Privacy Policy

Last updated: October 28, 2025

1. Introduction

bots-n-cats ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our GitHub App and associated services.

2. Information We Collect

2.1 GitHub Data

When you install bots-n-cats on your GitHub repositories, we collect:

  • Repository names and metadata
  • Webhook event data (event type, timestamp, actor)
  • Workflow and CI/CD status information
  • Pull request and issue metadata

We do NOT collect or access:

  • Source code contents
  • Commit messages or diff content
  • Code files or repository contents
  • Personal access tokens

2.2 Usage Data

We automatically collect certain information when you use our service:

  • Browser type and version
  • Device information
  • IP address (anonymized)
  • Usage statistics (page views, feature usage)
  • Error logs and diagnostics

2.3 Account Information

From your GitHub account, we collect:

  • GitHub username and profile URL
  • Email address (if public)
  • Organization memberships
  • Installation permissions

3. How We Use Your Information

We use the collected information for the following purposes:

  • Core Service Delivery: Generate musical representations of your development activity
  • Service Improvement: Analyze usage patterns to improve our audio algorithms
  • Security: Detect and prevent fraud, abuse, and security incidents
  • Communication: Send service updates, security alerts, and support messages
  • Analytics: Understand how users interact with our service
  • Compliance: Meet legal obligations and enforce our Terms of Service

4. Data Sharing and Disclosure

4.1 We Do Not Sell Your Data

We do not sell, trade, or rent your personal information to third parties.

4.2 Third-Party Service Providers

We may share data with trusted third-party service providers who assist us in operating our service:

  • GitHub: OAuth authentication and webhook delivery
  • Hosting Providers: Vercel, Railway (infrastructure)
  • Analytics: Vercel Analytics (anonymized usage data)
  • Error Tracking: Sentry or similar (error logs)

4.3 Legal Requirements

We may disclose your information if required by law, subpoena, or other legal process, or if necessary to:

  • Comply with legal obligations
  • Protect our rights or property
  • Prevent fraud or security issues
  • Protect the safety of users or the public

5. Data Retention

We retain your information for as long as necessary to provide our services:

  • Webhook Events: Processed in real-time, stored for 30 days
  • Audio Streams: Not recorded or stored (live-streamed only)
  • Account Data: Retained while your account is active
  • Usage Logs: Retained for 90 days

When you uninstall the app, we delete your webhook data within 30 days.

6. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in transit (TLS/SSL)
  • Encryption at rest for stored data
  • Secure webhook verification (HMAC signatures)
  • Access controls and authentication
  • Regular security audits

However, no method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

7. Your Rights

You have the following rights regarding your data:

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate or incomplete data
  • Deletion: Request deletion of your data (uninstall the app)
  • Export: Receive your data in a portable format
  • Opt-Out: Unsubscribe from marketing communications
  • Revoke Access: Remove app permissions via GitHub settings

To exercise these rights, contact us at privacy@bots-n-cats.live

8. Cookies and Tracking

We use essential cookies and similar technologies:

  • Session Cookies: Maintain your logged-in state
  • Analytics Cookies: Understand usage patterns (anonymized)
  • Preference Cookies: Remember your settings (volume, theme)

You can disable cookies in your browser settings, but this may affect service functionality.

9. Children's Privacy

bots-n-cats is not intended for users under 13 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

10. International Data Transfers

Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including:

  • Standard contractual clauses
  • GDPR compliance (for EU users)
  • Privacy Shield frameworks (where applicable)

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the new policy on this page
  • Updating the "Last updated" date
  • Sending an email notification (for significant changes)

Your continued use of the service after changes indicates acceptance of the updated policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us:

Summary: We collect minimal data needed to provide our service, never access your source code, don't sell your data, and give you full control over your information. 🐱