Privacy Policy
Last updated September 14, 2026
This is an initial policy, written to be accurate and complete rather than exhaustive. Git-PMO is currently a limited, invite-only release. If anything here is unclear, or you want a copy of what is held about you, write to cedrec@gmail.com.
Who this covers
This policy covers Git-PMO (gitpmo.com), a project-management tool where a project's records — tasks, risks, issues, decisions, documents — are stored as files in a GitHub repository the project's team already controls. It is operated by an individual developer, not a company.
Information collected
Your GitHub identity. Signing in uses GitHub OAuth. Git-PMO receives your GitHub login and name, and reads your permission level (admin, write, or read) on the specific repositories you connect a project to — never repositories you don't point it at. This decides what you can see and change inside that project.
A session cookie. A signed, functional cookie keeps you signed in. It is not used for advertising or tracking, and no third-party analytics or ad cookies are set.
Project content. What you and your team enter — tasks, risks, issues, decisions, documents — is written as Markdown and YAML files into your own GitHub repository, under your own GitHub account's control and retention. Git-PMO's server keeps a working copy needed to serve and synchronize the app.
Project configuration. Separately from your repository, Git-PMO keeps a small registry recording which repository a project is bound to, its chat platform binding, and — only if a project's creator adds them — credentials the creator explicitly enters: chat webhook URLs, AI provider API keys, and cloud-drive connections. These are encrypted before they are stored; access tokens for connected agents are stored as a one-way hash, never the token itself.
Chat integrations. If a project connects Discord, the bot reads the server, channel and user IDs it needs to post updates and respond to commands. It does not read general channel message content. Slack and Teams integrations (kept for existing projects) work the same way, over a webhook URL you provide.
Cloud drive connections. Connecting a cloud drive (Google Drive, Box, Dropbox, or
OneDrive) is optional and made by a project's creator. For Google Drive specifically, Git-PMO
requests only the drive.file scope, which grants access solely to the folder you
explicitly choose using Google's own folder picker — Git-PMO can never see any other file or folder
in your Drive, and never lists your Drive's contents. A refresh token is stored encrypted so the app
can periodically check that the chosen folder is still reachable.
AI provider keys. Using a hosted AI agent run is opt-in and requires a project's creator to add their own Anthropic or OpenAI API key. The key is encrypted at rest and never displayed again once saved. Starting a run sends the relevant project data — the instruction given and the records the agent reads or writes — to that vendor's API, billed to the key's owner.
How information is used
Solely to provide Git-PMO's project-management features: authenticating you, enforcing the permissions your repository already defines, posting updates to the chat platform you configured, reaching a drive folder or AI vendor you explicitly connected, and keeping the app's own records in sync with your repository. Git-PMO does not use your information for advertising, does not sell it, and does not share it with third parties except the vendor calls described above, which you initiate.
Your controls
- Revoke GitHub access any time from GitHub → Settings → Applications.
- Revoke a Google Drive connection from your Google Account's Security → Third-party access, or disconnect it inside Git-PMO's Project Settings.
- Remove an AI provider key or a chat integration at any time in Project Settings.
- Disconnecting a project removes it from Git-PMO's own registry; its content remains in your GitHub repository, under your control, untouched.
- Contact cedrec@gmail.com for any other request, including seeing or deleting what Git-PMO's registry holds about a project.
Security
Credentials you provide (webhook URLs, AI keys, drive tokens) are encrypted before they are stored. Access to a project's data is enforced by the permissions already set on its GitHub repository.
Children's privacy
Git-PMO is not directed to children under 13, and does not knowingly collect information from them.
Changes to this policy
This policy may be updated as the product changes. The date at the top of this page always reflects the most recent revision.
Contact
Questions or requests about this policy: cedrec@gmail.com.