Legal & Transparency

Privacy Policy

Effective date & last updated: October 1, 2026

1. Overview & Commitment

GitBowl ("we", "our", or "us") operates the Git repository hosting platform, smart-HTTP Git engine, web code editor, and developer services available at gitbowl.zone.id. We respect your privacy and are committed to safeguarding your personal data, developer credentials, and proprietary code.

This Privacy Policy explains what information we collect when you visit GitBowl, authenticate with Google, clone or push Git repositories, and interact with our web services.

2. Information We Collect

Google & Firebase Authentication

When you sign in via Google Authentication, Firebase provides your email address, verified display name, and public profile avatar. We never receive or store your Google account password.

Repository Data & Commits

Source code files, commit trees, commit messages, author signatures (name and email configured in git), branches, issues, comments, and project settings.

Developer Credentials & Tokens

Personal Access Tokens (PATs) generated for Git CLI access. We store only cryptographic SHA-256 hashes of your tokens; raw tokens cannot be retrieved once created.

Operational Logs & Network Metrics

Client IP addresses, Git user-agent headers, timestamped API requests, rate-limiting tokens, and HTTP status codes used to maintain network integrity and prevent abuse.

3. Public vs. Private Repositories

Public Repositories: Any content, source code, commits, or issues in a public repository are visible to the world. Anyone on the Internet can view, clone, and read public repositories. Do not include unencrypted API keys, secrets, private certificates, or proprietary data in public repositories.

Private Repositories: Private repositories are restricted. Access is granted solely to the authenticated owner and explicitly invited collaborators. Our employees and automated systems do not inspect your private code except where required by law, to prevent security incidents, or with your explicit consent for technical support.

4. Service Infrastructure & Subprocessors

GitBowl utilizes industry-leading infrastructure providers to ensure high availability, data redundancy, and security:

  • Google Firebase: Identity management, Google OAuth token verification, and analytics measurement.
  • Supabase & PostgreSQL: Git repository file storage, database schemas, Row Level Security (RLS), and transactions.
  • Cloudflare & Google Cloud: CDN edge delivery, DDoS prevention, SSL/TLS encryption, and container execution.

5. Data Protection & Security Controls

All communications between your browser or Git CLI and GitBowl are encrypted in transit using Transport Layer Security (TLS 1.3). Database tables enforce PostgreSQL Row Level Security to isolate repositories by user tenancy.

Authentication credentials, personal access tokens, and sessions are hashed with irreversible algorithms (SHA-256/bcrypt). We conduct regular automated vulnerability reviews and continuous integration testing.

6. Your Rights & Data Portability (GDPR & CCPA)

Regardless of your physical location, GitBowl provides comprehensive data ownership rights:

  • Access & Export: You can download any repository as a full .zip archive or clone the full Git commit history at any time.
  • Rectification: You can edit your profile username, display name, and repository settings directly in the app.
  • Deletion: Deleting a repository permanently removes all associated files, commit rows, and metadata. You may also request full account erasure.

7. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your data on GitBowl, please contact our privacy team at mail.gitbowl@gmail.com.