Overview
GitPocket, developed and operated by 9byNight LLC, is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights regarding your information.
Data We Collect
GitHub OAuth Token
When you sign in with GitHub, we receive an OAuth access token that allows the app to access your GitHub data on your behalf. This token is:
- Stored securely in iOS Keychain on your device
- Never transmitted to our servers (we don't have servers)
- Only used to communicate directly with GitHub's API
- Removed immediately when you sign out
Cached Data
To provide a better offline experience, GitPocket caches some GitHub data locally on your device:
- Repository information and file contents
- Gist content
- Release information
- User profile data
All cached data is stored locally on your device and is automatically cleared when you sign out or uninstall the app.
AI Features
GitPocket includes optional, user-initiated AI features (such as summaries of issues, pull requests, and repositories, and comment drafts) that use a "bring your own key" (BYOK) model:
- What is sent: Only the content you explicitly choose to summarize or draft from — such as issue, pull request, or repository text — is sent to the AI provider you have configured (for example, Anthropic or OpenAI)
- When it is sent: Data is transmitted only when you explicitly trigger an AI action. Nothing is sent to AI providers automatically or in the background
- Your API key: AI features require your own API key for the provider you choose. Your key is stored securely in iOS Keychain on your device and is only used to make requests to that provider on your behalf
- Provider terms: Content you send is processed by that provider under its own terms of service and privacy policy. Please review your chosen provider's policies before use
If you never use AI features, no data is ever sent to any AI provider.
In-App Purchases
GitPocket is free to download and offers an optional "GitPocket Pro" auto-renewing subscription purchased through Apple's In-App Purchase system:
- Apple processes all payments: Purchases are handled entirely by Apple. GitPocket never sees or stores your payment details, billing address, or other payment information
- Subscription status: Your subscription status is determined on-device via Apple's StoreKit framework. GitPocket does not operate a server that tracks your purchases
- Managing your subscription: Subscriptions are managed and cancelled through your App Store account settings, and refunds are handled by Apple
For details on how Apple handles payment data, see Apple's Privacy Policy (opens in new tab).
Website Analytics
Our website (gitpocket.app) uses Vercel Analytics to collect anonymous usage data:
- Page views and visitor counts
- Referral sources
- General geographic region (country-level only)
- Device type and browser information
This data is anonymized, does not identify individual users, and is used solely to improve the website experience. For more information, see Vercel's Analytics Privacy Policy (opens in new tab).
Data We Do NOT Collect
- No App Analytics: The iOS app does not collect any usage analytics or telemetry data
- No Passwords: We never see or store your GitHub password. Authentication is handled via OAuth
- No Personal Information: We do not collect email addresses, names, or other personal data beyond what GitHub provides via their API
- No Location Data: We do not access or collect your precise location
- No Ad Tracking: We do not use any advertising or third-party tracking services
Third-Party Services
GitPocket uses the following third-party services:
- GitHub API: All data displayed in the app comes directly from GitHub's API. Your use of GitHub is subject to GitHub's Privacy Policy (opens in new tab)
- AI Providers (optional): If you configure and use AI features, content you explicitly choose to summarize or draft from is sent to your chosen AI provider under that provider's terms and privacy policy (see the "AI Features" section above)
- Apple App Store: Optional in-app purchases are processed entirely by Apple (see the "In-App Purchases" section above)
- Vercel Analytics: Our website uses Vercel Analytics for anonymous visitor tracking. See Vercel's Analytics Privacy Policy (opens in new tab)
Data Retention
- OAuth Token: Retained until you sign out of the app
- Cached Data: Cleared periodically based on iOS storage management and when you sign out
- App Deletion: All data is permanently removed when you uninstall GitPocket
Your Rights
GDPR (European Users)
If you are in the European Economic Area, you have the right to:
- Access your data (sign in to see cached data)
- Delete your data (sign out to remove all local data)
- Data portability (export your data via GitHub's own export tools)
CCPA (California Users)
California residents have the right to:
- Know what personal information is collected
- Delete personal information
- Opt-out of sale of personal information (we do not sell any data)
Data Security
We take security seriously:
- OAuth tokens and AI API keys are stored in iOS Keychain with hardware-level encryption
- All communication with GitHub uses HTTPS
- No data is transmitted to third parties, except GitHub API requests you initiate and content you explicitly choose to send to your configured AI provider
- The app runs entirely on your device — GitPocket does not operate any backend servers
Children's Privacy
GitPocket is not directed to children under 13. We do not knowingly collect information from children under 13. If you are under 13, please do not use this app.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any changes by updating the "Last updated" date at the top of this policy.
Contact Us
If you have questions about this privacy policy or your data, please contact us at: