Privacy Policy

Last updated:

This Privacy Policy explains how GitRescue collects, uses, shares, and protects personal data when you visit our website, create an account, connect GitHub, purchase a subscription, or use GitRescue's hosted backup and restore service (the Service).

GitRescue is the controller of personal data used to run accounts, billing, security, support, and our website. When a customer uses the Service to back up personal data contained in its repositories, the customer decides why that data is processed and is normally the controller; GitRescue processes that data on the customer's behalf to provide the Service.

This policy does not govern GitHub, Stripe, or other third-party services you use directly. Their own privacy policies apply to their processing.

1. Personal data we collect

Information you provide

We collect information you give us, including:

  • your email address, password in hashed form, account preferences, and optional profile image;
  • multi-factor authentication settings and protected recovery-code records;
  • organization, membership, invitation, and authorization information;
  • billing choices and limited subscription, invoice, payment status, and transaction information received from Stripe (GitRescue does not store full payment card numbers);
  • support requests, feedback, and other messages you send us; and
  • instructions and information you provide when configuring, exporting, or restoring a backup.

Information from GitHub

When you install or connect the GitRescue GitHub App, we receive information allowed by the permissions you approve. This may include:

  • GitHub account and organization names, identifiers, profile images, and URLs;
  • repository names, identifiers, visibility, status, language, branches, refs, Git history, timestamps, and related metadata;
  • GitHub App installation details, repository selection, permissions, events, and connection status; and
  • short-lived access credentials needed to perform requested backup or restore operations.

Customer Content

The Service copies the contents and Git history of selected repositories to create encrypted backup artifacts. Repository content can contain personal data, confidential information, credentials, or other information chosen by the customer. GitRescue does not control what customers place in their repositories and does not routinely inspect Customer Content.

Usage, device, and security data

When you use the Service, we may automatically collect:

  • IP address, approximate location derived from IP address, browser and device information;
  • dates and times of access, pages viewed, referring pages, and interactions with the website;
  • sign-in, session, authentication, GitHub connection, backup, export, restore, alert, and account activity;
  • diagnostic information, request identifiers, error messages, performance data, and security events; and
  • cookies and similar technologies used for authentication, security, preferences, and analytics.

We receive this information from your browser or device, our systems, GitHub, payment and security providers, and people who administer an organization account.

2. How we use personal data

We use personal data to:

  • Provide the Service: create and manage accounts, connect selected GitHub repositories, make and retain backups, provide downloads and restores, send operational alerts, and provide support. We rely on performance of our contract with you.
  • Process subscriptions: create checkouts, administer plans, record payments, provide invoices, prevent payment fraud, handle cancellations, and process refunds where legally required. We rely on our contract and legal obligations relating to accounting and tax.
  • Secure and operate GitRescue: authenticate users, offer multi-factor authentication, keep audit records, prevent abuse, investigate failures, debug problems, enforce our Terms, and protect users, GitRescue, and others. We rely on our contract and legitimate interests in providing a reliable and secure service.
  • Communicate with you: send service messages, security notices, backup or permission alerts, support responses, and important policy updates. We rely on our contract, legal obligations, and legitimate interests. You can manage optional alert emails in your settings.
  • Understand and improve the Service: measure website use, monitor performance, fix problems, and improve features and usability. We rely on legitimate interests or consent where consent is required.
  • Comply with law and protect rights: respond to lawful requests, preserve evidence, enforce agreements, resolve disputes, report apparent child sexual exploitation where required or permitted, and prevent serious harm. We rely on legal obligations and legitimate interests.

Where we rely on legitimate interests, those interests are operating and improving a secure backup service, communicating with customers, preventing fraud and abuse, and protecting our legal rights. We consider the impact on individuals and do not rely on legitimate interests where their rights override those interests.

We do not sell Customer Content or personal data. We do not use Customer Content for advertising or to train general-purpose artificial intelligence models.

3. How we handle repository backups

GitRescue uses automated systems to fetch selected repositories and create encrypted backup artifacts. Hosted artifacts are encrypted in transit and at rest, including with per-backup envelope encryption. The Service decrypts a backup when an authorized user requests a download or restore.

We do not read repository contents as part of ordinary service delivery. Access is limited to automated processing and to authorized access where reasonably necessary to provide support with your permission, investigate a security or reliability issue, enforce our Terms, prevent serious harm, or comply with law.

The customer is responsible for ensuring that it has a lawful basis to place personal data in a repository and to have GitRescue back it up. If your personal data appears in a repository controlled by one of our customers, please contact that customer first. We will assist the customer with an appropriate request as required by applicable law.

4. When we share personal data

We share personal data only as needed for the purposes described in this policy:

  • Service providers: cloud hosting, encrypted object storage, encryption key management, database and application infrastructure, email delivery, analytics, security, customer support, and professional advisers. These providers process data for us under contractual restrictions appropriate to their role.
  • GitHub: to connect installations, fetch selected repositories, and perform exports and restores you request.
  • Stripe: to process payments, subscriptions, and billing portal access. Stripe receives payment and transaction information directly from you and acts under its own privacy terms for parts of that processing.
  • Organization administrators and members: account, repository, backup, restore, alert, audit, and billing information may be visible to authorized members of the same GitRescue organization according to their permissions.
  • Authorities and affected parties: where disclosure is reasonably necessary to comply with law or valid legal process; enforce our Terms; investigate fraud, abuse, prohibited content, or security incidents; protect a person's safety or rights; or establish, exercise, or defend legal claims.
  • Business transfers: in connection with a merger, financing, acquisition, reorganization, insolvency, or sale of all or part of the Service. We will require a recipient to respect this policy for personal data it receives.

We may share aggregated or de-identified information that cannot reasonably identify an individual.

5. International data transfers

GitRescue and its service providers may process personal data in countries other than the country where you live, including the United States and countries where our infrastructure providers operate.

Where data protection law requires it, we use a recognized transfer mechanism, such as an adequacy decision or contractual safeguards, and apply supplementary protections where appropriate. Contact us if you need more information about safeguards relevant to your data.

6. Retention

We keep personal data only for as long as reasonably necessary for the purposes described in this policy, including to provide the Service, comply with law, resolve disputes, maintain security records, and enforce agreements.

In particular:

  • repository backup versions are kept and pruned according to the retention schedule for the customer's plan;
  • temporary decrypted exports and restore credentials are kept only for the time needed to complete the requested operation and related security checks;
  • account, organization, repository metadata, and active audit information are generally kept while the account is open;
  • support and security records are kept for a reasonable period based on the sensitivity of the issue and the need to prevent repeat abuse or establish legal claims;
  • payment, invoice, transaction, and tax records are kept for the period required by applicable financial and tax law; and
  • analytics information is retained according to the settings of the relevant analytics service and is aggregated or deleted when no longer needed.

Closing an account deletes the account and backup data belonging to any personal workspace that closes with it from active systems. Data owned by an organization that continues to use GitRescue remains under that organization's control. Limited residual copies may remain temporarily in disaster-recovery systems or where we must retain information for security, fraud prevention, legal claims, financial recordkeeping, or compliance with law. Those copies are protected and removed or overwritten through normal retention cycles.

7. Security

We use technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. These include encryption in transit, encrypted repository artifacts at rest, access controls, secure authentication options, logging, and operational monitoring.

No system is completely secure. You are responsible for protecting your account credentials, using available security features, controlling who can access your GitRescue organization and GitHub installation, and telling us promptly about suspected unauthorized access.

8. Cookies and analytics

GitRescue uses cookies that are necessary for sign-in, session security, and core Service functions. We also use analytics services, including Google Analytics, to understand website traffic and product use. These tools may collect online identifiers, device information, pages visited, and interaction data, and may use cookies or similar technologies depending on their configuration.

You can control cookies through your browser. Blocking necessary cookies may prevent sign-in or other parts of the Service from working. Where applicable law requires consent for non-essential cookies or analytics, we will use those technologies on the basis of that consent.

GitRescue does not currently respond to browser “Do Not Track” signals, which are not interpreted consistently across services. We will honor legally required browser-based opt-out signals where they apply to our processing.

9. Your privacy rights

Depending on where you live and subject to legal exceptions, you may have the right to:

  • access personal data we hold about you;
  • correct inaccurate or incomplete data;
  • request deletion of personal data;
  • restrict or object to certain processing, including processing based on legitimate interests;
  • receive certain data in a portable format;
  • withdraw consent at any time where processing is based on consent; and
  • complain to your local data protection or privacy authority.

You may update some account information and notification preferences in the Service and may close your account in Settings. To make another request, use the support contact shown in Settings after signing in. We may need to verify your identity and authority before acting. You may use an authorized agent where local law permits it. We will not discriminate against you for exercising a privacy right.

You may object at any time to processing based on our legitimate interests, including direct marketing. GitRescue does not currently send third-party advertising, and operational messages necessary to provide or secure the Service are not marketing.

Rights are not absolute. For example, we may retain information where required by law or where needed to establish, exercise, or defend legal claims. If Customer Content is controlled by a GitRescue customer, we may direct your request to that customer.

10. Children

The Service is intended for adults and business use. You must be at least 18 years old to create an account. We do not knowingly collect account information from children. If you believe a child has created an account, contact us so we can investigate and take appropriate action.

Customer Content must never contain child sexual abuse material or facilitate the sexual exploitation of a child. If we become aware of apparent child sexual exploitation, we may preserve and report relevant information to the appropriate reporting body or authorities as required or permitted by law.

11. Changes to this policy

We may update this Privacy Policy as the Service, our providers, or applicable law changes. We will post the updated version and change the date above. If a change materially affects how we use personal data, we will provide reasonable advance notice through the Service or by email where practical.

12. Contact

GitRescue is responsible for this policy. For privacy questions, requests, or complaints, use the support contact shown in Settings after signing in.

You also have the right to contact the data protection or privacy authority where you live or work.