Last updated: July 3, 2026
GitAlert is owned and operated by YS Progress Inc., a corporation incorporated in Ontario, Canada ("we", "us", "our"), which is the data controller for the personal information described in this policy. GitAlert is an independent check that triages pull requests — including those opened by AI coding agents — and posts one neutral label without blocking your merge. This policy explains what data we collect, how the GitAlert GitHub App handles your code, who we share data with, and the choices and rights you have. By using GitAlert you acknowledge the practices described here.
We collect the following categories of data:
GitAlert connects to your Git provider through a dedicated application (the "GitAlert GitHub App"). It is separate from the account you sign in with. Here is exactly what it does and does not do with your code.
Permissions it requests
The App requests permission to read your pull requests and repository contents (so it can fetch the changes to analyse) and to write checks (so it can post its own neutral status on the pull request). It subscribes only to installation and pull-request events. Within those permissions, GitAlert never pushes commits, changes your branches, merges or closes pull requests, or posts comments — the only thing it creates is its own informational check-run.
What we store
For each installation, repository, and pull request we store metadata:
What we do not store
To produce a label we fetch the pull request’s diff and analyse it in memory. We do not store the diff or your source code. We do not store your GitHub access tokens (they are minted on demand, held only briefly, and never written to our database), and we do not store the full webhook payloads GitHub sends us — only the small set of fields listed above.
Dependency checks
When a pull request adds a new package, GitAlert checks whether that package name exists on the relevant public registry (PyPI for Python, npm for JavaScript). This sends the package name only — never your code — to that registry.
Sandbox runs (paid plans, optional)
On paid plans you can enable sandbox runs, where we build your project and run its existing tests to see whether the change actually holds up. This runs in an isolated, single-use environment operated by our sandbox provider (Daytona) that is destroyed after each run. The sandbox clones your repository over HTTPS, runs with a default-deny network policy that only permits your Git host and the public package registries, receives no secrets or credentials from us, and is fully separated from our own systems. On the free plan we never execute your code — triage is based only on reading the diff.
We use the data above only to:
We do not sell your personal data, and we do not use your source code or pull-request contents to train machine-learning models.
We do not sell or rent personal data. We share the minimum necessary with the service providers below, each of which processes it only to provide their service to us:
| Provider | What it processes | Purpose |
|---|---|---|
| GitHub, Inc. | Repository and pull-request metadata; PR diffs (in transit) | The GitAlert GitHub App integration |
| Stripe, Inc. | Billing details and payment card data | Subscription payments |
| Daytona | Your repository contents during a run (paid plans, when enabled) | Isolated sandbox build & test runs |
| PyPI, npm | New dependency names from your diff | Checking a package exists on the registry |
| Cloudflare, Inc. | IP address and request metadata; contact-form challenge | Network delivery, DDoS protection, anti-bot (Turnstile) |
| Pseudonymous usage analytics (consent only); sign-in profile if you use Google login | Analytics and authentication | |
| Microsoft (Clarity) | Pseudonymous usage and interaction analytics (consent only) | Product analytics |
| Tawk.to, Inc. | Messages and contact details you send in chat | Live support chat |
| Bunny (BunnyWay d.o.o.) | IP address needed to serve fonts | Privacy-friendly web fonts |
| Sign-in providers | Your profile and email at sign-in (GitHub, GitLab, Bitbucket, DigitalOcean, Google, Authentik) | Authentication |
| Email delivery provider | Your email address and message content | Transactional and account email |
Our Authentik single sign-on runs on our own infrastructure at key.gitalert.com. We may also disclose data where required by law or to protect our rights, users, or the security of the service.
We are based in Ontario, Canada, and several of our sub-processors are located in the United States and other countries. Using GitAlert therefore involves transferring your data across borders, including to the United States. Where the law requires it, we rely on appropriate safeguards (such as Standard Contractual Clauses) offered by those providers.
We protect your data with measures including:
No system is perfectly secure. In the event of a data breach that affects you, we will take reasonable steps to notify affected users and mitigate harm.
We keep personal data only for as long as it is needed for the purposes in this policy, or as required by law.
If you would like a specific retention period documented for your organisation, contact us and we can discuss it.
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent for analytics at any time (via the cookie banner). To exercise any of these rights, email us at [email protected]. You may also uninstall the GitAlert App from any repository at any time from your Git provider, which immediately stops new data from flowing to us. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
GitAlert is a tool for software developers and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
We may update this policy from time to time. The current version, with its “Last updated” date, is always posted on this page. Material changes will be reflected here.
For any question, request, or complaint about your privacy, contact YS Progress Inc. at [email protected]. We take privacy seriously and will do our best to help.