Privacy Policy
Effective date: September 10, 2026
Overview
GitSync.md ("the App") is an iOS application developed by Cody Bontecou that provides Git version control on iPhone and iPad. Your privacy matters. This policy explains what data the App accesses, how it's used, and what is never collected.
Core App and Optional Background Sync
The core Git client sends repository contents and Git credentials directly from your device to the Git provider you select. Background Sync runs entirely on your device: it uses the same in-app Git engine and your existing credentials, so repository names, URLs, contents, local file paths, and Git credentials are never sent anywhere except directly to your configured Git provider during a normal fetch or push. We do not receive or store repository contents, local file paths, Git credentials, advertising identifiers, location, contacts, or photos.
If you explicitly enable Background Sync for this installation (it is included with the app purchase), that one opt-in covers all current and future cloned or managed repositories unless you exclude one in its settings. You then control automatic fast-forward pulls and automatic publishing independently; publishing remains default-off. Push-only mode fetches remote metadata for safety but does not update the worktree. Reconciliation attempts run when the app is activated in the foreground and when iOS grants discretionary background processing time; Apple and iOS do not guarantee background delivery, timing, frequency, or execution. Background Sync has no server component: no relay, no push notification registration, and no Background Sync data is stored anywhere off your device.
Optional Push Sync
Push Sync is separate from Background Sync and off by default. If you enable it, the App registers an opaque device key, normalized names of cloned GitHub repositories, your Apple Push Notification service token and environment, and a last-registration time with our first-party Cloudflare relay. You then connect the GitSync.md GitHub App once for each personal account or organization and choose all or selected repositories. The relay retains the GitHub installation ID, account ID/login/type, numeric ID of the authorizing owner, repository-selection mode, installation status, and connection time. Repository and installation route indexes contain those same routing identifiers. Neither the App nor relay exposes a per-repository webhook secret to you.
The GitHub App has read-only Contents permission so GitHub can send push events; the relay does not use that permission to fetch repository files. Organization installations also have read-only Members permission solely to prove that the connecting user is an organization owner and to revalidate that authority before later deliveries. During connection, the relay exchanges a one-time OAuth code using PKCE, uses the resulting GitHub user token only for that ownership proof, never stores or returns the token, and immediately asks GitHub to revoke it. Periodic organization revalidation similarly uses a narrowly scoped, short-lived installation token and immediately requests its revocation. If revocation fails, the unretained token expires under GitHub's policy.
GitHub's signed webhook payload transiently passes through the relay and can contain repository URLs, commit messages, changed-file names, and sender/author data supplied by GitHub. The relay does not persist, application-log, or forward those descriptive fields. It reduces an eligible branch push to repository name, branch, target commit SHA, commit count, and an opaque delivery hint for APNs. It never receives local file contents, local paths, or device Git credentials, and it never calls GitHub to retrieve file contents.
A background attempt runs only for a matching branch included in Background Sync with automatic pull enabled; separately enabled publishing keeps the normal fail-closed rules. Tapping remains an explicit on-device pull-only fallback. Device records and route indexes expire 90 days after the last App registration, while enabled installations normally refresh sooner. Connection state expires after 15 minutes, owner-proof caches after five minutes, delivery throttles after the configured short window, and HMAC-pseudonymized per-IP abuse-prevention buckets after one hour. Turning Push Sync off makes a best-effort immediate unregister request and disables future device routing. The GitHub App is a separate GitHub-controlled installation: it can continue sending signed events that the relay discards after routing checks until you uninstall it through GitHub; the App provides a link to GitHub's installation settings even while Push Sync is off. Alert delivery and background execution are both best effort and depend on GitHub, Cloudflare, APNs, and iOS scheduling.
Data Stored on Your Device
The following data is stored locally on your device:
- Git author name and email — Used solely for Git commit metadata. You provide these when configuring the App.
- Authentication tokens — GitHub OAuth tokens or Personal Access Tokens are stored in the iOS Keychain, which is encrypted at rest by the operating system.
- Repository data — Cloned repositories, commit history, and working files are stored in the App's sandboxed container and iOS File Provider directory.
First-Party Onboarding Analytics
The App sends limited onboarding events to our Cloudflare Worker and D1 database so we can understand whether setup succeeds. We retain an app-generated installation identifier, opaque event identifier, event name, app version/build/platform, coarse onboarding step, coarse authentication method/outcome, whether you selected the default or a custom save location, a coarse error category, and event time. This analytics service rejects repository names or URLs, file or folder paths, branch names, author names or email addresses, GitHub usernames, credentials, file contents, free-form text, raw device identifiers, user agents, and raw request IP storage. These events are used for product analytics and troubleshooting, not advertising or cross-app tracking. Event rows are scheduled for deletion after 90 days. The App's settings can open a private data-request email draft containing the opaque installation identifier support needs; review it before sending and never post that identifier publicly.
Website Analytics
The GitSync.md website, including this policy, conditionally loads Cloudflare Web Analytics after a first-party analytics gate allows it. Cloudflare Web Analytics provides aggregate page-view, performance, country, host/path, referrer, device-type, browser, operating-system, and navigation-type measurements. Cloudflare states that this service does not track individual users across its customers' sites and does not use the website analytics for advertising. This website measurement is separate from the iOS App's onboarding analytics.
Third-Party Services
GitSync.md communicates directly with GitHub's servers using the Git protocol and GitHub's API. When you authenticate and perform Git operations (clone, pull, push), data is exchanged between your device and GitHub according to GitHub's Privacy Statement.
Background Sync performs no third-party communication beyond normal Git traffic to your configured provider. Separately enabled Push Sync uses GitHub Apps/webhooks, our Cloudflare Worker and KV storage, and Apple's APNs as described above. These providers can process ordinary network metadata, including IP addresses, under their respective terms and privacy policies; our Push Sync application code does not persist a raw IP address. The website analytics described above separately uses Cloudflare Web Analytics. App Store purchase administration is handled by Apple.
Retention, Deletion, and Control
Background Sync requires one explicit installation-level opt-in and can be globally disabled without affecting manual Git features. While enabled, automatic pull and automatic publishing can each be turned on or off independently; publishing has separate default-off consent. Turning off either action requests cancellation before that action continues, while global disable prevents all new automatic work and requests cancellation of work already in flight. A Git update or publication that completed before cancellation cannot be recalled. You can also exclude or re-include individual repositories and set their network/power policies. All Background Sync state — inclusion, policies, and sync health — is stored locally on your device, so turning the feature off or deleting the App removes it.
You can turn off Background Sync and exclude repositories in Repository Settings at any time. Push Sync has separate controls: removing a GitHub connection deletes that installation link from this device's relay record; managing or uninstalling the GitHub App occurs on GitHub; turning Push Sync off requests immediate deletion of this device record and route indexes; and records expire automatically 90 days after their last registration if an unregister request does not arrive. Deletion is best effort when the device is offline, and stale indexes are ignored and cleaned when encountered.
For an onboarding-analytics access/deletion request, use Request data access or deletion in the App's settings. It opens a private email draft to cody@isolated.tech with the opaque analytics installation identifier support needs; review the draft before sending. Use the separate in-App Push Sync controls for its device record. For private questions, email support, but never send your device secret, credentials, or tokens or put installation identifiers, repository details, or GitHub account details in a public GitHub issue. Deletion cannot remove records a third party must retain under its own legal obligations.
iOS File Provider
GitSync.md registers as an iOS File Provider, making your cloned repositories visible in the Files app. This allows other apps on your device to access your repository files. File access is governed by iOS's built-in permission model — the App does not control or monitor how other apps use these files.
x-callback-url
GitSync.md supports the syncmd:// URL scheme for automation. Other apps (such as Obsidian) can invoke Git operations via this URL scheme. Git operations execute on your device and communicate directly with the Git provider you configured. When the caller supplies an x-success or x-error callback URL, GitSync.md returns to that caller-supplied URL with result metadata such as action, status, message, commit SHA, branch, update state, and change count. Do not use a callback URL belonging to an app or service you do not trust.
Data Security
All sensitive credentials are stored in the iOS Keychain, which provides hardware-backed encryption. Repository data is stored within the App's sandboxed file system, protected by iOS's built-in data protection. GitHub API and OAuth communication uses HTTPS/TLS. Core Git and Git LFS communication uses the transport the user configures, including HTTPS/TLS or SSH with host-key verification.
Children's Privacy
The App is not directed to children under 13. We do not knowingly use Background Sync to collect personal information from children.
Changes to This Policy
If this Privacy Policy is updated, the revised version will be posted on this page with an updated effective date. Continued use of the App after changes constitutes acceptance of the updated policy.
Contact
For privacy or data requests, use the private in-App email flow described above or email cody@isolated.tech. GitHub Issues are available for non-private product questions only; never post installation identifiers, credentials, tokens, repository details, or other private data there.