Privacy Policy
1. Data we collect
- Account identifiers: your GitHub login / username, or your Apple user identifier if you sign in with Apple.
- GitHub OAuth access token (GitHub sign-in only): stored encrypted at rest (AES-256-GCM) on our server, and used only to perform the likes (stars), follows, and bio actions you request on your behalf.
- Your activity in GitBrew: comments, saves (favorites), blocks, and reports you make, and the posts you publish.
- Product analytics via PostHog: event and usage data, device/app version, and an identifier linked to your GitHub login when you are signed in (Usage Data and Identifiers). Session replay is disabled.
- Umami page analytics on the website: privacy-friendly page-view statistics that use no cookies.
2. What we do not do
- No advertising.
- No tracking of you across other companies' apps or websites.
- No sale of your data.
3. GitHub actions and what stays where
Likes are GitHub stars and follows are GitHub follows, made with your own token — they live on GitHub. Saves and blocks stay only in GitBrew.
4. Content safety
We enforce a zero tolerance policy for objectionable content (see our Terms of Use). Reports you make are handled by automated moderation, which acts within 24 hours.
5. How long we keep data
We keep your data until you delete your account.
6. Account deletion
You can delete your account in the app under Settings/Account → Delete account, or on the web at /account → Delete account.
Deletion removes your account, credentials, tokens, comments, saves, blocks, and your published posts. It does not remove your GitHub stars or follows — those live on GitHub and can be undone on GitHub itself. If you signed in with Apple, we revoke the Apple token on deletion.
7. Children
GitBrew is not directed at children under 13, and we do not knowingly collect data from them.
8. Your rights
You can access your data in the app, and you can delete it at any time by deleting your account (see above). Depending on where you live, you may also have rights to access, correct, export, or erase your personal data — contact us to exercise them.
9. Hosting
Our servers run on Zeabur; media is served from Bunny CDN.
10. Contact
Privacy questions or requests: [TODO: contact email — Leo to provide]
隐私政策(中文)
1. 我们收集的数据
- 账户标识符:你的 GitHub 登录名/用户名;若使用 Apple 登录,则为你的 Apple 用户标识符。
- GitHub OAuth 访问令牌(仅限 GitHub 登录):在我们的服务器上以加密(encrypted)形式存储(AES-256-GCM),仅用于代为执行你请求的点赞(star)、关注和签名(bio)操作。
- 你在 GitBrew 中的活动:你发表的评论、收藏(saves)、屏蔽(blocks)和举报(reports),以及你发布的帖子。
- 通过 PostHog 进行的产品分析:事件与使用数据、设备/应用版本,以及在你登录时与你的 GitHub 登录名关联的标识符(使用数据与标识符)。会话回放(session replay)已禁用。
- 网站上的 Umami 页面分析:注重隐私的页面浏览统计,不使用任何 Cookie。
2. 我们不会做的事
- 没有广告。
- 不会跨其他公司的应用或网站追踪你。
- 不出售你的数据。
3. GitHub 操作与数据归属
点赞(Like)即 GitHub star,关注(Follow)即 GitHub follow,均使用你自己的令牌完成——它们存在于 GitHub 上。收藏与屏蔽仅保存在 GitBrew 中。
4. 内容安全
我们对不良内容实行零容忍(zero tolerance)政策(见使用条款)。你的举报由自动化审核处理,并会在 24 小时(24 hours)内采取行动。
5. 数据保存时长
我们保存你的数据,直到你删除账户为止。
6. 删除账户
你可以在应用内 设置/账户(Settings/Account)→ Delete account(删除账户),或在网页 /account → Delete account 删除你的账户。
删除将移除你的账户、凭据、令牌、评论、收藏、屏蔽以及你发布的帖子。它不会移除你的 GitHub star 或 follow——它们存在于 GitHub 上,可在 GitHub 上自行撤销。若你使用 Apple 登录,我们会在删除时吊销 Apple 令牌。
7. 儿童
GitBrew 不面向 13 岁以下儿童,我们也不会有意识地收集他们的数据。
8. 你的权利
你可以在应用中访问你的数据,并可随时通过删除账户来删除数据(见上文)。根据你所在地区,你可能还享有访问、更正、导出或删除个人数据的权利——请联系我们行使这些权利。
9. 托管
我们的服务器运行在 Zeabur 上;媒体文件由 Bunny CDN 提供。
10. 联系我们
隐私问题或请求:[TODO: contact email — Leo to provide]