Privacy Policy

Effective date: August 11, 2026

CIAONEX ("the Company") values the privacy of Commitude ("the Service") users and processes personal data as described below, in compliance with South Korea's Personal Information Protection Act (PIPA), the EU General Data Protection Regulation (GDPR), and other applicable data protection laws.

1. Personal data we collect

When you sign in via GitHub OAuth, the Service collects the following information.

  • Your GitHub user ID, login name, email address, and profile image
  • Your GitHub access token (stored encrypted)
  • Information about the GitHub repositories you register (repository name, commit history, etc.)
  • Work timeline and session-summary data collected through the Claude Code/Codex real-time work connection (tool name, work status, permission mode, counts of attempted/completed/failed/denied commands and other tool, MCP, and network actions, observation coverage, inspected and changed-file paths relative to the project, sensitive-file access category and result, AI tool cost and token usage, etc.). When Claude denies an action before execution, only a coarse risk category and tool name are recorded. The default summaries are generated on-device. AI response bodies, source code, raw commands, secret values, absolute paths, working directories, and raw requests are not sent or stored. If file-path sharing is disabled, inspected, changed, and sensitive-file paths are also omitted. A detailed response is processed only if you explicitly enable it in your local credential, after secrets are removed and with a 500-character limit.
  • Pre-push local work statistics collected through the same connection (branch name, number of unpushed commits, number of files changed, lines added/removed) β€” commit messages and actual code diff content are never sent.
  • When Protection mode blocks a high-risk Push: the base/head commit SHA, project-relative changed-file paths, added/removed line counts, rule deductions, and approval/consumption times β€” source contents, commit messages, and secret values are not sent.
  • When you create an AI Work Verification Report: its title, an optional client display name, owner-authored client request, delivered outcome, developer checks and exclusions, a point-in-time snapshot of pre-push and AI activity metadata, and project-relative file paths only if you choose to disclose them β€” prompts, conversation text, source code, and actual secret values are not stored in the report.
  • When you create a public Build Feed: its random public identifier, language, expiry, and revocation time. On each request the public page composes only tool/file counts, scores, and risk from the last 7 days of existing AI work, Confidence, and Pre-push records. It does not store a separate event copy or publish prompts, conversation text, file paths, source code, raw commands, secret values, or absolute paths.
  • A customer/subscription identifier issued by our payment processor (Polar) when you subscribe β€” we never store your card number or other payment credentials ourselves.
  • Only if you separately consent to optional analytics cookies: visit statistics collected by Google Analytics/Tag Manager (device/browser info, pages viewed, time on page, approximate location, etc.)
  • Only if you separately consent to optional analytics cookies: a random identifier cookie and event data for the Service's own visit and conversion statistics β€” timestamps for landing visits, GitHub button clicks and successful authentication, Early Access applications, account creation, first project connection, and first analysis, together with CTA location, UTM campaign values, referring domain, and language. We do not store your IP address or raw User-Agent; the User-Agent is used only to classify human, crawler, social-preview, or uptime-monitor traffic and retain a recognized bot name.
  • A pseudonymous identifier used to connect conversion steps after GitHub authentication β€” generated by HMAC with a Company secret instead of storing the raw GitHub user ID, and linked to the internal member identifier after account creation.
  • When you contact support: your email address, inquiry and reply content, and files you attach
  • Security and operational audit records (type and time of login, logout, sign-up, account deletion, subscription or administrative action; IP address; and the minimum metadata needed)

2. Purpose of collection and use

Each processing activity relies on one of the following legal bases: performance of our contract with you, your consent (for opt-in features), or the Company's legitimate interests.

  • Authenticating and signing you in
  • Providing the dashboard based on your GitHub repositories' commit history
  • Explaining and enforcing Push Safety Gate decisions, and binding a one-time user approval to the exact blocked change before retrying a Push
  • Generating public web and PDF reports from the AI activity metadata you select, and allowing a client who receives the random link to view it during the selected access period
  • Displaying safe metadata from recent AI work, Confidence, and Pre-push activity in a public Build Feed that you explicitly enable and share by random link
  • Generating AI Commit Descriptions, Session Summaries, and Social Captions β€” only when you request the feature, in which case the feature-specific input (a commit message and partial code changes, work summaries and commit messages, or a generated session summary) is sent to Google Gemini.
  • Processing subscription payments and managing your plan
  • Receiving and answering support inquiries and reviewing attachments
  • Protecting the Service, preventing abuse, diagnosing incidents, and maintaining an operational audit trail
  • Only with your optional analytics-cookie consent: analyzing visits and improving the Service. Both first-party analytics and Google Analytics/Tag Manager remain off until consent, including sign-up conversion measurement.
  • Only with your optional analytics-cookie consent: aggregating page views and visitors, analyzing the conversion funnel and CTA conversion rates, and separating automated traffic

3. Retention period

Upon account deletion, we destroy the information below without delay. You can delete your account yourself from the "Delete account" option in the menu that appears when you click your profile at the bottom of the sidebar.

  • GitHub access token, email, and profile information: deleted immediately upon account deletion
  • Payment-related records: retained for 5 years as required by applicable consumer-protection and e-commerce law, then destroyed
  • HMAC pseudonym used to prevent repeated free-trial use: we do not retain the raw GitHub user ID for this purpose. Only a one-way pseudonym generated with a Company secret is retained while the Service operates, and it is not linked to your email, name, or profile.
  • Commit history, work timeline, AI-generated results, and other service usage records: retained until the relevant project or your account is deleted
  • Raw GitHub API responses and commit diff/schema lookup cache: retained for up to about 30 minutes; entries older than 30 minutes are physically deleted by a cleanup task that runs every minute
  • Blocked-Push approval records (commit SHA, relative file paths, line counts, deductions, and approval state): retained for 24 hours; records older than 24 hours are physically deleted by an hourly cleanup. Approval audit records contain neither file paths nor commit SHA and follow the security and operational audit retention below.
  • AI Work Verification Reports: public for the 7-, 30-, or 90-day period you select, or until you stop sharing; automatically deleted 30 days after expiry or revocation, and deleted immediately with the project or account
  • Public Build Feed settings: public for the 7-, 30-, or 90-day period you select, or until you stop sharing; automatically deleted 30 days after expiry or revocation, and deleted immediately with the project or account. The Feed composes safe statistics from existing project records on request and does not retain a separate public event copy.
  • Support inquiries, replies, and attachments: retained for 1 year after receipt, then automatically destroyed; inquiries linked to a signed-in member are destroyed when the account is deleted
  • Early Access application data not linked to an account: retained for 1 year after application, then automatically destroyed; account-linked application data is destroyed when the account is deleted
  • Security and operational audit records: retained for up to 1 year. Login/logout records and IP addresses are destroyed after 90 days; on account deletion, that member's identifier, IP address, and metadata are removed immediately.
  • Daily database backups for disaster recovery: kept in access-restricted private storage for 30 days after creation, then automatically deleted. Project/account deletions are fully removed from backups as those existing snapshots expire under this schedule.
  • Raw visit statistics logs (visitor identifier, page visited, time of visit): retained for 90 days, then automatically destroyed. After destruction, only aggregated, non-identifying daily counts (views and visitor counts per page) are kept for statistical purposes.
  • Marketing conversion events (random visitor identifier, pseudonymous identifier, event type/time/properties, and bot classification): retained for 1 year, then automatically destroyed. On account deletion, links to your member record and pseudonymous identifier are removed immediately regardless of the retention period, leaving only anonymous events.

4. Third-party disclosure and processing

The Service shares the minimum necessary personal data with, or entrusts processing to, the following third parties. See the next section for the countries these transfers go to.

  • GitHub, Inc. β€” login authentication and repository data lookup
  • Google LLC (Gemini API Paid Service) β€” feature-specific input is sent only when you request an AI Commit Description, Session Summary, or Social Caption. The app blocks calls unless an operator has confirmed that the project has an active billing account.
  • Google LLC (Analytics/Tag Manager) β€” visit analytics only after you consent to optional analytics cookies
  • Polar Software, Inc. β€” subscription payment processing
  • DigitalOcean, LLC β€” hosting the Service and database, and storing support attachments and backups
  • Plus Five Five, Inc. (Resend) β€” sending and receiving Service and support email
  • Functional Software, Inc. (Sentry) β€” error diagnosis. Default PII transmission is disabled, and request parameters and hook content are filtered.
  • Slack Technologies, LLC β€” operational alerts. Alerts do not include direct identifiers such as email addresses, GitHub logins, or inquiry content.

5. International transfers

Cross-border processing and storage essential to the core Service is limited to what is necessary to perform our contract with you and is disclosed here under Article 28-8(1)(3) of South Korea's PIPA. Optional analytics transfers occur only after separate consent. Data is encrypted in transit over HTTPS when you use the relevant feature or an operational event occurs; data that must be stored remains with the processor while needed to provide the Service. Our retention follows Section 3, and processors retain data only as required by our processing agreement and their applicable privacy policy. You can refuse optional transfers by rejecting or withdrawing analytics consent and by not requesting an AI feature, without losing core features. Refusing transfers necessary for GitHub authentication, hosting, email, or billing may make the relevant feature or Service unavailable. Provider contact details are listed below.

  • GitHub, Inc. β€” United States β€” login credentials and repository access tokens sent by HTTPS during sign-in or repository lookup β€” our copy is deleted with the account/project β€” contact: https://docs.github.com/site-policy/privacy-policies/github-general-privacy-statement
  • Google LLC β€” United States β€” feature-specific AI input sent when you request the feature, or visit data sent only after analytics consent and operator audit β€” Gemini Paid Service keeps limited abuse-prevention logs; Google Analytics user/event retention must be audited and set to 2 months before enablement β€” contact: https://policies.google.com/privacy
  • Polar Software, Inc. β€” United States β€” billing/subscription identifiers sent by HTTPS on payment or subscription changes β€” our legally required billing record is retained for 5 years; Polar's policy also applies β€” contact: privacy@polar.sh
  • DigitalOcean, LLC β€” Singapore β€” member data in the Service database/backups and support attachments transferred and stored over encrypted connections while you use the Service β€” Section 3 retention applies β€” contact: https://www.digitalocean.com/legal/privacy-policy
  • Plus Five Five, Inc. (Resend) β€” United States β€” email addresses, bodies, and attachments sent by HTTPS when email is sent or received β€” our support retention is 1 year; processor retention follows the processing agreement and policy β€” contact: privacy@resend.com
  • Functional Software, Inc. (Sentry) β€” United States β€” filtered error diagnostics sent by HTTPS when an error occurs, with default PII collection disabled β€” processed only as needed for diagnosis β€” contact: https://sentry.io/privacy/
  • Slack Technologies, LLC β€” United States β€” sign-up, inquiry, subscription, and deletion operational events sent by HTTPS with direct identifiers removed β€” operator workspace retention applies β€” contact: privacy@slack.com

6. Your rights

You may exercise the following rights over your personal data at any time. Contact us at the address below and we will respond without delay.

  • Right of access: confirm what personal data the Company holds about you
  • Right to rectification and erasure: request correction or deletion of inaccurate personal data
  • Right to restriction of processing: request that processing of your personal data be paused
  • Right to data portability: receive the personal data you provided in a structured, commonly used format, or have it transferred to another provider
  • Right to object: object to processing based on the Company's legitimate interests
  • Right to lodge a complaint with a supervisory authority β€” see Section 13 for contact details.

7. Minors

The Service is not directed at, and is not intended for use by, anyone under 18. If we learn that we have collected personal data from someone under 18, we will delete it without delay. If you believe someone under 18 has provided us with their personal data, please contact us at the address below.

8. Notice for California and other U.S. residents

The Company respects the rights afforded by U.S. state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA). The Company does not sell your personal information to third parties for monetary or other valuable consideration.

9. Source code access and security

Commitude looks up only the minimum information needed to render the dashboard and never permanently stores the full contents of your source files. Using your GitHub permissions, it retrieves commit information, changed files (diffs), and the schema files needed to build the Schema view. Raw GitHub API responses and commit, diff, and schema lookup data are held in a display cache for up to about 30 minutes, and expired entries are physically deleted every minute. The default login can access public repositories only; private repositories are accessible only after you approve additional permission. The Schema diagram (table/column structure), Hotspots (frequently changed file paths), and Confidence Score evidence (file paths behind risk signals) are stored per project so those features can operate, and are deleted with the project or account. Only structural information such as names, paths, and counts is stored, never original source-file contents. A public Build Feed only operates after you enable and share a random public URL. It composes the last 7 days of AI work, Confidence, and Pre-push metadata on request and displays the project name, tool and file/command/MCP/network counts, observation coverage, score/risk, and a short commit hash. It does not publish prompts, conversation or command text, file paths, source code, secret values, session identifiers, or path evidence behind Confidence signals. For a high-risk Push stopped in Protection mode, Commitude explains each rule deduction using project-relative file paths and changed-line statistics. It does not inspect or store source contents for this check. A logged-in project owner must explicitly approve the exact base/head SHA and file-statistics fingerprint; that approval expires after 10 minutes, works once, and cannot be replaced by an AI-set environment variable. The temporary approval record is retained for 24 hours, after which an hourly cleanup physically deletes it. AI Commit Description, Session Summary, and Social Caption use the Gemini API Paid Service only when you request the feature. Commit Description sends the commit message and up to 6,000 characters of changed code; Session Summary sends on-device work summaries and commit messages; Social Caption sends the already-generated session summary. The app blocks API calls in any environment where the operator has not confirmed an active Google Cloud billing account and Paid Service data terms. Generated results are deleted with the project or account. The default Claude Code/Codex connection summary and session summary are generated deterministically on-device. A summary may include counts of tool, command, MCP, and network actions, observation coverage, project-relative inspected and changed-file paths, and sensitive-file access categories and results. It does not include AI response bodies, source code, raw commands, or secret values; inspected, changed, and sensitive-file paths are omitted when file-path sharing is disabled. A detailed response is sent only if you explicitly enable it in the local setting, after secrets are removed and with a 500-character limit. Commitude does not use your source code to train its own AI models.

10. Security measures

  • Your GitHub access token and real-time hook credentials are stored encrypted in our database.
  • HTTPS (SSL) is used for all communication.
  • Access to personal data is restricted to the minimum needed to operate the Service.

11. Cookies and tracking technologies

Optional analytics cookies and first-party visit/conversion tracking operate only after you separately consent. Before consent, the Service does not load Google Analytics/Tag Manager or create its own visitor identifier or analytics events. You can reject analytics in the first-visit banner or allow and withdraw consent at any time under β€œAnalytics cookie settings” on this page. On withdrawal, the Service deletes Google Analytics cookies visible to the browser and stops further collection. Rejecting analytics does not affect sign-in or core features; blocking strictly necessary session and security cookies may affect the Service.

12. Data breach response

If a personal data breach occurs, the Company will notify the relevant authorities and affected users without undue delay, within the timeframes required by applicable law, and take appropriate remedial action.

13. Privacy contact and supervisory authorities

For any privacy-related questions, please contact us below. Name: Kevin Kang / Title: Representative / Email: kevin@ciaonex.com You may also file a privacy-related inquiry or complaint with a supervisory authority. South Korea: Personal Information Protection Commission (privacy.go.kr, 182 toll-free within Korea) Other countries: the data protection authority in your country of residence

14. Changes to this policy

This policy may be revised to reflect changes in law or our service. We will announce any material changes within the Service or by email.