MyGitNotes

Privacy Policy

What MyGitNotes Pro collects about you, why, and what you can do about it.

1. Who is responsible

The data controller is 紅蔥頭工作室 (Shallots Studio), a business registered in Taiwan with unified business number 73046593. Contact: support@mygitnotes.com.

2. What we collect

  • Your GitHub identity: your numeric GitHub id and login name, received when you sign in with GitHub.
  • Authorization tokens: the tokens GitHub issues so the Service can reach the repositories you granted to our GitHub App. They are stored encrypted (sealed with a server secret), and a copy of the database holds no readable token.
  • The repositories you open: repository name, branch and when you last opened it, so the Service can offer them again.
  • Billing: payments are handled by Paddle, our merchant of record. Paddle collects your payment details. We receive a customer and subscription reference, your plan, its status and renewal dates. We do not see your full card number.
  • Optional features, only if you use them: API keys you add for AI providers, stored encrypted and never sent back to your browser; assets you upload to storage; and the files and commands in a hosted sandbox, which run in an isolated environment tied to you and a repository.
  • Usage records: the hours in which you used the Service, one record per hour and nothing about what you did, and when you first and last used it. We keep the hourly records for 400 days.
  • Repository facts: what GitHub reports about the repository you work in, namely whether it was made from our starter template, whether it is private, and its size. We ask GitHub at most once a day and keep the latest answer until you ask us to delete your account.
  • Page views: which kind of page of the Service or this site was opened (never the name of a notebook, folder or note), the site that linked to it, and a visitor code computed from your IP address and browser with a random value that we delete the next day. We store no IP address for this, cannot link your visits across days, and use no cookie. We keep page views for 400 days.
  • Technical logs: our hosting provider records requests, including IP address and time, to run and secure the Service.

3. What we do not do

We do not sell your data or show advertising, and we use no advertising trackers and no third-party analytics: the only page counts are our own, made without cookies (see section 2). We do not use your notes to train AI models, and we do not read your notes except as needed to run the feature you are using. Your notes themselves stay in your GitHub repositories; the Service handles them in memory while you work.

4. How we use data

To sign you in and keep you signed in, to provide the features you use, to bill and manage your subscription, to keep the Service secure and prevent abuse, to answer your messages, and to meet legal obligations.

5. Cookies and browser storage

We set one session cookie, which keeps you signed in and is limited to this site. Your theme and language choices are kept in your browser’s local storage. Neither is used for tracking.

6. Who processes data for us

Your data is therefore processed in Singapore and may be processed in other countries, including the United States, where these providers operate.

  • GitHub: sign-in and your repositories.
  • Vercel: hosting, serverless functions and, for Pro, sandboxes. Our functions run in Singapore.
  • Neon: the database that holds your account records, in Singapore.
  • Cloudflare: DNS and email routing, and asset storage where you use it.
  • Paddle: payments, invoices and tax.
  • AI providers you choose: they receive what a feature sends them, such as a commit message and a summary of the changed files for commit message polish, using your own API key and under their terms.

7. How long we keep it

Sign-in sessions expire on their own. Your repository list stays until you remove an entry or ask us to delete your account. When you ask, we delete your account records within 30 days, including your usage records and the facts about repositories that only you have in your list. Page views cannot be tied to you, so they stay until their 400 days are over. We keep billing records for as long as tax and accounting law requires. Server logs are kept for a short period.

8. Your rights

Under Taiwan’s Personal Data Protection Act and, where it applies to you, other data protection laws, you may ask to access, receive a copy of, correct or delete your personal data, or to restrict or object to its use. Write to support@mygitnotes.com and we will answer within a reasonable time.

You can also revoke the Service’s access to your repositories at any time under GitHub Settings → Applications.

9. Security

We seal stored credentials, limit what each part of the Service can reach, and use encrypted connections. No system is perfectly secure; if a breach affects you, we will tell you as the law requires.

10. Children

The Service is not for people under 16, and we do not knowingly collect their data.

11. Changes

We may update this policy and will change the date above. For a material change we notify you in the Service or by email.

MyGitNotes is operated by 紅蔥頭工作室 (Shallots Studio), Taiwan unified business number 73046593.