1. Who is responsible
CommitDiary is responsible for the personal data CommitDiary collects through its website, extension-connected services, and dashboard. For privacy questions, contact privacy@commitdiary.dev.
If the legal entity name or registered address shown in your deployment is incomplete, it must be configured before live Paddle domain review. The live notice must identify the actual legal entity and registered or principal business address.
2. Data we collect
Depending on the features you use, this can include:
- account details such as username, email address, authentication records, and profile information;
- Git and work-journal data such as repository identity, commit metadata, file paths, statistics, selected patch excerpts, categories, and generated reports;
- support requests, feedback, device information, IP address, security events, and service-usage information;
- billing identifiers and subscription status received from Paddle. Paddle collects and processes payment details under its own privacy terms; and
- integration data when you choose to connect services such as Discord or Git providers.
3. Why we use it
We use data to create and secure accounts, provide requested features, sync and display work history, generate reports, deliver integrations, provide support, prevent abuse, improve reliability, meet legal obligations, and keep billing records.
We use optional marketing data only where you have given a separate, clear choice. Service access is not conditioned on marketing consent.
4. Processing grounds
Depending on the activity and applicable law, we rely on providing the service you requested, complying with a legal obligation, our legitimate interests in security and service operation, or your consent. We do not treat silence or a pre-selected marketing option as consent.
Where processing relies on consent, you can withdraw it as easily as you gave it. Withdrawal does not affect processing that already happened lawfully or processing needed for the service or a legal obligation.
6. Retention
We keep account and work-journal data while your account is active and for as long as needed to provide a feature you requested. After closure, we delete or anonymise it on a controlled schedule unless we need to retain it for a legal obligation, billing record, security investigation, dispute, backup recovery window, or the establishment or defence of a claim.
Security and request logs are retained only for as long as needed for abuse prevention, incident response, troubleshooting, and legal accountability. We review retention periods as the product changes.
7. Your choices and rights
You may ask us to access, correct, delete, restrict, or provide a copy of personal data, or object to processing where the law allows. You can also withdraw optional consent and unsubscribe from marketing messages. Contact privacy@commitdiary.dev; we may need to verify your identity before acting.
We will respond within the period required by applicable data-protection law and explain any lawful reason a request cannot be completed in full.
8. Children and minors
CommitDiary is a developer tool and is not directed to children. Do not create an account or submit personal data if you are not legally able to agree to these terms. If you believe a minor has provided data without the required authorisation, contact us so we can review and remove it where appropriate.
9. Security
We use access controls, authenticated sessions, encryption in transit, provider safeguards, rate limits, audit signals, and least-privilege operational access appropriate to the risk. No online service can promise absolute security, so protect your credentials and avoid sending secrets or data you are not authorised to share.
If we identify a personal-data incident, we will investigate, contain it, document the response, and notify regulators or affected people when required by applicable law.
10. International processing
Some providers may process data outside Nigeria. We assess the transfer and use contractual, organisational, or other safeguards required by applicable data-protection law. The service provider list and material changes to international processing will be reflected here or in an applicable vendor notice.
12. Updates and contact
We may update this notice when our processing or legal obligations change. The current version is dated 28 August 2026. For privacy requests or concerns, email privacy@commitdiary.dev.