Privacy Policy

Last updated: July 26, 2026

1. Who we are

Gitship (“we”, “us”) is a social media scheduling service for developers, available at gitship.dev. It turns your GitHub activity into posts and publishes them to the social accounts you connect. This policy explains what data we collect, why, and what control you keep over it.

For anything privacy-related, contact us at privacy@gitship.dev.

2. Data we collect

Account data.

You sign in with GitHub. We receive your GitHub username, display name, email address, and avatar. We never see your GitHub password.

Repository activity.

For the repositories you explicitly select, we read metadata: commit messages, pull request titles, release notes, and repository names. We use this to draft posts about your work. We do not read, store, or train on your source code contents.

Connected social accounts.

When you connect X, LinkedIn, Threads, or Reddit, we store the OAuth access tokens those platforms issue, along with your public profile handle. Tokens are used for exactly one thing: publishing the posts you schedule, to the accounts you chose. We never post without an action you took.

Content you create.

Your drafts, scheduled posts, post history, and any images or video you attach are stored so the service can function.

Billing data.

Payments are processed by Stripe. We store your subscription status and Stripe customer reference; your card number never touches our servers.

Usage analytics.

We use Mixpanel (EU servers) to understand how the product is used — pages viewed, features clicked. We honor your browser's Do Not Track setting.

3. How we use your data

We use the data above to:

  • authenticate you and keep your session secure;
  • generate post drafts from your repository activity, including with AI assistance (see section 5);
  • publish posts to your connected accounts at the times you schedule;
  • show you analytics about your own posts' performance;
  • bill you for a paid plan, if you have one;
  • improve the product based on aggregate usage.

We do not sell your data, share it with advertisers, or use it for any purpose beyond running Gitship.

4. Where your data lives

Gitship runs on Vercel with its database and file storage hosted by Supabase in the European Union (AWS eu-west-3, Paris). Application servers run in the same region. If you are in the EU, your data stays in the EU.

5. AI-generated drafts

When Gitship drafts a post for you, the repository metadata described above (commit messages, PR titles, release notes) is sent to Anthropic's Claude API to generate the text. Anthropic processes this data as a service provider and does not train on it. Drafts are suggestions — nothing is published until you approve it.

6. Third parties we rely on

We share data only with the processors needed to run the service:

  • GitHub — sign-in and repository metadata;
  • X, LinkedIn, Meta (Threads), Reddit — publishing the posts you schedule, under each platform's own terms;
  • Supabase — database and media storage (EU);
  • Vercel — application hosting;
  • Stripe — payment processing;
  • Anthropic — AI draft generation;
  • Mixpanel — product analytics (EU servers).

7. Cookies

We use a session cookie to keep you signed in, and browser local storage for analytics preferences. We do not use third-party advertising cookies or cross-site trackers.

8. Data retention

We keep your data for as long as your account exists. Disconnecting a social account deletes its tokens immediately. Deleting your account deletes your profile, drafts, post history, media, and all stored tokens within 30 days, except for billing records we are legally required to keep.

9. Deleting your data

You can, at any time:

  • disconnect any social account from your dashboard — its access token is deleted on the spot;
  • revoke Gitship's access from GitHub, X, LinkedIn, Threads, or Reddit directly in each platform's settings;
  • request full account deletion by emailing privacy@gitship.dev from your account email — we confirm within 72 hours and complete deletion within 30 days.

10. Your rights

If you are in the EU/EEA or the UK, you have the right to access, correct, export, restrict, or delete your personal data, and the right to lodge a complaint with your local supervisory authority. Wherever you are, email us and we will honor the same rights. We respond within 30 days.

11. Security

All traffic is encrypted in transit (TLS). OAuth tokens and data at rest are encrypted by our hosting providers. Access to production data is limited to what is strictly needed to operate the service.

12. Changes to this policy

If we make material changes, we will update this page and note the new date below. Continued use of Gitship after a change means you accept the updated policy.