Privacy Policy

Last updated: August 9, 2026

1. Who We Are

Gitsu is operated by Coduo Studio LLC, a company incorporated in Delaware, United States. Gitsu is a desktop and web client for GitHub Projects v2 — a keyboard-first interface for managing issues and projects stored in your GitHub account.

Contact us at support@gitsu.app for any privacy-related questions.

2. Our Privacy Principle

Your project data never leaves GitHub. Gitsu is a client application that reads and writes to your GitHub account through the GitHub API. We do not store, copy, or have access to your issues, labels, milestones, or project boards on our servers.

3. Information We Collect

What We Do NOT Collect

  • Your project data (issues, labels, milestones, boards) — this stays in GitHub
  • Passwords — authentication is handled entirely by GitHub OAuth
  • Contact lists, address books, or files from your device
  • Precise location data

Authentication Data

When you sign in with GitHub OAuth, we receive your GitHub username, email address, and profile information. This is used solely to authenticate you and provide the Service.

Payment Data

Payments are processed by Stripe. We do not store your credit card number or bank details. Stripe provides us with limited information such as the last four digits of your card, card brand, and billing country for record-keeping purposes.

Analytics Data

We use PostHog (hosted in the EU) for product analytics. PostHog collects aggregated usage data such as pages visited, features used, device type, browser, operating system, and country-level location. This helps us understand how Gitsu is used and where to improve.

4. How We Use Information

  • Provide the Service — authenticate you and connect to your GitHub account.
  • Process payments — manage subscriptions and lifetime purchases through Stripe.
  • Improve the product — analyze aggregated usage patterns to guide development.
  • Communicate — respond to support requests and send essential service notices.
  • Legal compliance — meet our obligations under applicable law.

We do not sell your personal information. We do not use your data for advertising.

5. Cookies

CookiePurposeDurationOpt Out
SessionAuthentication & session managementSessionEssential — required
PostHogProduct analytics1 yearBlock third-party cookies in browser settings

We do not use advertising cookies or cross-site tracking.

6. Third-Party Processors

ProviderPurposePrivacy Policy
GitHubAuthentication & project data accessPrivacy Statement
StripePayment processingPrivacy Policy
PostHog (EU)Product analyticsPrivacy Policy

7. Data Retention

  • Project data — not stored by us. Lives in your GitHub account and is subject to GitHub’s retention policies.
  • Authentication data — retained while your account is active. Removed upon account deletion.
  • Payment records — retained as required by tax and accounting law (typically 7 years).
  • Analytics data — aggregated data retained by PostHog for up to 12 months.

8. Your Rights

GDPR (EEA/UK)

If you are in the European Economic Area or the United Kingdom, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Request erasure of your data
  • Restrict processing of your data
  • Data portability — receive your data in a structured format
  • Object to processing based on legitimate interest
  • Lodge a complaint with your local data protection authority

Our legal bases for processing are: contract performance (providing the Service), legitimate interest (analytics and product improvement), and legal obligation (tax and accounting records).

CCPA (California)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of your personal information
  • Request correction of inaccurate information
  • Opt out of the sale or sharing of personal information

Gitsu does not sell or share personal information as defined by the CCPA.

How to Exercise Your Rights

Contact us at support@gitsu.app. We will respond within 30 days. We may ask you to verify your identity before processing your request.

9. International Transfers

Your data may be processed in the United States and the European Union (PostHog’s EU infrastructure). Where data is transferred outside the EEA, we rely on Standard Contractual Clauses or other appropriate safeguards to ensure an adequate level of protection.

10. Children

Gitsu is not directed to anyone under the age of 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal data, contact us at support@gitsu.app and we will delete it promptly.

11. Security

We take reasonable measures to protect your information:

  • All connections to Gitsu use TLS/HTTPS encryption in transit.
  • Authentication is delegated to GitHub OAuth — we do not store passwords.
  • Payment processing is handled entirely by Stripe — we do not store card details.
  • Analytics data is hosted on PostHog’s EU infrastructure.

In the unlikely event of a data breach affecting your personal information, we will notify affected users and relevant authorities as required by applicable law.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be posted with a new “Last updated” date at the top of this page. We encourage you to review this page periodically.

13. Contact

For privacy-related questions, data requests, or concerns, contact us at support@gitsu.app. We aim to respond within 30 days.

See also our Terms of Service.