What we collect

  • GitHub data (read-only): pull request metadata (titles, numbers, authors, reviewers, review states, timestamps, repository names) from repositories you connect through the Gitboard GitHub App. We do not read repository code.
  • Slack data: your workspace's bot token (encrypted at rest), channel IDs you select for digests, and Slack user IDs you map for DM nudges.
  • Account data: your GitHub login, organization membership, and email as provided by GitHub OAuth.
  • Billing data (paid plans): handled by Stripe. We store your Stripe customer and subscription identifiers only; card details never touch our servers.

What we do with it

We render your pull-request board, send the Slack digests and DM nudges you configure, and enforce plan limits. Nothing else. We do not sell or share personal data with advertisers, and we do not train machine-learning models on your data.

Where it lives

Data is hosted on Hetzner servers in the EU. Subprocessors: Hetzner (hosting), Cloudflare (network), GitHub (source data), Slack (message delivery), Stripe (payments, paid plans only).

Retention and deletion

  • Disconnecting Slack immediately revokes and deletes the workspace token, digests, and user mappings.
  • Uninstalling the GitHub App or deleting your organization removes the organization's data from our production database.
  • Encrypted daily backups are retained for 30 days, after which deleted data is gone from backups as well.
  • You can request export or deletion at any time via [email protected].

Your rights

EU/EEA users have GDPR rights of access, rectification, erasure, restriction, portability, and objection. Write to [email protected]; we respond within 30 days. You may lodge complaints with your local supervisory authority (AZOP in Croatia).

We will announce material changes to this policy on this page at least 14 days before they take effect.