Privacy Policy
Last updated: July 17, 2026
1. Scope of this policy
This Privacy Policy explains how gitmatter handles information for the marketing website and the hosted application at gitmatter.com. It does not cover self-hosted deployments, where you run gitmatter on your own infrastructure and the gitmatter maintainers receive no data.
2. Controller and processor roles
For account and website data — the information needed to create and operate your account — gitmatter acts as the data controller. For the content you put into a matter (documents, prompts, chats, and outputs), gitmatter acts as a processor that handles that content on your behalf and under your instructions; you or your organization remain the controller. If you require a data processing agreement, contact us.
3. Self-hosted deployments
If you self-host gitmatter on your own infrastructure, database, object storage, and model provider keys, the gitmatter maintainers do not collect your account data, documents, prompts, chats, audit logs, or usage data. Your data handling depends on the systems, hosting providers, model providers, and configuration you choose for your deployment.
4. Hosted service notice
You are responsible for ensuring that anything you upload, submit, or store in the hosted service complies with your confidentiality, privilege, data-protection, and professional obligations.
5. Information we collect for the hosted service
When you use the hosted website or application, we may collect information needed to run it:
- Email address and account credentials
- Clients, matters, and the documents and files you upload
- Prompts, chat history, reviews, extractions, and AI outputs
- The audit spine: commits, authors, messages, field-level diffs, and blame
- Security-event and usage logs, settings, and preferences
- Error and diagnostic data (crash reports), with document content, keys, request bodies, and credentials stripped before they leave our servers
- Messages you send us by email
6. Legal bases for processing
Where data-protection law (such as the GDPR) applies, we process personal data on these bases: to perform our contract with you (operating your account and the Service); our legitimate interests (securing, troubleshooting, and improving the Service); your consent where we ask for it; and compliance with legal obligations. For content processed on your behalf, your organization is responsible for establishing the lawful basis.
7. AI providers, keys, and training
gitmatter does not train foundation models on your prompts, documents, chats, or outputs. When a feature runs, your document and prompt content is sent to the AI provider you select (Anthropic, Google, OpenAI, or OpenRouter) so the provider can generate a response. With bring-your-own-key, requests go out under your own provider account, and we request zero-data-retention handling where the provider supports it.
Third-party model handling, retention, logging, and training policies are governed by that provider's own terms and settings. Review the policy for the provider you use: Anthropic, OpenAI, Google, and OpenRouter. Provider keys are encrypted at rest; see the Security page for details.
8. Automated processing
AI features generate redlines, extractions, drafts, and summaries from your content. These are decision-support outputs, not automated decisions that produce legal or similarly significant effects on their own — a person reviews and decides. You are responsible for verifying Output before relying on it.
9. How we use hosted service information
- Provide, maintain, secure, and troubleshoot the service
- Operate product features and keep the audit spine accurate
- Respond to contact, support, or security messages
- Understand usage and improve the product
- Comply with legal obligations and enforce our terms
10. Information sharing and subprocessors
We do not sell your personal information. We share information only with subprocessors and partners that help us operate the Service — infrastructure and hosting, object storage, authentication, email, analytics, error monitoring, and the AI model provider you select — and only as needed to run it. We may also disclose information with your consent or at your direction, to comply with legal obligations or court orders, or to protect rights, safety, security, or property. A current list of subprocessors is available on request.
11. International data transfers
We and our subprocessors may process information in countries other than yours. Where required, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses — for transfers of personal data outside your region.
12. Document storage region
For new hosted organizations, an administrator selects an immutable document object-storage target during onboarding. EU selections route document files to our Cloudflare R2 bucket configured for the European Union jurisdiction. US and Australian selections route document files to their respective regional object-storage targets. This control applies to document files only; account data, audit logs, backups, and AI-provider processing may have separate locations and are not covered by this selection.
Organization administrators can download a record of the selected target and the associated application audit event from Settings. It should be retained with the applicable provider configuration evidence when assessing or documenting data-residency requirements.
13. Data security and breach notification
We use technical and organizational measures designed to protect information in the hosted service; see the Security page for our posture. No method of transmission or storage is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and any relevant authority as required by applicable law.
14. Data retention and deletion
Deleted documents are purged after a soft-delete window; aged audit logs and revoked tokens are purged on a schedule. Organization admins can export all tenant data at any time, and deleting your account removes your records, except where a longer retention period is required or permitted by law.
15. Your rights and how to exercise them
Depending on your location, you may have rights to:
- Access and receive a copy of your data
- Correct inaccurate or incomplete data
- Request deletion of your data
- Object to or restrict processing
- Data portability
- Withdraw consent where processing is based on consent
To exercise a right, email us at the address below; we will respond within the time required by applicable law. If we process your content on behalf of your organization, we will direct your request to that organization. You also have the right to lodge a complaint with your local data-protection supervisory authority.
16. Cookies
We may use cookies and similar technologies to operate the website, keep you signed in, and understand usage. You can control cookies through your browser settings.
17. Children's privacy
The service is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from anyone under 18.
18. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the date above.
19. Contact
For privacy questions or to exercise a right, email contact@gitmatter.com.