← Back

Privacy Policy

Last updated: March 2026

What we collect

When you sign in with GitHub, we collect your GitHub username, email address, and an OAuth access token scoped to read-only repository access. We do not store your code. We fetch commit messages (not code content) to generate changelogs, and we store those generated changelogs in our database.

How we use it

Your GitHub token is used solely to fetch commit history from repositories you explicitly connect. Commit messages are sent to Anthropic's API to generate changelog text. We do not sell, share, or use your data for advertising.

Data storage

Your data is stored in Supabase (PostgreSQL), hosted in the EU. GitHub access tokens are stored server-side only and are never exposed to the browser. You can delete your account and all associated data at any time by emailing us.

Third-party services

  • GitHub — OAuth authentication and commit data
  • Anthropic — AI changelog generation (commit messages only, no code)
  • Supabase — Database and authentication
  • Lemon Squeezy — Payment processing
  • Vercel — Hosting

Contact

Questions? Email us at hello@gitchangelog.dev