Privacy Policy
Last updated: September 9, 2026
1. Who We Are
Gitsu is operated by Coduo Studio LLC, a company incorporated in Delaware, United States. Gitsu is a desktop and web client for GitHub Projects v2 — a keyboard-first interface for managing issues and projects stored in your GitHub account.
Contact us at support@gitsu.app for any privacy-related questions.
2. Our Privacy Principle
Your project data never leaves GitHub. Gitsu is a client application that reads and writes to your GitHub account through the GitHub API. We do not store, copy, or have access to your issues, labels, milestones, or project boards on our servers.
3. Information We Collect
What We Do NOT Collect
- Your project data (issues, labels, milestones, boards) — this stays in GitHub
- Passwords — authentication is handled entirely by GitHub OAuth
- Contact lists, address books, or files from your device
- Precise location data
Authentication Data
When you sign in with GitHub OAuth, we receive your GitHub username, email address, and profile information. This is used solely to authenticate you and provide the Service.
Payment Data
Payments are processed by Stripe. We do not store your credit card number or bank details. Stripe provides us with limited information such as the last four digits of your card, card brand, and billing country for record-keeping purposes.
Analytics Data
We use PostHog to measure how Gitsu is found and used. There are three separate streams, described below. All three are sent to PostHog’s EU region only. None of them creates a person profile, and every event carries a fresh random identifier, so two events cannot be joined to each other or back to you.
Website analytics
On this website, analytics is cookieless. It sets no cookies and stores nothing in your browser between visits, builds no personal profile, and does not identify you or track you across sites. We record which page was viewed, which call-to-action was selected, the deployment environment and site release, and any campaign parameters in the link you followed. IP addresses and geo-IP lookups are discarded on collection, so events are not tied to a person.
Campaign parameters are the utm_ values a marketing link can carry. We record them exactly as they appear in the link, because the raw value is what makes the measurement useful. We drop any campaign value that contains an email address, but we cannot reliably detect every kind of personal detail somebody might place in a link. If you follow a link whose campaign parameters contain personal information, that text is stored with the event as written. Removing the utm_ parameters from a link before opening it avoids this.
Conversion milestones
Our servers record four counts as they happen: a signup completed, a Checkout was created, a subscription became active, and a first paid conversion. These are counts, not a profile. Each is sent with a fresh random identifier and person processing switched off, and carries only campaign context and commercial detail such as plan, billing interval and currency. Your account id, GitHub identity, email, name, Stripe identifiers, IP address, user agent and request payload are refused by name and can never be attached. This measurement is part of operating the Service and is not optional.
Product analytics (optional, off by default)
The Gitsu desktop and web apps can send a small set of usage events so we can see which features are used and how large the Projects people work with are. This is off unless you turn it on. Nothing is sent until you give an affirmative answer, and the app re-checks that answer before every single event.
You are asked once during first-run setup, with the box unticked. You can turn it on or off at any time inside Gitsu under Settings, in the Privacy pane, using the Share product analytics switch. Turning it off silences the very next event. It does not delete events already sent.
When it is on, the apps send event names drawn from a fixed list, carrying only approved fields: which app you are using, which feature you used, the kind of view, an outcome, a sanitized error category, and integer counts and durations. Two allowlists enforce this in code, one for event names and one for field names, and an event carrying anything outside them is discarded whole rather than trimmed. Your issue titles, bodies, comments, labels, Project and repository names, search text, URLs, usernames and tokens are not approved fields and cannot be sent. There is no autocapture, no session recording, no automatic crash capture, and no link between these events and your account.
Your Analytics Choice
We store your answer so the desktop and web apps read the same setting: whether product analytics is on, which version of this notice you saw when you decided, and when you decided. It is held in our database against your numeric GitHub account id and is never sent to PostHog. If the notice changes materially, we ask you again rather than carrying an old answer forward.
4. How We Use Information
- Provide the Service — authenticate you and connect to your GitHub account.
- Process payments — manage subscriptions and lifetime purchases through Stripe.
- Improve the product — analyze aggregated, personless usage counts to guide development. Website analytics and conversion milestones run on all traffic; product analytics in the apps runs only if you turn it on.
- Communicate — respond to support requests and send essential service notices.
- Legal compliance — meet our obligations under applicable law.
We do not sell your personal information. We do not use your data for advertising.
5. Cookies
| Cookie | Purpose | Duration | Opt Out |
|---|---|---|---|
| Session | Authentication & session management | Session | Essential — required |
Our website analytics is cookieless — it sets no analytics or advertising cookies and does no cross-site tracking, so there is nothing to opt out of in your browser settings.
6. Third-Party Processors
| Provider | Purpose | Privacy Policy |
|---|---|---|
| GitHub | Authentication & project data access | Privacy Statement |
| Stripe | Payment processing | Privacy Policy |
| PostHog (EU region) | Website analytics, conversion milestones, and optional product analytics | Privacy Policy |
| Supabase | Database hosting for account, billing, and analytics-consent records | Privacy Policy |
7. Data Retention
- Project data — not stored by us. Lives in your GitHub account and is subject to GitHub’s retention policies.
- Authentication data — retained while your account is active. Removed upon account deletion.
- Payment records — retained as required by tax and accounting law (typically 7 years).
- Analytics data — website analytics, conversion milestones and product analytics are retained by PostHog for up to 12 months. Because these events carry no identifier that persists between them, we cannot look up, export or delete an individual visitor’s analytics events.
- Your analytics choice — one record per account, retained for as long as the account exists. There is no self-service control that deletes it; ask us using the contact route in section 8 and we will remove it.
8. Your Rights
GDPR (EEA/UK)
If you are in the European Economic Area or the United Kingdom, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Request erasure of your data
- Restrict processing of your data
- Data portability — receive your data in a structured format
- Object to processing based on legitimate interest
- Lodge a complaint with your local data protection authority
Our legal bases for processing are:
- Contract performance — authenticating you, connecting to your GitHub account, and managing your subscription.
- Consent — optional product analytics in the desktop and web apps. Nothing is sent unless you opt in, you may withdraw at any time in Settings under Privacy, and we ask again rather than carry an old answer forward when this notice changes materially. Withdrawal stops future events; it does not undo processing that already happened.
- Legitimate interest — cookieless website analytics and personless server conversion milestones, used to understand how Gitsu is found and whether signup and checkout work. Both are aggregate counts that are not linked to you, and we also rely on this basis to record and honour your product analytics choice.
- Legal obligation — tax and accounting records.
CCPA (California)
If you are a California resident, you have the right to:
- Know what personal information we collect and how it is used
- Request deletion of your personal information
- Request correction of inaccurate information
- Opt out of the sale or sharing of personal information
Gitsu does not sell or share personal information as defined by the CCPA.
How to Exercise Your Rights
Contact us at support@gitsu.app. We will respond within 30 days. We may ask you to verify your identity before processing your request.
9. International Transfers
Your data may be processed in the United States and the European Union. Analytics is a specific exception: all three analytics streams described in section 3 are sent to PostHog’s EU region and nowhere else. Each of the three refuses any destination other than the single allowlisted EU ingestion host, and drops the event rather than sending it elsewhere, so analytics data does not reach the United States. Where other data is transferred outside the EEA, we rely on Standard Contractual Clauses or other appropriate safeguards to ensure an adequate level of protection.
10. Children
Gitsu is not directed to anyone under the age of 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal data, contact us at support@gitsu.app and we will delete it promptly.
11. Security
We take reasonable measures to protect your information:
- All connections to Gitsu use TLS/HTTPS encryption in transit.
- Authentication is delegated to GitHub OAuth — we do not store passwords.
- Payment processing is handled entirely by Stripe — we do not store card details.
- Analytics data is hosted on PostHog’s EU infrastructure.
In the unlikely event of a data breach affecting your personal information, we will notify affected users and relevant authorities as required by applicable law.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted with a new “Last updated” date at the top of this page. We encourage you to review this page periodically.
13. Contact
For privacy-related questions, data requests, or concerns, contact us at support@gitsu.app. We aim to respond within 30 days.
See also our Terms of Service.