Privacy Policy

Last updated: June 19, 2026

PushNotes (“we”, “us”) generates changelogs from your GitHub commits. This policy explains what data we process, why, and the choices you have.

Data we collect

Account & GitHub. When you sign in with GitHub we store your GitHub user id, username, email, and avatar, plus an OAuth access token used to read your repositories. The token is encrypted at rest (AES-256-GCM) and never exposed to the browser.

Repository & changelog content. Repository metadata you connect, commit messages used for generation, and the changelogs and release summaries produced from them.

Newsletter subscribers. If a visitor subscribes to a public changelog, we store their email address and subscription status (double opt-in).

Analytics cookie. Public changelog pages set a first-party cookie pn_vid — a random identifier (never an IP or fingerprint) used only to count unique views and let a visitor toggle reactions. It is set only after you accept cookies.

Billing. Payments are processed by Stripe. We store a Stripe customer id and subscription status; we never see or store card numbers.

Legal basis

We process account and repository data to provide the service (performance of a contract), transactional emails and security on the basis of legitimate interest, and analytics cookies on the basis of your consent (which you can decline).

Third-party processors

We share data only with processors needed to run the service: GitHub (authentication & repositories), OpenAI (changelog generation from commit messages), Stripe (billing), Resend (transactional email), Neon (database), Vercel (hosting), and Sentry (error monitoring, with cookies and credentials stripped).

Data retention

Soft-deleted changelogs are purged after 30 days; webhook delivery logs and view events after 90 days; the generation cache after 7 days; and expired sessions are pruned continuously. Account data is kept until you delete your workspace.

Your rights

You can delete your workspace at any time from Settings, which permanently removes your repositories, changelogs, members, and associated data by cascade. Newsletter subscribers can unsubscribe via the link in any email; a workspace owner can permanently erase a subscriber’s record on request. Depending on your jurisdiction you may also have rights to access, correct, or port your data — contact us to exercise them.

Cookies

pn_session (essential, authentication), pn_consent (records your cookie choice), and pn_vid (analytics, only after consent).

Contact

Questions about this policy or your data: privacy@pushnotes.app.