← gitpmo.com

Privacy Policy

Last updated September 14, 2026

This is an initial policy, written to be accurate and complete rather than exhaustive. Git-PMO is currently a limited, invite-only release. If anything here is unclear, or you want a copy of what is held about you, write to cedrec@gmail.com.

Who this covers

This policy covers Git-PMO (gitpmo.com), a project-management tool where a project's records — tasks, risks, issues, decisions, documents — are stored as files in a GitHub repository the project's team already controls. It is operated by an individual developer, not a company.

Information collected

Your GitHub identity. Signing in uses GitHub OAuth. Git-PMO receives your GitHub login and name, and reads your permission level (admin, write, or read) on the specific repositories you connect a project to — never repositories you don't point it at. This decides what you can see and change inside that project.

A session cookie. A signed, functional cookie keeps you signed in. It is not used for advertising or tracking, and no third-party analytics or ad cookies are set.

Project content. What you and your team enter — tasks, risks, issues, decisions, documents — is written as Markdown and YAML files into your own GitHub repository, under your own GitHub account's control and retention. Git-PMO's server keeps a working copy needed to serve and synchronize the app.

Project configuration. Separately from your repository, Git-PMO keeps a small registry recording which repository a project is bound to, its chat platform binding, and — only if a project's creator adds them — credentials the creator explicitly enters: chat webhook URLs, AI provider API keys, and cloud-drive connections. These are encrypted before they are stored; access tokens for connected agents are stored as a one-way hash, never the token itself.

Chat integrations. If a project connects Discord, the bot reads the server, channel and user IDs it needs to post updates and respond to commands. It does not read general channel message content. Slack and Teams integrations (kept for existing projects) work the same way, over a webhook URL you provide.

Cloud drive connections. Connecting a cloud drive (Google Drive, Box, Dropbox, or OneDrive) is optional and made by a project's creator. For Google Drive specifically, Git-PMO requests only the drive.file scope, which grants access solely to the folder you explicitly choose using Google's own folder picker — Git-PMO can never see any other file or folder in your Drive, and never lists your Drive's contents. A refresh token is stored encrypted so the app can periodically check that the chosen folder is still reachable.

AI provider keys. Using a hosted AI agent run is opt-in and requires a project's creator to add their own Anthropic or OpenAI API key. The key is encrypted at rest and never displayed again once saved. Starting a run sends the relevant project data — the instruction given and the records the agent reads or writes — to that vendor's API, billed to the key's owner.

How information is used

Solely to provide Git-PMO's project-management features: authenticating you, enforcing the permissions your repository already defines, posting updates to the chat platform you configured, reaching a drive folder or AI vendor you explicitly connected, and keeping the app's own records in sync with your repository. Git-PMO does not use your information for advertising, does not sell it, and does not share it with third parties except the vendor calls described above, which you initiate.

Your controls

Security

Credentials you provide (webhook URLs, AI keys, drive tokens) are encrypted before they are stored. Access to a project's data is enforced by the permissions already set on its GitHub repository.

Children's privacy

Git-PMO is not directed to children under 13, and does not knowingly collect information from them.

Changes to this policy

This policy may be updated as the product changes. The date at the top of this page always reflects the most recent revision.

Contact

Questions or requests about this policy: cedrec@gmail.com.