Legal
Privacy Policy
Last updated: July 1, 2026
1. Overview
Brain2Git (“we”, “us”, “our”) is a voice-to-GitHub-issue tool. This policy explains what data we collect when you use the app, why we collect it, and how you can control it. By using Brain2Git you agree to the practices described here.
2. Data We Collect
- Account data — your email address and GitHub profile information, provided via GitHub OAuth sign-in.
- GitHub access tokens — an access token (and refresh token, if issued) scoped to the repositories you explicitly grant access to via the Brain2Git GitHub App installation. We never request access to your entire GitHub account.
- Voice recordings — audio you record in the app, stored in encrypted cloud storage to generate a transcript.
- Transcripts and generated content — the text transcribed from your voice, and the issue title, description, acceptance criteria, and labels generated from it.
- AI provider API keys — if you supply your own API key (OpenAI, Anthropic, Google, Groq, OpenRouter), it is encrypted at rest using AES-256-CBC before storage. We never store it in plaintext or log it.
- Usage and activity logs — timestamps of actions like recording started, issue generated, and issue created, used for your own history view and basic diagnostics.
3. How We Use Your Data
- To transcribe, translate, and structure your voice notes into GitHub issues.
- To create and update issues in the GitHub repositories you've connected.
- To authenticate you and maintain your session.
- To show you your own voice note and issue history within the app.
- To diagnose bugs and maintain service reliability.
We do not sell your data, and we do not use your voice recordings or transcripts to train any model.
4. Third-Party Services
Brain2Git relies on the following third parties to operate. Each processes a narrow slice of your data as described:
- Supabase — hosts our database, authentication, and file storage (audio recordings).
- GitHub — OAuth sign-in and issue creation, scoped to repositories you select.
- Vercel — hosts the application and serverless functions.
- Your chosen AI provider (OpenAI, Anthropic, Google, Groq, or OpenRouter) — receives your audio and transcript solely to perform transcription and text generation, using the API key you supplied. We do not control these providers' own data retention policies — review theirs directly if you have concerns.
5. Data Retention
We retain your voice recordings, transcripts, and generated issues until you delete them or delete your account. Deleting an issue or voice note from the app removes it from our database. Deleting your account removes your profile, connected repositories, encrypted API keys, and all associated content.
6. Your Rights
- Delete individual voice notes or generated issues at any time from within the app.
- Disconnect any connected GitHub repository at any time from your dashboard.
- Remove your stored AI API key at any time from Settings.
- Request full account deletion by contacting us at the address below.
7. Security
API keys are encrypted with AES-256-CBC before they touch our database. GitHub tokens are stored server-side and never exposed to the browser. All traffic is served over HTTPS. Row-level security policies restrict every database query to the authenticated owner of that data.
8. Children's Privacy
Brain2Git is not directed at children under 13, and we do not knowingly collect data from them.
9. Changes to This Policy
We may update this policy as the product evolves. Material changes will be reflected by updating the “Last updated” date above.
10. Contact
Questions about this policy or your data? Email akhiljimmy18@gmail.com.