gituas← back to site

Privacy Policy

Last updated · June 11, 2026

Gituas (“Gituas,” “we,” “us”) is an autonomous marketing and operations platform for software makers. This policy explains what data we collect, why, how we protect it, and how you can delete it.

1. Who we are

Gituas connects to a maker’s code repository and their social and payment accounts, then uses AI to plan, create, and publish marketing content on their behalf. We are the data controller for the information described below. For any privacy question, contact us at privacy@gituas.app.

2. Information we collect

  • Account data. When you sign in with GitHub, we receive your name, email address, avatar, and GitHub account ID.
  • Connected-platform credentials.When you connect a third-party account (TikTok, X, LinkedIn, Reddit, Meta, Stripe, and similar), we receive and store the access and refresh tokens that platform issues. These are encrypted at rest (see §6).
  • Platform profile data. With your authorization, we read basic profile information from connected platforms — for example, your TikTok display name, avatar, and open ID — solely to confirm the connected account and attribute published content.
  • Repository data. We read metadata and content from repositories you authorize (such as README, descriptions, releases, and languages) to understand your product and generate relevant marketing.
  • Content you and our agents create. Drafts, captions, images, videos, schedules, and approvals generated within Gituas.
  • Audience engagement content.Where you enable engagement features, we receive the comments and direct messages your audience sends to your connected accounts (including the message text and the sender’s public handle/ID), so our agents can read them and draft or send replies you authorize.
  • Analytics and insights. Aggregate performance metrics from connected accounts — such as reach, impressions, follower counts, likes, and saves — used to report results and improve the content we generate for you.
  • Usage and device data. Log data such as IP address, browser type, and actions taken, used for security and reliability.

3. How we use your information

  • To provide the service: plan, generate, schedule, and publish content you approve.
  • To publish to your connected accounts strictly within the scopes you grant.
  • To operate, secure, debug, and improve the platform.
  • To communicate with you about your account and service changes.

We do not sell your personal information, and we do not use platform data for advertising profiling or any purpose other than operating the features you enable.

4. TikTok and other connected platforms

When you connect TikTok, we access your data through the TikTok API only to (a) verify the connected account and (b) upload and publish videos and photo posts that you or your configured automations authorize. Our use and transfer of information received from TikTok adheres to the TikTok Developer Terms of Service and applicable platform policies. We request only the scopes required for these features (such as user.info.basic, video.upload, and video.publish). The same principles apply to every other connected platform: least-privilege scopes, used only for the features you turn on.

4a. Instagram and Meta

When you connect an Instagram professional account through Instagram Login, we access your data through the Instagram Platform only to (a) confirm the connected account, (b) publish posts, Reels, and stories you or your configured automations authorize, (c) read and reply to comments and direct messages, and (d) read account and media insights. We request only the scopes required for the features you enable (such as instagram_business_basic, instagram_business_content_publish, instagram_business_manage_comments, instagram_business_manage_messages, and instagram_business_manage_insights). Direct messages are used onlyto respond to people who message you first, within the platform’s permitted messaging window; we never send unsolicited messages and never use messaging data for advertising or profiling. Our use of information received from the Meta Platforms adheres to the Meta Platform Terms and Developer Policies.

4b. Google and YouTube

When you connect a YouTube channel, Gituas uses YouTube API Services. We request only youtube.upload (to publish the videos you or your configured automations authorize) and youtube.readonly (to confirm which channel is connected and to read public statistics such as view, like, and comment counts for your own videos). We do not read your subscriptions, watch history, or private playlists, and we never post to a channel without an action you authorized.

By connecting a channel you also agree to the YouTube Terms of Service. Information Gituas receives from Google APIs is handled in accordance with the Google Privacy Policy.

Limited Use.Gituas’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, we use this data only to provide and improve the features you enabled; we do not transfer it to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition; we do not use it for advertising or to build advertising profiles; and we do not allow humans to read it, except with your explicit consent, to resolve a support issue you raised, for security purposes, or where required by law.

You can revoke Gituas’ access to your Google account at any time from your Google account permissions page, or by disconnecting YouTube from your Gituas dashboard, which deletes the stored tokens.

5. How we share information

We share data only with service providers that help us run Gituas, including:

  • Hosting & infrastructure — Vercel (application) and Neon (database).
  • AI processing — Google (Gemini) to generate marketing content.
  • Connected platforms — TikTok, YouTube, X, LinkedIn, Reddit, Meta, and Stripe, to which we send the content and requests you authorize.

We may also disclose information if required by law or to protect the rights, safety, and security of Gituas and its users. We never sell personal data.

6. Data storage and security

Data is stored on managed infrastructure in the United States and European Union. All third-party access tokens are encrypted at rest using AES-256-GCM before being written to the database, and are decrypted only in memory at the moment an action you authorized is performed. Access to production systems is restricted and logged.

7. Data retention

We keep your data for as long as your account is active. When you disconnect a platform, we delete the associated access tokens. When you delete your account, we delete your personal data and connected-platform data within 30 days, except where we must retain limited records to meet legal obligations.

8. Your rights and choices

  • Access, correct, or export your personal data.
  • Disconnect any platform at any time from your dashboard, which revokes our stored tokens.
  • Delete your account and all associated data — see Data Deletion.

Depending on where you live, you may have additional rights under the GDPR or CCPA. To exercise any right, email privacy@gituas.app.

9. Cookies

We use only essential cookies required to keep you signed in and to secure your session. We do not use advertising or cross-site tracking cookies.

10. Children

Gituas is not directed to anyone under 16, and we do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the service evolves. We will revise the “Last updated” date above and, for material changes, notify you in-app or by email.

12. Contact

Questions or requests: privacy@gituas.app. See also our Terms of Service and Data Deletion instructions.