Legal
Privacy Policy
Version 1.2 · Effective July 16, 2026
TheGitAI is an AI coding agent that reads and edits code on your machine. This policy explains, in specific terms, what leaves your computer, what we keep, for how long, and what we never store at all.
Plain-language summary (not a substitute for the full policy)
- We do not store your source code, your prompts, or your conversations on our servers. Saved sessions keep metadata only; your conversation history stays on your machine.
- To run a model, your prompt and the relevant code are sent to third-party AI providers. You choose which model runs.
- We keep your account details, your usage totals, and 30 days of request logs. We never store your IP address — only a salted, one-way hash of it.
- We don't sell your data, we don't use your code to train models, and we don't use Google Analytics.
- Email privacy@thegit.ai to delete your account.
1. Who We Are
TheGitAI is operated by Atlast Technologies ("we", "us", or "our"), which is the controller of the personal information described in this policy.
This policy applies to the TheGitAI command-line interface, our websites, dashboards, and related services (together, the "Service"). It forms part of our Terms of Service.
2. What We Do Not Collect
We do not store your source code, your prompts, or your conversations on our servers.
When you save a session, TheGitAI writes metadata only. The conversation history, the session summary, and the contents of your files are stripped out before anything is written to our database. Your conversation history and your repository index live on your machine, not ours.
We do not sell your personal information, we do not share it with data brokers or advertisers, and we do not use your code to train models.
3. What We Store
So that section 2 is not doing quiet work, here is everything we do keep.
Your account. Your email address, a hashed password, and the dates you signed up, verified your email, accepted the Terms, last signed in, and last used each login token. We keep this until you delete your account.
Usage totals. For each request: its cost, the model used, a session identifier, and a timestamp. We use this to enforce quotas and to show you your usage. It contains no prompt or code content.
Session metadata. For each saved session: its name, the project directory path, the git branch, the model, and a message count. This includes the file paths and shell commands the agent worked with — but never the contents of those files.
Request logs. For each request to our servers: your account identifier, a trace and request identifier, the session identifier, the endpoint, the status code, how long it took, your client's browser or CLI user agent, its operating system, architecture and version, and a salted one-way hash of your IP address. We never store your IP address itself. If the request fails we also store an error code, an error category, and the error message, along with limited diagnostic details about what went wrong. We automatically redact recognisable secrets before any of this is written, and we cap the size of what is stored — but an error message is free text, so we cannot promise it never contains a fragment of your input. These logs are deleted automatically after 30 days.
Deeper diagnostic telemetry — which does capture prompt and tool detail — is enabled only for our own internal admin accounts, under an explicit debug flag. It is never collected from customer accounts, and it is deleted after 4 days.
4. Service Providers & AI Processing
We use third-party service providers to operate, secure, host, authenticate, monitor, and deliver the Service, including providers that process relevant task context for AI inference. We may add, replace, or remove service providers as our infrastructure evolves. We do not publicly disclose confidential infrastructure, routing, vendor, or commercial information. Material changes affecting how personal information is processed will be reflected in this Privacy Policy where required by applicable law.
Relevant prompts, code excerpts, command output, and other task context may be transmitted to third-party AI processing and infrastructure providers solely as necessary to perform the requested task and operate the Service.
We use Cloudflare Turnstile on the account login form to distinguish people from abusive automated traffic. Cloudflare receives standard network, browser, and device signals needed to evaluate the challenge and may use strictly necessary browser storage for that security purpose. Turnstile does not receive your account password from us.
The AI model you select in TheGitAI identifies the organisation whose model answers your request — for example Anthropic, OpenAI, Google, Z.ai, MiniMax, or Xiaomi. You choose that model, and you can change it at any time.
Selecting a model determines which model answers you. It does not limit the providers described above from processing your request and task context as necessary to deliver the Service.
5. International Transfers
Our service providers are located in a number of countries, and some are outside your country of residence, including outside the European Economic Area. Where we transfer personal information internationally, we rely on appropriate safeguards — such as Standard Contractual Clauses or an equivalent legal mechanism — or on your explicit choice to use a particular AI model.
7. Your Rights & Deleting Your Account
Deleting your account. Email us at privacy@thegit.ai from your account's email address and we will delete your account and its data within 30 days. This removes your account record, your saved sessions, your usage history, your access tokens, and your request logs. We keep our security audit trail, but your email address is stripped out of it.
Your rights. Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict how we process it, and to withdraw consent. Email privacy@thegit.ai and we will respond within 30 days. We will not discriminate against you for exercising any of these rights. You may also lodge a complaint with your local data-protection authority.
Legal basis (EEA/UK). We process your account details and usage totals to perform our contract with you, and we process request logs under our legitimate interest in keeping the Service secure, available, and working correctly.
8. Children
The Service is not directed to children. You must be at least 18 years old, or the age of majority in your jurisdiction if higher, to use it. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
9. Changes to This Policy
We may update this policy from time to time. When we do, we will revise the version and effective date above and, where appropriate, provide additional notice. Your continued use of the Service after an updated policy takes effect constitutes your acceptance of it.
10. Contact
Questions about this policy, or want your data deleted? Contact us at privacy@thegit.ai. For legal notices, use legal@atlast.dev.