Privacy Policy
Last updated: 3 October 2026. This Privacy Policy explains which personal data is processed when you use the GiCode app, why, and what rights you have. It applies to GiCode on iPhone.
1. Controller.
The controller within the meaning of the General Data Protection Regulation (GDPR) is Kevin Wurbs, Hauptstraße 18, 04808 Lossatal OT Thammenhain, Germany. Contact for all privacy matters: app@wurbs.me.
2. Short version.
GiCode has no server of its own and no user account. We do not collect, receive or store your personal data, and we use no analytics, advertising, tracking or third-party tracking software. Everything the App needs is stored on your device. When you use a function that needs a network, your device connects directly to the service you chose, or to Apple, and not through us.
3. Data stored on your device.
To work, the App stores the following on your device only: the accounts you add (provider, server address, user name, display name and avatar address), your access tokens and your SSH private key (in the iOS Keychain), the name and email address you set for your commits, your repositories and the files in them, groups and other settings (such as your language), a record that you accepted these documents, and the start date of the free trial and your purchase status. We have no access to this data. It is processed to provide the functions you ask for (Art. 6(1)(b) GDPR). Deleting an account or the SSH key in Settings, or deleting the App, removes the related data from the App; iOS may keep Keychain items after an app is deleted.
4. Free trial and abuse prevention.
The start date of the free trial is kept in the iOS Keychain so that reinstalling the App does not restart the trial. It stays on your device and is not sent to us. The legal basis is our legitimate interest in preventing abuse of the trial (Art. 6(1)(f) GDPR). You can object at any time; see section 11.
5. Git hosting services and servers you connect.
When you add an account or a repository, or use functions such as clone, fetch, pull, push, pipelines, pull requests and issues, the App sends requests directly from your device to the service you chose, for example GitHub, GitLab or your own server. This includes your access token or SSH key for authentication, the content of the requests, the content of your repositories, the name and email address in your commits, and technical data such as your IP address, which the service receives by the nature of the connection. We do not receive any of this. The legal basis is the performance of the contract with you (Art. 6(1)(b) GDPR). These services are independent controllers; their privacy policies apply to their processing.
6. Profile pictures.
To show profile and owner pictures, the App loads images directly from the service concerned (for example github.com). That service receives your IP address and the technical data of the request. The legal basis is our legitimate interest in a recognisable user interface (Art. 6(1)(f) GDPR). If a picture cannot be loaded, the App shows a letter instead.
7. Purchases and Apple.
GiCode Pro is bought through Apple's In-App Purchase. Apple processes your Apple ID, payment data and purchase history as an independent controller under its own privacy policy; we receive no payment data. The App only asks Apple's StoreKit framework on your device whether you own GiCode Pro and which price is shown for your region. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). If you take part in TestFlight or allow your device to share analytics or crash reports with developers, Apple may provide us with anonymised, aggregated diagnostics; this depends only on your settings with Apple.
8. Contacting us.
If you write to us, we process your email address and your message to answer you (Art. 6(1)(b) or (f) GDPR) and delete them once the matter is resolved, unless statutory retention duties apply.
9. Recipients and transfers to third countries.
We do not pass personal data to anyone and use no processors, because we do not process your data on our own systems. The services you connect to and Apple may process data in countries outside the European Economic Area, in particular the United States. They are responsible for appropriate safeguards, for example the EU-US Data Privacy Framework or standard contractual clauses.
10. Storage period, automated decisions and security.
Data on your device stays there until you delete it or the App. There is no automated decision-making and no profiling. Connections to services use encryption (TLS or SSH), and secrets are kept in the iOS Keychain. No system is completely secure; please protect your device with a passcode and keep your access tokens limited to the permissions you need.
11. Your rights.
You have the right to access, rectification, erasure, restriction of processing and data portability, and the right to object to processing based on legitimate interests (Art. 15 to 21 GDPR), and to withdraw a consent at any time with effect for the future. Because we hold no personal data about you, we can in most cases only confirm that; for data held by GitHub, GitLab, Apple or another service, please contact that service. You also have the right to lodge a complaint with a data protection supervisory authority, for example in the place of your residence or work or of the alleged infringement. For us, the competent authority is the Sächsische Datenschutz- und Transparenzbeauftragte.
12. Children.
GiCode is not directed at children under 16, and we do not knowingly process their data.
13. Changes.
We may update this Privacy Policy, for example when the App or the law changes. The current version is always available in the App under Settings. If a change materially affects you, we will tell you in the App.
