§ PRIVACY  /  LAST UPDATED 2026·08·26

Privacy Policy

gitHtml is a local-first reader for GitHub repositories. Repository names, files, notes, favorites, and reading history stay on your device. We collect limited account, activity, purchase, and attribution data to operate the app and understand whether it is being used.

The short version

Information stored only on your device

Repository content is requested directly from GitHub over TLS using your GitHub authorization. It is not proxied through or retained by a gitHtml server.

Account and authentication

gitHtml uses a GitHub App for sign-in. The OAuth callback is handled by our Cloudflare Worker at go.githtml.com. During sign-in, the Worker exchanges the temporary GitHub code, fetches your GitHub numeric ID and username, creates or updates your gitHtml account, and issues an opaque gitHtml session.

Credentials are delivered to the app through a short-lived, single-use handoff code. The encrypted handoff package is retained for about two minutes and deleted when claimed or expired. GitHub access and refresh tokens are then kept in the iOS Keychain; Cloudflare does not retain them as account records. gitHtml stores only a hash of the server session token.

We retain your internal gitHtml account ID, GitHub numeric ID, GitHub username, account creation date, and last-active date. We do not ask GitHub for or store your email address.

Coarse activity information

To understand real usage without collecting repository content, our Cloudflare D1 database stores one daily summary per active account. It may record the date and app version for these events:

These summaries never include repository names, owners, URLs, file names or paths, file contents, notes, or text you enter. We use them to report registered, activated, 7-day active, and 30-day active users.

Purchases (RevenueCat)

Apple processes purchases through StoreKit. We use RevenueCat to validate receipts, provide entitlements, restore purchases, and report aggregate subscription performance. After sign-in, the app uses your internal gitHtml account ID as its RevenueCat user ID so purchases can follow your account across devices. Any earlier anonymous RevenueCat install is aliased to that account.

RevenueCat receives purchase and subscription information, an app user identifier, device and app metadata needed to provide its service, and limited install-attribution fields. Our Worker receives a minimized subset of RevenueCat webhook fields needed to determine paying-user status and commission records; it discards subscriber attributes such as email, phone number, display name, and arbitrary custom attributes.

RevenueCat's privacy policy: revenuecat.com/privacy.

Product analytics (TelemetryDeck)

We use TelemetryDeck to measure app launches, onboarding, GitHub sign-in, paywall, purchase, restore, and other bounded product-funnel events. Parameters are selected values such as a slide number, product tier, or fixed failure category—not free text or repository content.

After sign-in, gitHtml supplies the internal account ID as TelemetryDeck's custom user input. The TelemetryDeck SDK salts and hashes that value before transmission. We do not send your GitHub ID, username, repository names, file paths, notes, or email address to TelemetryDeck.

TelemetryDeck's privacy policy: telemetrydeck.com/privacy.

Advertising attribution (Tenjin)

We use Tenjin to measure whether installs and a small set of conversion milestones resulted from advertising, including campaigns on Meta and TikTok. Tenjin receives an install-level analytics identifier, device and app metadata, attribution and deferred-link information, and these bounded milestones: app opened, onboarding started or completed, paywall viewed, purchase completed, and trial or subscription started. Revenue events may also be sent from RevenueCat to Tenjin.

Tenjin does not receive your internal gitHtml account ID, GitHub ID, GitHub username, email address, repository names, file paths, notes, or document contents. Where required, the app asks for Apple's App Tracking Transparency permission before advertising identifiers are available. You can decline that request and still use gitHtml; privacy- preserving attribution such as SKAdNetwork may still operate.

Tenjin's privacy policy: tenjin.com/privacy.

Cloudflare and security

Our account and attribution APIs run on Cloudflare Workers and use Cloudflare D1 and KV. Secrets are stored as Worker secrets, session tokens are generated and hashed using Web Crypto, and structured operational logs are used to detect failures and abuse. Standard network metadata such as IP address, user agent, request path, and timing may be processed by Cloudflare for security and delivery.

Administrative reports contain aggregate account totals and a paginated GitHub username list. They are restricted to authorized operators and are used only to operate and evaluate gitHtml.

Retention

Scheduled cleanup jobs enforce these periods. Deleted D1 data may remain recoverable in Cloudflare's Time Travel backups for up to 30 days before aging out.

Your controls and deletion

If a network request cannot finish immediately, the app retains a minimal pending-revocation instruction in Keychain and retries later. Legally necessary transaction or commission records are retained only in anonymized form. You may also revoke gitHtml directly in GitHub under Settings → Applications.

Children

gitHtml is made for developers accessing their own repositories and is not directed to children under 13. We do not knowingly collect personal information from children under 13.

Changes to this policy

We will update this page when our data practices materially change. The date at the top reflects the latest revision.

Contact

Privacy or deletion questions: support@wavetechhq.com.