GAGit Repository Agent

Privacy Policy

Last Updated: September 27, 2026

This Privacy Policy explains what information "Git Repository Agent" (the "Service") handles, how it is used, and the choices users have. By using the Service, the user agrees to the handling of information described in this policy.

1. Information We Handle

  1. Browser identifier. The Service does not use user accounts. A random identifier is generated in the user's browser and stored in LocalStorage to associate registered repositories and access permissions with that browser. The server stores only a one-way hash of this identifier. The selected display language is also stored in the browser.
  2. Repository information. For repositories the user registers, the Service retrieves information from GitHub, such as the README, file structure, configuration files, commit messages, issues, pull requests and code differences, and stores the resulting analysis, tasks, roadmap and history.
  3. GitHub access tokens. Tokens provided for private repositories are stored encrypted, are never displayed again, and are used only to read the corresponding repository.
  4. Contact form. The category, message and, only if the user chooses to provide it, an email address.
  5. Usage data. Google Analytics collects information such as pages viewed, device and browser type, approximate location and interactions, using cookies. Cloudflare Turnstile processes browser signals to distinguish people from automated programs.

2. How We Use Information

  1. To analyze repositories and to generate and update competitive analysis, tasks and roadmaps.
  2. To re-analyze repositories automatically when they are updated, and to provide sharing with team members.
  3. To prevent abuse, secure the Service and investigate problems.
  4. To understand how the Service is used and to improve it.
  5. To review requests and feedback and, where an email address was provided, to reply.

3. AI Processing

Repository information is sent to Google's Gemini models through Google Cloud Vertex AI for analysis. Before any text is sent, the Service automatically masks detected secrets and personal data (such as API keys, passwords, private keys, email addresses and phone numbers) and excludes the contents of sensitive files such as .env files and private keys. This masking is a best-effort safeguard and may not detect every secret, so users should not store secrets in repositories.

4. Third-Party Services

The Service relies on the following providers, each of which handles data under its own privacy policy:

  1. Google Cloud (Cloud Run and Vertex AI): application hosting and AI analysis.
  2. Vercel: hosting of the web interface.
  3. Turso: database.
  4. GitHub: source of repository information.
  5. Google Analytics: usage measurement.
  6. Cloudflare Turnstile: bot protection.
  7. Gmail (Google): delivery of contact form messages to the operator.

The operator does not sell personal information.

5. Sharing Within the Service

Repositories are visible only in the browser that registered them. If the owner creates a share link, people who open the link and join can view the analysis for that repository. For private repositories, members must provide their own GitHub token, and their access is verified with GitHub.

6. Retention and Deletion

Repository data is retained while the repository remains registered. When the owner unregisters a repository, its analyses, tasks, history, stored token and sharing information are deleted. Clearing the browser's site data removes the browser's access but does not delete data on the server; to request deletion in that case, please use the contact page. Contact form messages are retained as long as necessary to respond and improve the Service.

7. Security

The Service uses encrypted connections (HTTPS), encrypts stored GitHub tokens, restricts access to repositories by browser identifier, and uses bot protection on registration and contact forms. No method of transmission or storage is completely secure, and absolute security cannot be guaranteed.

8. User Choices

  1. Providing an email address in the contact form is optional.
  2. Users can block or delete cookies in their browser settings, or opt out of Google Analytics with the Google Analytics Opt-out Browser Add-on.
  3. Users can unregister their repositories at any time from the Settings tab.

9. Children

The Service is not directed to children under the age of 13.

10. Changes to This Policy

The operator may update this Privacy Policy at any time. The updated policy becomes effective when it is posted on this website.

11. Contact

For questions about this policy, please use the contact page.

← Git Repository Agent