Trust center

Privacy Policy

This policy explains what Gitbeep processes to assess pull-request changes, route impact cards, and provide explicitly requested AI research.

Effective August 23, 2026 · Gitbeep is a product of 9626956 Canada Inc.

1. Who we are and what this covers

Gitbeep is operated by 9626956 Canada Inc. (“Gitbeep,” “we,” or “us”). This policy covers the Gitbeep website, account experience, and integrations. GitHub, Slack, Google, Stripe, Resend, and other third-party services have their own privacy policies for the data they process independently.

2. Information we process

  • Account and authentication data: name, email address, profile image, verification status, authentication-provider identifiers and tokens, sessions, IP address, and user agent.
  • Workspace configuration: workspace names, memberships and roles, Beep Rules, selected repositories and Slack channels, card-display settings, and configuration history.
  • GitHub data: App installation and repository identifiers; pull-request event, number, title, description, author, target branch, head commit, changed-file paths and statuses, and addition/deletion counts. We store the resulting impact card, signals, and suggested checks. The current pipeline does not persist full source files or diff patches.
  • Manual AI research data: when a paid workspace owner or administrator deliberately runs PR-risk research, we process the submitted question, bounded excerpts retrieved from our reviewed PR-risk research corpus, the generated answer, source identifiers and relevance scores, model identifier, and usage metadata. Gitbeep's D1 application cache stores a hash derived from the normalized question rather than the verbatim question, together with the answer and source metadata.
  • Slack data: workspace identifiers and name, bot identity, granted scopes, an encrypted installation token, channels available to the installed app, selected destinations, Slack message identifiers, and delivery status. The current product posts outbound cards and does not ingest Slack message history.
  • Billing data: Stripe customer, price, and subscription identifiers and subscription status. Payment-card details are collected and processed by Stripe, not stored by Gitbeep.
  • Operational and support data: signed-webhook identifiers and event types, processing status, delivery and provider-message identifiers, bounded error details, daily aggregate counts, emails you send us, and information needed to investigate support or security requests.

Google Sign-In data use, retention, and deletion: If you choose Continue with Google, Gitbeep uses the name, email address, profile image, email-verification status, Google account identifier, and authentication tokens Google provides only to authenticate you, create or access your Gitbeep account, and maintain your session—not for advertising. We retain this data while your Gitbeep account is active and delete it after a verified account-deletion request, subject to limited security, legal, and backup retention described below. You can revoke future access in your Google Account, but revocation does not itself delete data held by Gitbeep; request deletion by emailing accounts@gitbeep.com.

We do not currently use third-party advertising trackers or sell personal information.

3. How we use information

  • Authenticate users, create workspaces, and maintain sessions.
  • Connect selected GitHub repositories and Slack workspaces.
  • Assess pull-request metadata, apply customer-configured rules, deliver cards, and show delivery history.
  • Retrieve research material and generate an advisory answer when an authorized user explicitly requests AI research. This separate feature does not change deterministic risk ratings or trigger Slack delivery.
  • Operate subscriptions, send transactional email, answer support requests, prevent abuse, and troubleshoot failures.
  • Protect the service, enforce our terms, and meet legal obligations.

Where privacy law requires a legal basis, we generally rely on performance of our contract, our legitimate interests in operating and securing Gitbeep, consent where requested, and compliance with law.

4. Service providers and disclosures

We disclose data only as needed to operate Gitbeep, follow customer instructions, complete a business transaction, or comply with law. Current categories include:

  • Cloudflare for application hosting, networking, D1 data storage and recovery, isolated R2 operational archives, AI Search retrieval, and Workers AI generation.
  • GitHub and Slack for customer-authorized integrations.
  • GitHub, Google, and Resend for sign-in and transactional email, depending on the method you choose.
  • Stripe for checkout, subscriptions, payments, tax-related information, and fraud prevention.
  • Professional advisers, authorities, or a successor to our business when reasonably necessary and permitted by law.

These providers may process information in Canada, the United States, or other countries where they operate.

5. Retention and deletion

We retain current account, workspace, integration, and subscription state while an account is active and for as long as reasonably necessary to provide and secure the service, resolve disputes, and meet legal obligations. Recent operational detail remains in D1 for 30 days for completed webhook processing, 90 days for delivery attempts and impact-card operational metadata, and 180 days for sent or discarded billing-email operations. Sanitized terminal records then remain in an environment-isolated R2 archive for up to 365 days, while daily aggregate counts may remain with the workspace record. Completed webhook delivery identifiers remain as compact D1 replay-protection records. Failed and unresolved operations may remain available for investigation. OAuth state and one-time authentication codes expire automatically. Residual copies may remain temporarily in provider backups.

Manual AI research answers and their source metadata are eligible for Gitbeep's active D1 cache for up to seven days. Expired rows are not served and are removed in bounded maintenance batches. Deleting an active cache row does not immediately remove recoverable database history: Cloudflare D1 Time Travel may retain a copy for the separate recovery window available on our Cloudflare plan. Cloudflare may also retain or process data according to its applicable service terms and documented data-handling practices.

RAG questions, generated answers, retrieved excerpts, and source paths are not copied to the operational R2 archive; D1 retains only daily fresh, cached, and failed counts for operational reporting.

You can limit GitHub access to selected repositories, disable Beep Rules, or uninstall the GitHub or Slack App through those providers. To request account or workspace deletion, including its isolated operational-archive prefix, email accounts@gitbeep.com. We may need to verify your identity and authority over the workspace.

6. Security and your choices

We use administrative, technical, and organizational safeguards designed for the nature of the data, including signed-webhook verification, encrypted Slack installation tokens, limited integration permissions, secure cookies over HTTPS, and workspace-scoped authorization. No online service can guarantee absolute security. See our Security page for current controls and limitations.

Depending on your location, you may have rights to access, correct, delete, restrict, or export personal information, or object to certain processing. Contact us to exercise a right. You may also complain to your local privacy regulator.

7. Children, changes, and contact

Gitbeep is a business service and is not directed to anyone below the age of majority where they live. We do not knowingly collect children's personal information. We may update this policy as the service changes. Material updates will be posted here and, when appropriate, communicated through the service or email.

Questions or privacy requests: accounts@gitbeep.com.

Document status: This is Gitbeep's practical launch policy and describes how the service operates today. It is prepared for review by qualified counsel as the product and customer base grow.