Privacy Policy
Effective Date: January 1, 2026 • Last updated: August 4, 2026
01. Information We Collect & Scope
Account Authentication Data: When signing in via GitHub OAuth, we receive basic public profile information (primary email address, full name, GitHub username, and avatar URL) required to create and authenticate your account.
Git Commit Metadata: When you authorize repository access, we fetch read-only commit metadata (commit SHA, author name, timestamp, commit message, pull request titles, and tags).
Usage & Operational Telemetry: We collect non-identifiable technical log data (browser user agent, IP address, page response times, and button interaction metrics) to monitor system uptime, prevent abuse, and optimize performance.
02. Zero-Store Source Code Commitment
AutoChangelog is architected around a strict zero-code-storage guarantee. We do not clone, download, host, or store your raw source code files or repository contents on our servers.
Code diffs and commit messages are streamed into isolated memory containers strictly during the changelog generation pipeline and are immediately purged upon completion. Furthermore, your data is never used to train public or third-party AI models.
03. How We Utilize Collected Data
We process your data strictly to deliver and maintain the core functionalities of the Service:
- Authenticating user logins and enforcing role-based project access control.
- Synthesizing git commit headers into human-readable release note drafts via our LLM pipeline.
- Processing subscription billing, invoice generation, and tier upgrade entitlements.
- Dispatching critical administrative alerts, security notices, and billing receipts.
- Rendering public project changelog pages and optional Explore Feed listings.
04. Trusted Sub-Processors & Data Sharing
We never sell, rent, or trade your personal information to third parties or advertising networks. We share minimal data exclusively with vetted enterprise sub-processors under strict Data Processing Agreements (DPAs):
- Artificial Intelligence Providers (Google Gemini / OpenAI): Commit messages and diff headers are transmitted via encrypted API endpoints to generate text summaries. Submissions are zero-retention and excluded from model training.
- Database & Authentication Infrastructure (Supabase): User account credentials, project configurations, and saved changelogs are stored in AES-256 encrypted PostgreSQL databases.
- Payment Gateway (Stripe): Payment processing is handled directly by Stripe. We never store credit card numbers or secret security codes on our servers.
- Hosting & Edge Delivery (Vercel): Frontend application assets and public changelogs are served via Vercel’s global Edge CDN network.
05. Data Security & Retention Protocols
We enforce rigorous administrative, technical, and physical security controls to safeguard your data. All data transmitted between your browser, GitHub, and our servers is encrypted using modern TLS 1.3 encryption protocols.
We retain account data for as long as your account remains active. If you delete a project or cancel your account, associated project metadata and saved changelogs are permanently deleted from our primary database within 30 days.
06. Your GDPR & CCPA Data Rights
Under applicable global privacy regulations (including GDPR and CCPA), you possess the following rights regarding your personal information:
- Right to Access & Export: Request a copy of all personal data held in our systems.
- Right to Deletion (Right to be Forgotten): Request permanent erasure of your account data.
- Right to Revoke Permissions: You can revoke GitHub OAuth access at any time directly through your GitHub Account Settings.
To exercise any of these privacy rights, contact our Data Protection Officer at privacy@autochangelog.org.
08. Contact Us
For any questions, concerns, or regulatory compliance requests regarding this Privacy Policy, please email us at support@autochangelog.org.