RetroFill
Legal

Privacy policy

What we store, why, for how long, and how to make it go away. The short version: your GitHub profile, an encrypted token, your plans, logs and purchases, and a Stripe id — nobody else gets it, and one click deletes it.

[ OK ] effective 2026-09-15 · version 1.1

[ PLAIN LANGUAGE ]
  • > We store what we need to sign you in, push your repo and bill you. The list is in section 2.
  • > We never read your other repositories, never sell data, and run no ad trackers.
  • > Public previews send the username you type to GitHub through our server and are not linked to you.
  • > “Delete account” in Settings erases everything we hold immediately. Stripe and Link keep the payment records the law requires them to keep.

> this summary helps you read the page; the numbered sections are the agreement

1. Who we are and what this covers

This policy explains how RetroFill (“we”, “us”) handles personal data when you use retrofill.dev and the RetroFill application (the “Service”). RetroFill is operated by a sole proprietor in Ontario, Canada, and is the controller of that data. We handle personal information in line with Canada’s PIPEDA and, where it applies to you, the GDPR, UK GDPR and CCPA/CPRA. This policy applies together with our Terms of Service.

2. What we collect, why, and for how long

Swipe the table sideways to see every column.

DataWhyKept
GitHub profile: id, login, display name, avatar URL, primary email address, account creation dateSign you in, author commits under your name, run the account-age safety checkUntil you delete your account
GitHub OAuth token and its scopesRead your contribution calendar; create, push to and delete the one repository you nameUntil you delete your account or revoke access; encrypted at rest (AES-256-GCM)
Timezone offset and display name you setCommit timestamps and the author name on commitsUntil you delete your account
Plans: the days and commit counts you painted, seed, persona, repository name and template, custom commit messagesBuild the repository, show History and undo a fillUntil you delete your account
Job records and logs: status, repository created, commit count, the execution log, undo stateHistory page, undo, supportUntil you delete your account
GitHub App installation: the installation id, the GitHub account id it belongs to, and an encrypted token used only to create the repository you asked forPush your fill to the one repository you gave us and nothing elseUntil you remove the installation on GitHub or delete your account
Autopilot state: enabled, repository name and the ids of the repositories Autopilot created, persona, rhythm, last run, last errorRun Autopilot for youUntil you disable it or delete your account
Product events: signup, login, preview, checkout started, purchase, fill started/completed/failed, undo, autopilot commitUnderstand what works, detect abuse, count public statistics (users, fills, commits — no names)Until you delete your account
Stripe customer id, purchases and subscription statusBilling, entitlements, refundsUntil you delete your account. Stripe and Link keep the payment records the law requires them to keep
Referral code and, if you arrived through an invite link, the inviter's codeGrant the inviter their reward once (and take it back if the purchase is refunded)Cookie: 30 days; the referral record: until you delete your account
Share cards: your GitHub login, the dates and commit counts of a finished fill, and the repo link if the repo is publicThe public page at retrofill.dev/share/<id>, reachable by anyone who has the link, which you can share after a fillUntil you delete your account (undoing the fill marks the card as undone)
IP address of requestsRate limiting of public endpoints; hosting provider request logsIn memory for about one minute for rate limiting; hosting logs per the provider's retention

Public previews. When you type a username on the landing page without signing in, our server asks GitHub for that account’s public contribution calendar using a server-side token, caches the result for ten minutes under that username and date range, and returns it to your browser. We do not record who asked for which username. The plan you build in the preview is kept in your browser’s local storage only, until you connect.

What we write to GitHub. The repository we create on your account contains the files and commit messages generated for your plan (or the custom messages you supplied), authored with your display name and your GitHub noreply address. It is subject to GitHub’s privacy policy once it is on GitHub.

3. What we don't collect

  • The contents of any repository other than the one we create for a job. Sign-in is read-only and the write scope is used only to create, push to and delete that repository.
  • Your password. Sign-in is GitHub OAuth; we never see it.
  • Card numbers. Stripe collects payment details directly.
  • Advertising identifiers, cross-site tracking, or data from data brokers. We do not run third-party analytics or advertising scripts.
  • We do not sell personal data and never have.

4. Cookies and local storage

rf_session
A signed session token that keeps you signed in. HttpOnly, strictly necessary. Lasts until you sign out or it expires.
rf_oauth
A short-lived state token that protects the GitHub sign-in handshake. Strictly necessary; deleted when sign-in completes.
rf_ref
Set only if you arrive through a referral link, so the referrer can be rewarded once. 30 days.
rf_sidebar
Remembers whether you collapsed the app sidebar. Strictly necessary preference; one year.
retrofill:draft (local storage)
The plan you built in the landing-page preview, so it is restored after you connect. Stays in your browser; never sent to us until you execute it.

We use no analytics or advertising cookies, so there is no cookie banner: everything above is strictly necessary for the Service to work.

5. Processors and international transfers

  • GitHub, Inc. — identity, contribution calendars and repositories, under your own agreement with GitHub.
  • Stripe, Inc. and its Link service — payments, receipts and subscription management. Under Stripe Managed Payments, Link is the seller of record for your purchase and sends your receipt; Stripe holds your card details and your billing address for tax purposes.
  • Railway Corp. (hosting) — runs the Service and stores its database on that host, in the United States.
  • We do not send email ourselves today. Receipts come from Link; refund answers appear on the receipt in Billing.

These providers process data on our instructions under data-processing terms. Data may be stored or processed in the United States; where required, transfers rely on standard contractual clauses or an equivalent mechanism.

6. Legal bases

  • Performance of a contract — everything needed to sign you in, build and push your repository, bill you and run Autopilot.
  • Legitimate interests — security, rate limiting, abuse prevention, product analytics on our own events, and public aggregate statistics that identify nobody.
  • Legal obligation — answering lawful requests, and Stripe’s and Link’s own duty to keep payment records.
  • Consent — we do not currently send marketing email. If we ever do, it will be opt-in with an unsubscribe link.

7. Retention and deletion

8. Your rights

Depending on where you live (including under the GDPR, the UK GDPR and the CCPA/CPRA), you have the right to access the personal data we hold about you, to receive a copy in a portable format, to correct it, to delete it, to restrict or object to certain processing, and not to be discriminated against for exercising these rights. You can delete everything yourself from Settings; for access, export or correction requests email us and we will respond within 30 days. You may also complain to your local data-protection authority. We do not sell or share personal data as those terms are defined under California law.

9. Security

  • GitHub tokens are encrypted at rest with AES-256-GCM using a key held outside the database, and are never written to logs.
  • All traffic is over HTTPS. Sessions are signed tokens in HttpOnly cookies.
  • We request the smallest GitHub scopes that the next step needs, and only when it needs them.
  • If we learn of a breach affecting your data, we will notify you without undue delay and in any case within 72 hours of confirming it.

10. Children

The Service is not directed at children and may not be used by anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy; the effective date at the top changes when we do. For material changes we will notify you by email or in the app before they take effect.

12. Contact

Privacy questions and requests: support@retrofill.dev.