Privacy policy
What we store, why, for how long, and how to make it go away. The short version: your GitHub profile, an encrypted token, your plans, logs and purchases, and a Stripe id — nobody else gets it, and one click deletes it.
[ OK ] effective 2026-09-15 · version 1.1
- > We store what we need to sign you in, push your repo and bill you. The list is in section 2.
- > We never read your other repositories, never sell data, and run no ad trackers.
- > Public previews send the username you type to GitHub through our server and are not linked to you.
- > “Delete account” in Settings erases everything we hold immediately. Stripe and Link keep the payment records the law requires them to keep.
> this summary helps you read the page; the numbered sections are the agreement
1. Who we are and what this covers
This policy explains how RetroFill (“we”, “us”) handles personal data when you use retrofill.dev and the RetroFill application (the “Service”). RetroFill is operated by a sole proprietor in Ontario, Canada, and is the controller of that data. We handle personal information in line with Canada’s PIPEDA and, where it applies to you, the GDPR, UK GDPR and CCPA/CPRA. This policy applies together with our Terms of Service.
2. What we collect, why, and for how long
Swipe the table sideways to see every column.
| Data | Why | Kept |
|---|---|---|
| GitHub profile: id, login, display name, avatar URL, primary email address, account creation date | Sign you in, author commits under your name, run the account-age safety check | Until you delete your account |
| GitHub OAuth token and its scopes | Read your contribution calendar; create, push to and delete the one repository you name | Until you delete your account or revoke access; encrypted at rest (AES-256-GCM) |
| Timezone offset and display name you set | Commit timestamps and the author name on commits | Until you delete your account |
| Plans: the days and commit counts you painted, seed, persona, repository name and template, custom commit messages | Build the repository, show History and undo a fill | Until you delete your account |
| Job records and logs: status, repository created, commit count, the execution log, undo state | History page, undo, support | Until you delete your account |
| GitHub App installation: the installation id, the GitHub account id it belongs to, and an encrypted token used only to create the repository you asked for | Push your fill to the one repository you gave us and nothing else | Until you remove the installation on GitHub or delete your account |
| Autopilot state: enabled, repository name and the ids of the repositories Autopilot created, persona, rhythm, last run, last error | Run Autopilot for you | Until you disable it or delete your account |
| Product events: signup, login, preview, checkout started, purchase, fill started/completed/failed, undo, autopilot commit | Understand what works, detect abuse, count public statistics (users, fills, commits — no names) | Until you delete your account |
| Stripe customer id, purchases and subscription status | Billing, entitlements, refunds | Until you delete your account. Stripe and Link keep the payment records the law requires them to keep |
| Referral code and, if you arrived through an invite link, the inviter's code | Grant the inviter their reward once (and take it back if the purchase is refunded) | Cookie: 30 days; the referral record: until you delete your account |
| Share cards: your GitHub login, the dates and commit counts of a finished fill, and the repo link if the repo is public | The public page at retrofill.dev/share/<id>, reachable by anyone who has the link, which you can share after a fill | Until you delete your account (undoing the fill marks the card as undone) |
| IP address of requests | Rate limiting of public endpoints; hosting provider request logs | In memory for about one minute for rate limiting; hosting logs per the provider's retention |
Public previews. When you type a username on the landing page without signing in, our server asks GitHub for that account’s public contribution calendar using a server-side token, caches the result for ten minutes under that username and date range, and returns it to your browser. We do not record who asked for which username. The plan you build in the preview is kept in your browser’s local storage only, until you connect.
What we write to GitHub. The repository we create on your account contains the files and commit messages generated for your plan (or the custom messages you supplied), authored with your display name and your GitHub noreply address. It is subject to GitHub’s privacy policy once it is on GitHub.
3. What we don't collect
- The contents of any repository other than the one we create for a job. Sign-in is read-only and the write scope is used only to create, push to and delete that repository.
- Your password. Sign-in is GitHub OAuth; we never see it.
- Card numbers. Stripe collects payment details directly.
- Advertising identifiers, cross-site tracking, or data from data brokers. We do not run third-party analytics or advertising scripts.
- We do not sell personal data and never have.
5. Processors and international transfers
- GitHub, Inc. — identity, contribution calendars and repositories, under your own agreement with GitHub.
- Stripe, Inc. and its Link service — payments, receipts and subscription management. Under Stripe Managed Payments, Link is the seller of record for your purchase and sends your receipt; Stripe holds your card details and your billing address for tax purposes.
- Railway Corp. (hosting) — runs the Service and stores its database on that host, in the United States.
- We do not send email ourselves today. Receipts come from Link; refund answers appear on the receipt in Billing.
These providers process data on our instructions under data-processing terms. Data may be stored or processed in the United States; where required, transfers rely on standard contractual clauses or an equivalent mechanism.
6. Legal bases
- Performance of a contract — everything needed to sign you in, build and push your repository, bill you and run Autopilot.
- Legitimate interests — security, rate limiting, abuse prevention, product analytics on our own events, and public aggregate statistics that identify nobody.
- Legal obligation — answering lawful requests, and Stripe’s and Link’s own duty to keep payment records.
- Consent — we do not currently send marketing email. If we ever do, it will be opt-in with an unsubscribe link.
7. Retention and deletion
- We keep your data for as long as your account exists. There is no separate log-retention period: deleting the account deletes the logs.
- Delete account, in Settings, removes your profile, tokens, plans, jobs, logs, Autopilot state, events and our copy of your purchase records immediately and permanently. Stripe and Link keep the payment records the law requires them to keep.
- Repositories on GitHub are not affected by deleting your RetroFill account. Use undo first, or delete them on GitHub, if you want them gone.
- Revoking the app in your GitHub settings invalidates the token we hold; we also delete tokens when you delete your account.
8. Your rights
Depending on where you live (including under the GDPR, the UK GDPR and the CCPA/CPRA), you have the right to access the personal data we hold about you, to receive a copy in a portable format, to correct it, to delete it, to restrict or object to certain processing, and not to be discriminated against for exercising these rights. You can delete everything yourself from Settings; for access, export or correction requests email us and we will respond within 30 days. You may also complain to your local data-protection authority. We do not sell or share personal data as those terms are defined under California law.
9. Security
- GitHub tokens are encrypted at rest with AES-256-GCM using a key held outside the database, and are never written to logs.
- All traffic is over HTTPS. Sessions are signed tokens in HttpOnly cookies.
- We request the smallest GitHub scopes that the next step needs, and only when it needs them.
- If we learn of a breach affecting your data, we will notify you without undue delay and in any case within 72 hours of confirming it.
10. Children
The Service is not directed at children and may not be used by anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy; the effective date at the top changes when we do. For material changes we will notify you by email or in the app before they take effect.
12. Contact
Privacy questions and requests: support@retrofill.dev.