Last updated July 26, 2026
Commit0 is version control for teams who work with large binary files. This policy explains what we collect, why we collect it, and what you can do about it. We have tried to write it the way we would explain it to you in person.
The short version
Your name, email address, and either a password (which we store only as a secure hash, so we never see the password itself) or the identity handed to us by whichever sign in provider you choose. If you sign in through a provider, we receive your name, email address, and an account identifier from them. We never receive your password.
The files you push, their revision history, commit messages, branch and lock information, and the names of your repositories and organizations. Each repository lives in the region you choose for it when you create it.
Which product actions happened and when: signing in, importing a repository, checking in, syncing, pushing, resolving a merge, opening a view, cancelling an operation. Each one is recorded with how long it took, how many bytes moved, and which region it hit, alongside your account, organization, and repository identifiers. File paths and file contents are deliberately excluded, and that exclusion is enforced in our code rather than left to convention.
The desktop app reports app version, operating system, and error details so we can find and fix problems. Reports carry a random per install identifier that we generate. It is not derived from your hardware, so it cannot be used to recognise your machine across other software. Crash reports have personal file paths stripped out before they leave your machine.
Telemetry is on by default and you can switch it off in Settings at any time. Switching it off deletes the identifier rather than merely hiding it, and switching it back on creates a brand new one, so opting out is a genuine break in the record.
Our servers record IP addresses, browser or client version, timestamps, and which endpoints were called. We use these to keep the service running, investigate incidents, and detect abuse.
When paid plans are available, a payment processor handles your card details directly. We never see or store full card numbers. We keep your plan, invoice history, and how much storage you are using.
Support requests, bug reports, and anything else you write to us, along with our replies.
The web app uses a small number of cookies, all of them functional: one to keep you signed in, one security token that prevents other websites from acting on your behalf, one that remembers where to send you after you sign in, and one that remembers a referral link for up to a week. There are no advertising cookies, no analytics cookies, and no cross site tracking. This marketing site sets no cookies of its own.
We use a small number of service providers to run Commit0: cloud hosting and object storage, a content delivery network, an error monitoring service, an email delivery service, and, once paid plans launch, a payment processor. They only receive what they need to do their job, they act on our instructions, and none of them are permitted to use your data for their own purposes. We are happy to name them if you ask.
You choose a region for each repository when you create it, and that repository's files stay in that region. Your account and organization records live in our primary region. Some providers, particularly for logs, error reports, and email delivery, may process data in other countries. If you have a specific residency requirement, write to us and we will tell you exactly how your setup would work.
We keep your account information for as long as your account is open, and for a short period afterwards in case you come back or we need it for legal or accounting reasons. Repository content is kept until you delete the repository or your account, after which it is removed from our systems and ages out of backups. Technical logs and usage analytics are kept for a limited period and then deleted or aggregated so they no longer identify you.
Depending on where you live you may have additional legal rights, for example under the GDPR in Europe or the CCPA in California. Rather than run separate policies, we apply the rights above to everyone. Email privacy@commit0.com and we will get back to you within 30 days.
Everything travels over encrypted connections. Your repository content and the databases behind it are encrypted at rest by our storage providers, and so are their backups. Passwords are stored only as secure hashes. On the desktop app, your sign in credential is held in your operating system's keychain rather than in a plain file. Access to production systems is limited to the people who need it. No system is perfect, and if a breach ever affects your data we will tell you promptly.
Commit0 is a professional tool and is not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has given us information, write to us and we will delete it.
When we change this policy we will update the date at the top. If a change materially affects what we collect or how we use it, we will tell you in the app or by email before it takes effect.
Questions, requests, or concerns about privacy go to privacy@commit0.com. A real person reads it.