Effective: August 26, 2026
This policy explains how the hosted GitRank service processes information when you use the website, connect GitHub or another integration, or authorize the GitRank MCP connector from an AI client such as ChatGPT or Claude. A self-hosted GitRank deployment is controlled by its operator, whose policy applies instead.
The connector stores the OAuth client, selected organizations, and grants you approve. Read, configuration, background execution, and external communication are separate grants. Tool audit records contain the tool name, organization, outcome, duration, client, user, and request identifier; they do not contain tool payloads. Queued operations store the minimum identifiers and parameters required to execute the requested job and its result or error.
External messages and public changelog publication require an exact preview and short-lived, one-time confirmation. Revoking a connected AI app immediately blocks new tool access and cancels pending jobs.
We use information to provide and secure GitRank, synchronize the integrations you select, perform requested AI analysis, show product analytics, deliver notifications you authorize, troubleshoot the service, and comply with applicable obligations. We do not sell personal information or use private repository content for advertising.
Depending on the features you configure, information may be processed by infrastructure, database, authentication, AI, source-control, email, and messaging providers, including Cloudflare, Supabase, Anthropic, GitHub, Google, and Discord. Each provider processes data under its own terms and the permissions you grant. GitRank does not make a blanket regional-hosting or compliance-certification promise.
Records are retained while needed to provide the service, preserve security and audit history, or meet legal obligations. You can revoke connected AI apps in Account Settings, disconnect integrations in organization settings, and request account or hosted-data deletion through the contact page. Some limited backups and security records may remain for a reasonable period.
GitRank uses access controls, organization-scoped authorization, least-privilege connector grants, rate limits, and audit logging. No system is completely secure. Organization administrators should grant only the repositories, organizations, and connector capabilities required for their use case.
Contact GitRank through the contact page for privacy questions or requests. We may update this policy as the service changes and will revise the effective date on this page.