Privacy Policy

Last updated: August 12, 2026

1. Introduction

Commit+ ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we handle information when you use Commit+ ("the Application"), a native Git client for macOS.

We believe in transparency and want you to understand exactly what data we do and do not collect. Our guiding principle is simple: your data belongs to you, and we respect that completely.

2. Information We Collect

Guest use does not require a Commit+ account. If you choose to create or sign in to a Commit+ account, we process only the information needed to provide account, subscription, sync, and device-access services.

  • Firebase account information, such as your user ID, email address, display name, and sign-in methods.
  • Your server-owned Free or Pro entitlement and billing status. Payment details are handled by our billing provider and are not stored in the Application.
  • Settings, provider-account metadata, and repository bookmarks that you explicitly choose to sync. Provider credentials and access tokens remain in this Mac's Keychain.
  • A random UUID generated by Commit+ for this app installation, plus the generic Mac model family, macOS version, Commit+ version, device status, and created, last-seen, or revoked timestamps.

The random device ID is used only to enforce signed-in Mac limits and protect account sync access. It is stored in ThisDeviceOnly Keychain storage. We do not derive it from a serial number, MAC address, Apple account, IP address, or hardware fingerprint.

3. Repository Data

Repository contents and Git data—including your code, commit history, branches, and working-tree state—remain on your local machine. Commit+ accesses them only to display them within the Application and to perform Git operations you initiate. We do not upload, sync, or back up repository contents, local paths, Git history, remotes, credentials, or Git activity as part of the Commit+ account or device registry. A repository bookmark may contain the remote identity needed to reopen a repository when you explicitly enable that cloud feature, but never its working tree or history.

4. Usage Data & Analytics

Commit+ does not include any analytics SDKs, crash reporters, or usage tracking tools. We do not know how often you use the Application, which features you use, or how long you spend in the app. There are no product analytics, usage profiling, or fingerprinting mechanisms. Service providers may process standard operational request data, such as an IP address, to secure and operate their infrastructure; Commit+ does not add that data to your device registry. The website may use a country derived from the request, together with browser language or time zone, only to display regional pricing; this pricing-market selection is not stored in your account or device registry.

5. Third-Party Services

Commit+ uses Firebase Authentication, Cloud Functions, and Firestore for optional accounts, entitlement, device access, and sync. Polar provides subscription checkout and billing. Their processing is governed by their own terms and privacy policies.

Commit+ can also integrate with third-party Git hosting platforms, such as GitHub and GitLab, when you explicitly connect an account or perform a remote operation. Their processing is governed by their policies. Git/provider credentials stay in Keychain or your configured Git credential manager or SSH agent; Commit+ cloud sync stores only non-secret provider metadata when enabled.

6. Update Checks

The Application may periodically check for updates by making a request to a public GitHub Releases endpoint. This request contains no identifying information beyond what is standard in any HTTP request (e.g., your IP address may be visible to GitHub's servers). You can disable automatic update checks in the Application preferences at any time.

7. Security, Retention, and Your Controls

Commit+ restricts account and synced data to authenticated sessions and uses a server-owned active-device registry for official cloud access. No system is completely secure, so you should also protect your Mac, account, Git hosting accounts, and recovery methods.

You can sign out to release this Mac, revoke or replace another Mac, disable settings sync, and delete your Commit+ account. Revoked-device records may be retained with minimal status and timestamps while the account exists so that access decisions and account security remain consistent. Account deletion removes account-owned device, settings, bookmark, entitlement, and authentication data, subject to limited records a service provider must retain for legal, fraud-prevention, or billing obligations.

8. Children's Privacy

Commit+ is not directed at children under the age of 13. We do not knowingly collect any information from children.

9. Changes to This Policy

If we make material changes to this Privacy Policy, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.

10. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, please reach out to us at trantienthanh2412@gmail.com.