Legal
Privacy Policy
This policy explains how GitNative Ltd handles information when you use GitNative products, workspaces, integrations, MCP tools, agent skills, and plugins.
Effective 14 July 2026
1. Who this notice covers
This notice applies to GitNative websites, applications, workspaces, APIs, MCP tools, agent skills, plugins, support channels, and related services. GitNative Ltd is responsible for the personal information described here unless a separate customer agreement assigns a different role.
A workspace owner or organisation may also control information placed in its workspace. Contact that organisation first when your request concerns content it manages.
2. Information we collect
- Account and profile information, including name, email address, avatar, login provider identifiers, role, and workspace membership.
- Workspace content, including repositories and indexed metadata, tickets, projects, decisions, notes, meetings, transcripts, comments, incidents, releases, and files that users choose to connect or create.
- Integration and authentication metadata, including installation identifiers, granted scopes, key prefixes, token status, connection state, and audit events. Credentials are handled as secrets and are not intended for inclusion in prompts or logs.
- Service activity and device information, including requests, feature usage, approximate network information, browser or client type, timestamps, diagnostics, and security events.
- Commercial and support information, including subscription status, billing records supplied by payment providers, support conversations, and product feedback.
3. Agent, plugin, and MCP data
When an authorised agent uses GitNative, the service receives the tool request, the workspace and user identifiers needed to enforce access, and the minimum workspace context needed to return the result or perform the requested action. Tool results may be returned to the agent client you selected.
Local MCP clients authenticate with a developer key scoped to one user and workspace. Hosted integrations such as the ChatGPT plugin use GitNative’s browser-based OAuth connection instead. Hosted connections can be reviewed or revoked under Settings → API Keys → Connected agents. Do not put credentials, private keys, or unrelated personal information into prompts or tool inputs.
GitNative does not receive local repository files merely because a skill or AGENTS.md file is installed. Content is shared only when a connected integration, agent, or user sends it to the service.
4. How we use information
- Provide, secure, maintain, and troubleshoot accounts, workspaces, integrations, agent tools, and support.
- Index and retrieve authorised engineering context, coordinate requested workflows, and record auditable changes.
- Process subscriptions, communicate service information, prevent abuse, and enforce product limits and agreements.
- Understand aggregate product performance and improve reliability, accessibility, and user experience.
- Comply with legal obligations and protect users, GitNative, and the public.
5. Legal grounds
Depending on the relationship and location, we process personal information to perform a contract, pursue legitimate interests such as operating and securing the service, comply with legal obligations, or act with consent. Where processing relies on consent, it can be withdrawn for future processing.
6. When information is shared
- With members of the workspace according to its roles and permissions.
- With infrastructure, hosting, authentication, analytics, communications, payment, and support providers that help operate the service under appropriate contractual controls.
- With third-party integrations a user or workspace chooses to connect, according to the scopes and actions authorised for that integration.
- When required by law, needed to protect rights or safety, or connected to a merger, financing, acquisition, or transfer of business assets subject to appropriate safeguards.
7. International transfers
GitNative and its service providers may process information in countries other than the one where it was collected. Where required, we use recognised transfer mechanisms and contractual safeguards intended to protect that information.
8. Retention and deletion
We keep personal information for as long as needed to provide the service, meet contractual and legal obligations, resolve disputes, prevent abuse, and maintain security. Retention varies by data type, workspace settings, integration lifecycle, and applicable agreement.
Account or workspace deletion removes or de-identifies information from active systems subject to ownership-transfer rules, backup cycles, fraud prevention, legal holds, and records we must retain. Workspace owners may control retention of workspace content.
9. Security
We use administrative, technical, and organisational measures designed to protect information, including scoped access, encryption where appropriate, audit trails, and credential redaction. No service can guarantee absolute security. Rotate or revoke an exposed integration credential immediately and contact support.
10. Your choices and rights
- Review and update profile, workspace, integration, notification, and cookie settings available in the product.
- Request access, correction, deletion, restriction, objection, or portability where applicable.
- Withdraw consent for future processing when consent is the legal basis.
- Complain to the UK Information Commissioner’s Office or another competent data-protection authority.
11. Cookies and similar technologies
We use essential storage and cookies for authentication, security, preferences, and core operation. Optional technologies are controlled through the cookie preferences interface where required. Browser controls can also limit cookies, although essential features may then stop working.
12. Changes and contact
We may update this notice as the product, providers, or legal requirements change. Material updates will be identified by a new effective date and, when appropriate, an in-product notice.
For privacy questions or rights requests, email [email protected]. We may need to verify identity and workspace authority before completing a request.