HomeLegalPrivacy Policy

Privacy Policy

Last updated: March 8, 2026

Introduction

Gitera ("we," "our," or "us") operates the Gitera platform at gitera.io (the "Service"). We are committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use and share it, and your choices regarding that information when you use our website and services.

By accessing or using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Service.

Information We Collect

Information You Provide Directly

  • Account information — name, email address, and GitHub username when you sign up
  • Organization data — GitHub organization name and membership details when you install our GitHub App
  • Payment information — billing details processed securely by our payment provider, Freemius; we do not store credit card numbers on our servers
  • Support communications — any messages, feedback, or requests you send us

Information Collected Automatically

  • GitHub Actions data — workflow run metadata, job statuses, runner information, and logs synced through your GitHub App installation
  • Usage analytics — pages visited, features used, click events, and session duration
  • Device & browser information — IP address, browser type and version, operating system, and screen resolution
  • Cookies & similar technologies — see the "Cookies & Tracking Technologies" section below

Information from Third Parties

  • GitHub — public profile information and organization membership when you authenticate via OAuth or install our GitHub App
  • Payment processor — transaction confirmations and subscription status from Freemius

How We Use Your Information

We use the information we collect for the following purposes:

  • Provide the Service — to operate, maintain, and deliver the features of the Gitera platform, including workflow analytics, cost monitoring, and security policy enforcement
  • Process payments — to manage your subscription, process transactions, and send billing-related communications
  • Communicate with you — to send threshold alerts, workflow failure notifications, product updates, and respond to support inquiries
  • Improve & optimize — to analyze usage patterns, diagnose technical issues, and develop new features
  • Ensure security — to detect, prevent, and address fraud, abuse, or security incidents
  • Legal compliance — to meet applicable legal obligations, resolve disputes, and enforce our agreements

Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases:

  • Performance of a contract — processing necessary to provide the Service you requested
  • Legitimate interests — analytics, security, and product improvement, where those interests are not overridden by your rights
  • Consent — where you have given explicit consent (e.g., marketing communications); you may withdraw consent at any time
  • Legal obligation — processing required to comply with applicable law

Cookies & Tracking Technologies

We use cookies and similar technologies to operate and improve the Service:

  • Essential cookies — required for authentication, session management, and security (cannot be disabled)
  • Analytics cookies — help us understand how users interact with our platform so we can improve it
  • Preference cookies — remember your settings (e.g., theme, dashboard layout)

You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent the Service from functioning properly.

Data Sharing & Third-Party Services

We never sell your personal data. We share information only in the following circumstances:

Service Providers (Sub-Processors)

We use the following third-party providers to operate the Service:

  • Supabase — authentication, database hosting, and real-time services
  • Freemius — payment processing and subscription management
  • GitHub — source code platform integration and OAuth authentication
  • Elasticsearch — log storage, indexing, and search
  • Upstash — Redis caching and rate limiting
  • Vercel — website hosting and edge delivery
  • Resend — transactional email delivery

Each sub-processor is contractually bound to process data only as instructed and under appropriate security and confidentiality obligations.

Other Disclosures

  • Legal requirements — when required by law, regulation, legal process, or governmental request
  • Safety & enforcement — to protect the rights, safety, or property of Gitera, our users, or the public
  • Business transfers — in connection with a merger, acquisition, or sale of assets (you will be notified in advance)
  • With your consent — when you explicitly authorize sharing with a third party

Data Retention

We retain your information only as long as necessary to fulfill the purposes described in this policy:

  • Account data — retained while your account is active and for up to 30 days after deletion request to allow for recovery
  • Workflow & log data — retained based on your subscription plan retention settings; deleted when you remove the integration or close your account
  • Payment records — retained for up to 7 years as required by tax and financial regulations
  • Analytics data — aggregated and anonymized data may be retained indefinitely for statistical analysis

Data Security

We take the security of your data seriously and implement robust technical and organizational measures:

  • Encryption in transit — all data transmitted to and from our Service is encrypted using TLS 1.2+
  • Encryption at rest — sensitive data stored in our databases is encrypted at rest
  • Access controls — role-based access with the principle of least privilege; employee access to user data is strictly limited and audited
  • Row-level security — database-level policies ensure users can only access data belonging to their organization
  • Regular security reviews — we conduct periodic security assessments and keep dependencies up to date
  • Incident response — we maintain an incident response plan and will notify affected users within 72 hours of a confirmed data breach

International Data Transfers

Our Service and sub-processors may process data in countries outside your country of residence, including the United States. When we transfer personal data outside the EEA or UK, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Sub-processors' certifications and compliance frameworks
  • Your explicit consent where applicable

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure — request deletion of your personal data ("right to be forgotten")
  • Data portability — receive your data in a structured, machine-readable format
  • Restriction — request that we limit how we process your data
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time
  • Opt-out of marketing — unsubscribe from marketing emails via the link in any email

To exercise any of these rights, contact us at privacy@gitera.io. We will respond within 30 days (or as required by applicable law).

California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know — what personal information we collect, use, and disclose
  • Right to delete — request deletion of your personal information
  • Right to opt-out — we do not sell personal information; no opt-out is required
  • Non-discrimination — we will not discriminate against you for exercising your privacy rights

GitHub App Permissions

When you install the Gitera GitHub App, it requests the following permissions in your GitHub organization. Each permission is required to deliver specific product functionality:

Repository Permissions

  • Actions (write) — to trigger, cancel, and re-run workflow runs, and to retrieve run data, job statuses, logs, and usage metrics
  • Administration (read) — to read repository settings required for configuration and access management
  • Contents (read) — to read workflow YAML files and action definitions stored in repositories
  • Deployments (write) — to create and update deployment records linked to workflow runs for deployment tracking
  • Metadata (read) — to list repositories and basic repository information (required by GitHub for all apps)
  • Pull requests (write) — to post PR comments with workflow insights, status summaries, and failure analysis
  • Repository hooks (write) — to create and manage webhooks that deliver real-time workflow events to Gitera
  • Workflows (write) — to enable, disable, and manage workflow files across repositories

Organization Permissions

  • Members (read) — to support team-based access control and user synchronization
  • Organization administration (read) — to read organization-level settings and policies for governance features
  • Organization API insights (read) — to access API usage data for cost and rate-limit monitoring
  • Organization custom org roles (read) — to read custom organization roles for role-based access management
  • Organization custom roles (read) — to read custom repository roles for fine-grained access control
  • Organization self-hosted runners (read) — to monitor self-hosted runner availability and usage across the organization

Subscribed Events

  • pull_request — to receive real-time PR events for PR insights, notifications, and status updates
  • workflow_run — to receive real-time workflow run events for monitoring, alerting, and failure analysis

You can review and revoke the GitHub App installation at any time from your GitHub organization settings at Settings → GitHub Apps.

Children's Privacy

Our Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected such data, please contact us at privacy@gitera.io.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify registered users via email for significant changes
  • Post a prominent notice on our website

We encourage you to review this Privacy Policy periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

If you are in the EEA and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection authority.

Have questions about our policies?

We're committed to transparency. Feel free to reach out if you need more information.

Contact Us