Legal

Privacy Policy

Version 1.2 · Effective July 16, 2026

TheGitAI is an AI coding agent that reads and edits code on your machine. This policy explains, in specific terms, what leaves your computer, what we keep, for how long, and what we never store at all.

1. Who We Are

TheGitAI is operated by Atlast Technologies ("we", "us", or "our"), which is the controller of the personal information described in this policy.

This policy applies to the TheGitAI command-line interface, our websites, dashboards, and related services (together, the "Service"). It forms part of our Terms of Service.

2. What We Do Not Collect

When you save a session, TheGitAI writes metadata only. The conversation history, the session summary, and the contents of your files are stripped out before anything is written to our database. Your conversation history and your repository index live on your machine, not ours.

We do not sell your personal information, we do not share it with data brokers or advertisers, and we do not use your code to train models.

3. What We Store

So that section 2 is not doing quiet work, here is everything we do keep.

Your account. Your email address, a hashed password, and the dates you signed up, verified your email, accepted the Terms, last signed in, and last used each login token. We keep this until you delete your account.

Usage totals. For each request: its cost, the model used, a session identifier, and a timestamp. We use this to enforce quotas and to show you your usage. It contains no prompt or code content.

Session metadata. For each saved session: its name, the project directory path, the git branch, the model, and a message count. This includes the file paths and shell commands the agent worked with — but never the contents of those files.

Request logs. For each request to our servers: your account identifier, a trace and request identifier, the session identifier, the endpoint, the status code, how long it took, your client's browser or CLI user agent, its operating system, architecture and version, and a salted one-way hash of your IP address. We never store your IP address itself. If the request fails we also store an error code, an error category, and the error message, along with limited diagnostic details about what went wrong. We automatically redact recognisable secrets before any of this is written, and we cap the size of what is stored — but an error message is free text, so we cannot promise it never contains a fragment of your input. These logs are deleted automatically after 30 days.

Deeper diagnostic telemetry — which does capture prompt and tool detail — is enabled only for our own internal admin accounts, under an explicit debug flag. It is never collected from customer accounts, and it is deleted after 4 days.

4. Service Providers & AI Processing

We use third-party service providers to operate, secure, host, authenticate, monitor, and deliver the Service, including providers that process relevant task context for AI inference. We may add, replace, or remove service providers as our infrastructure evolves. We do not publicly disclose confidential infrastructure, routing, vendor, or commercial information. Material changes affecting how personal information is processed will be reflected in this Privacy Policy where required by applicable law.

Relevant prompts, code excerpts, command output, and other task context may be transmitted to third-party AI processing and infrastructure providers solely as necessary to perform the requested task and operate the Service.

We use Cloudflare Turnstile on the account login form to distinguish people from abusive automated traffic. Cloudflare receives standard network, browser, and device signals needed to evaluate the challenge and may use strictly necessary browser storage for that security purpose. Turnstile does not receive your account password from us.

The AI model you select in TheGitAI identifies the organisation whose model answers your request — for example Anthropic, OpenAI, Google, Z.ai, MiniMax, or Xiaomi. You choose that model, and you can change it at any time.

Selecting a model determines which model answers you. It does not limit the providers described above from processing your request and task context as necessary to deliver the Service.

5. International Transfers

Our service providers are located in a number of countries, and some are outside your country of residence, including outside the European Economic Area. Where we transfer personal information internationally, we rely on appropriate safeguards — such as Standard Contractual Clauses or an equivalent legal mechanism — or on your explicit choice to use a particular AI model.

6. Cookies & Analytics

We set an essential httpOnly session cookie that keeps you signed in. It expires after 24 hours without an authenticated request. Cloudflare Turnstile may use strictly necessary browser storage while protecting the login form from automated abuse.

We use a privacy-preserving, cookieless analytics tool to count page views. It does not use cookies, does not fingerprint you, and does not track you across sites. We do not use Google Analytics, and we run no advertising or cross-site tracking scripts.

7. Your Rights & Deleting Your Account

Deleting your account. Email us at privacy@thegit.ai from your account's email address and we will delete your account and its data within 30 days. This removes your account record, your saved sessions, your usage history, your access tokens, and your request logs. We keep our security audit trail, but your email address is stripped out of it.

Your rights. Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict how we process it, and to withdraw consent. Email privacy@thegit.ai and we will respond within 30 days. We will not discriminate against you for exercising any of these rights. You may also lodge a complaint with your local data-protection authority.

Legal basis (EEA/UK). We process your account details and usage totals to perform our contract with you, and we process request logs under our legitimate interest in keeping the Service secure, available, and working correctly.

8. Children

The Service is not directed to children. You must be at least 18 years old, or the age of majority in your jurisdiction if higher, to use it. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

9. Changes to This Policy

We may update this policy from time to time. When we do, we will revise the version and effective date above and, where appropriate, provide additional notice. Your continued use of the Service after an updated policy takes effect constitutes your acceptance of it.

10. Contact

Questions about this policy, or want your data deleted? Contact us at privacy@thegit.ai. For legal notices, use legal@atlast.dev.