) disables it immediately and a background job removes your repositories, files and account data shortly after.
- Files that are no longer referenced by any published version are removed by a periodic cleanup.
- Contact messages and reports are kept for as long as needed to handle them.
- Hosting logs are retained for a short period as set by the provider.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to complain to a supervisory authority. You can see and delete most of your data yourself from your profile. For anything else, email us and we will respond within 30 days.
Security
Data is encrypted in transit. Access to production systems is limited to the people who operate the service. Passwords and repository passwords are hashed with bcrypt; API tokens are hashed with SHA-256. No system is perfectly secure, so keep a copy of your original files and tell us at once if you suspect a problem.
Children's information
GitBrand is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has created an account, contact us and we will remove it.
Changes to this policy
When we change this policy we update the effective date above. For material changes we will also notify account holders by email or with a notice on the site.
Contact
Questions or requests about your data: hi@gitbrand.com.