Privacy Policy
Last updated: August 18, 2026
At RepoGo ("RepoGo," "we," "us," or "our"), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, transmit, and safeguard your information when you use our mobile, desktop, and web-based development Service (the "Service").
Please read this Privacy Policy carefully. By using the Service, you consent to the practices described here. If you do not agree, do not use the Service.
0. Summary: What We Send to Third-Party AI Services
RepoGo is a client for AI coding agents, so providing the Service can require sending what you ask to one or more third-party AI services. This table is the short version; §3.3 and §4 are the full terms.
Before the first transmission for an AI feature, the RepoGo app shows what data will be sent, names the known companies that may receive it, and asks for your affirmative permission. If you decline, that request is canceled and the data is not transmitted for that request. Permission is stored on that device for the disclosed data category and company set. To withdraw it in the iOS app, open Account → AI & Privacy and tap the green Chat or Voice label next to a company, or choose Withdraw All Permissions; other clients provide an equivalent control where the permission ask is used. RepoGo then asks again before the next applicable AI request. Withdrawal applies to future requests; it cannot recall data already transmitted or cancel a request or voice session already underway.
The list is a best-effort disclosure of the known possible recipients for the selected agent, model, connected account, and current provider availability. It does not mean every listed company receives every request. If app configuration cannot identify a narrower set, the app displays a broader bundled list of supported AI services and still requires permission; missing disclosure metadata never bypasses the permission ask.
How disclosure and permission are presented may differ between RepoGo clients (for example, the iOS app, the Android app, and the web dashboard) and between versions of them. The timing, layout, and management of the permission ask — and where you withdraw it — can vary by platform, and a permission granted on one device or client does not automatically carry to another. What does not vary is the substance: the categories of data sent and the possible recipients described in this section apply to every client, and this Privacy Policy governs all of them.
| What is sent | When | Who receives it |
|---|---|---|
| Your prompt, and any files or photos you attach | You send a message to a coding agent | The operator of the agent you picked and the routing or inference companies named or described in the permission sheet — for example Anthropic (Claude), OpenAI (Codex), Anysphere (Cursor), GitHub/Microsoft (Copilot), or Vercel AI Gateway and its inference providers (RepoGo agent) |
| Your codebase — during a session the agent makes tool calls to read and edit files to carry out your request | Throughout the turn, as the agent decides what it needs | Same as above |
| Output from commands the agent runs | The agent runs a command during your turn | Same as above |
| Web-search queries the agent creates from your request | Only if the agent searches for current information | The model provider's native search service or Perplexity through Vercel AI Gateway, as named in the permission sheet |
| Live microphone audio, and a transcript of the conversation | Only while a voice conversation is running | Google (Gemini Live), OpenAI (Realtime), or xAI (Grok Voice), depending on the provider you select |
| Questions sent to Ask Expert, plus relevant past chats, repository, GitHub, memory, agent-status, and workspace context it retrieves | During a voice conversation, only when the voice agent calls Ask Expert | Vercel AI Gateway and Google, in addition to the selected voice provider |
| The name and file context of the workspace you are in | Alongside any of the above | Same recipient as the request it accompanies |
Some agents and gateways pass a request to another company. Cursor and Copilot offer mixed model lists, so Anysphere may forward a request to Anthropic, OpenAI, Google, or xAI, and GitHub may forward one to Anthropic, OpenAI, Google, Microsoft, or Moonshot AI. RepoGo sends every cloud-model request through Vercel AI Gateway using the Gateway API key you connected; RepoGo does not select an alternate gateway or direct cloud-provider route. Your Vercel account settings, retention configuration, terms, and billing apply. During voice, the optional Ask Expert tool also uses that Gateway account and a Google model.
Vercel AI Gateway may select among the inference infrastructure providers it supports for a model based on availability. The permission sheet therefore names the model's developer and the Gateway, and discloses this infrastructure routing as a category rather than claiming one fixed provider. Depending on the model, the infrastructure provider serving a request may include — but is not limited to — Amazon Web Services, Google, Microsoft, Fireworks AI, Together AI, Baseten, Novita AI, DeepInfra, or Nebius; the current roster is published by Vercel in its AI Gateway documentation and may change without notice. By granting permission for a Gateway-routed request, you agree that Vercel may route it to any inference provider it supports for that model. If the RepoGo agent searches the web, the search query may be sent to Perplexity through the Gateway. RepoGo does not set a per-request retention override; the settings of the account you connected and the applicable provider agreements control retention.
RepoGo confirms that every third-party AI service to which the app enables transmission must provide the same or equal protection for the personal data covered by this Privacy Policy through its applicable agreement, privacy commitments, and security controls. This includes onward inference providers used by an agent or gateway. We review the services exposed in the app and will stop enabling new transmissions to a service if we can no longer make that confirmation. Each company also handles what it receives under its own privacy policy and retention practices, which we link in the app. RepoGo does not use your prompts, code, or chat history to train its own models without your explicit opt-in (§2.2.1).
1. Information We Collect
1.1 Information You Provide
Account Information:
- Email address
- Name
- Profile picture
- GitHub username and OAuth access tokens (when connected)
- Credentials, API keys, or access tokens you provide for third-party integrations (for example, AI providers and sandbox providers)
Content You Submit:
- Code, repository files, diffs, project configurations, and related project metadata you choose to sync
- Environment files (
.env) and any environment variables you add to the Service - Prompts, chat messages, AI instructions, generated responses, and tool outputs
- Live microphone audio captured while you run a voice conversation, and the resulting transcript
- Chat attachments, uploaded images, video, documents, ZIP archives, and other files you upload through the Service
- Comments, support requests, correspondence, and usage preferences
Payment Information:
- Payment details (processed by Stripe, RevenueCat, or the applicable app-store billing system)
- Billing address
- Transaction history
1.2 Information Automatically Collected
Usage Data:
- IP address and approximate location derived from it
- Device information (type, model, OS, browser, language, time zone)
- Access times, session duration, and dates
- Features used, commands invoked, and actions taken
- Referral URLs
Technical Data:
- Cookies and similar technologies
- Session tokens and authentication state
- Error logs, crash reports, and diagnostics
- Push-notification identifiers (such as APNs tokens and any equivalent push tokens supported by the Service)
1.3 Information From Third Parties
GitHub:
When you connect your GitHub account so you can download and sync repositories to your phone and other connected devices, we receive:
- Repository metadata (names, branches, commits, file contents you choose to download)
- Your GitHub profile information
- Organization memberships, as scoped by the OAuth permissions you grant
- Information necessary to read or write repositories you have authorized
Third-Party CLI Agents and AI Providers:
When you use AI-powered or CLI-agent features (including but not limited to the companies identified in §3.3), metadata about your usage (such as counts, errors, and latency) may be returned to us. The AI providers and gateways themselves process your prompts and file contents under their applicable privacy policies, terms, and security controls.
Sandbox and Infrastructure Providers:
When you launch cloud development environments through integrated providers (including but not limited to Vercel, Hetzner, and other infrastructure partners disclosed when you use the applicable feature), metadata such as environment IDs, status, resource usage, and logs may be returned to RepoGo to facilitate the Service.
2. How We Use Your Information
2.1 To Provide the Service
- Create, authenticate, and manage your account
- Connect your GitHub account so repositories can be downloaded to your phone and other devices
- Receive, store, cache, and transmit your code, files, diffs, hashes, commit metadata, and related project data as necessary to synchronize changes between your devices, your source control provider (such as GitHub), and sandbox environments
- Store chat histories, prompts, responses, tool outputs, attachments, and offloaded message parts so you can reload conversations, continue work across devices, and use related Service features
- Forward prompts and file contents to third-party AI agents at your direction
- Stream microphone audio, voice transcripts, and relevant workspace context to the voice AI provider you select
- Provision and orchestrate sandbox environments through third-party providers
- Transmit environment files (
.env) you attach to RepoGo up to the applicable sandbox provider when a sandbox starts, so that sandbox processes can access the environment values you have supplied - Send service-related notifications (including push notifications)
- Detect, investigate, and prevent abuse, fraud, and security incidents
2.2 To Improve the Service
- Analyze usage patterns and performance
- Diagnose bugs and technical issues
- Develop new features and capabilities
- Conduct internal analytics and research
- Optimize reliability and cost
2.2.1 No Model Training Without Opt-In
RepoGo does not currently use your data, code, prompts, or chat history to train our own models without your explicit opt-in. We do not sell your data to model-training providers. When we control an optional setting that would allow a third-party provider to use your content for model training, we do not intentionally enable that setting on your behalf without your explicit opt-in.
However, third-party AI providers and gateways that you choose to use through the Service may handle prompts, files, and outputs under their own terms, retention settings, enterprise controls, and account configuration, especially when you bring your own API keys or provider accounts. Whether such a provider uses your content for model training is governed by your agreement with that provider, not solely by this Privacy Policy.
If this ever changes in the future, we will:
- Provide you with clear, prominent advance notice
- Require your explicit, affirmative opt-in before any of your data, code, prompts, or chat history is used for AI model training
- Allow you to decline without losing access to the core Service
- Update this Privacy Policy and notify you of the change
Silence, continued use of the Service, or pre-checked boxes will not be treated as consent for model training.
We may use aggregated, de-identified usage data (that cannot reasonably be linked back to you or your code) for product analytics and to improve the Service.
2.3 Communication
- Send service updates, security alerts, and administrative messages
- Respond to your inquiries and support requests
- Send marketing communications (only with your consent where required by law; you may opt out at any time)
2.4 Security, Compliance, and Legal
- Prevent fraud, abuse, unauthorized access, and other harmful activity
- Enforce our Terms of Service and other policies
- Comply with legal obligations, court orders, and lawful requests
- Protect the rights, property, and safety of RepoGo, our Users, and others
3. How We Share Your Information
We do not sell your personal information or share it for cross-context behavioral advertising. We may share your information as described below.
3.1 Service Providers and Subprocessors
We work with third-party service providers that perform services on our behalf:
- Authentication, Database, and Sync: Firebase and Google Cloud services, including Firebase Authentication, Firestore, and Cloud Storage
- Cloud Hosting and Transport: Google Cloud (including Cloud Run), AWS (including S3), Cloudflare, and similar infrastructure providers used to host the Service and transport data between devices and sandboxes
- Payment Processing and Platform Billing: Stripe, RevenueCat, Apple App Store, and other applicable billing platforms
- Push Notifications and Live Activity Delivery: APNs and related Apple services used to deliver notifications and Live Activity updates
- Email and Transactional Messaging: Resend and similar providers used for account and support emails
- Operational Monitoring and Diagnostics: Logging, metrics, crash reporting, and related infrastructure used to keep the Service reliable
Where these companies act as our service providers or subprocessors, they process information pursuant to their contracts with us. In other cases, such as payment platforms or provider accounts you connect, they may also process information under their own terms with you.
3.2 GitHub
When you connect your GitHub account, we access the repositories and metadata you authorize via OAuth. We do not share your information with GitHub beyond what is required to perform the integration (for example, reading, writing, or cloning repositories you direct us to).
3.3 Third-Party AI Providers and CLI Agents
When you invoke AI features or CLI agents through the Service, we forward the prompts, commands, attachments, tool output, and relevant code context described in §0 to the known possible recipients named or described in the permission sheet before the first send. Depending on the selected agent, model, connected account, and provider availability, those companies may include:
- Anthropic (Claude, Claude Code)
- OpenAI (GPT models, Codex CLI)
- Google (Gemini, voice features, and the voice Ask Expert model)
- Anysphere (Cursor Agent / Cursor CLI)
- GitHub and Microsoft (Copilot and related services)
- Amazon Web Services (AWS) (Bedrock and Claude Platform on AWS, when available for the selected model)
- Vercel (AI Gateway and related services)
- Perplexity (web search through Vercel AI Gateway, when the agent searches)
- xAI (Grok)
- Moonshot AI, Z.ai, Alibaba Cloud, and MiniMax (when you select a model developed by those companies)
- Inference infrastructure providers used by Vercel AI Gateway for the selected model — such as, but not limited to, Fireworks AI, Novita AI, Baseten, Together AI, DeepInfra, and Nebius. The permission sheet discloses this routing as a category; the current roster is published by Vercel and may change without notice
- Any other AI service — RepoGo asks your permission in the app before enabling transmission to an AI service or category of recipients not described above
Each such provider handles your data under its applicable privacy policy, security controls, and retention practices, linked in the app. As stated in §0, RepoGo only enables transmission where the third-party AI service provides the same or equal protection for the personal data covered by this Privacy Policy.
3.4 Sandbox and Infrastructure Providers
When you launch cloud development environments or provision infrastructure through the Service, we transmit relevant data to the provider used for that environment, including but not limited to:
- Vercel (Vercel Sandbox and related services)
- Hetzner (including dedicated cloud-development hosts)
- Other cloud, container, networking, storage, or infrastructure providers disclosed when you use the applicable feature
Data transmitted may include your repository files, environment variables and .env file contents, build artifacts, prompts, and commands required to operate the sandbox. Once transmitted, this data is subject to the provider's own privacy policy, security controls, retention practices, and terms of service. RepoGo does not control how these providers handle data after it has been transmitted to them.
3.5 Legal and Safety
We may disclose your information if we believe in good faith that disclosure is necessary to:
- Comply with applicable law, regulation, or legal process (including subpoenas and court orders)
- Enforce our Terms of Service
- Protect the rights, property, or safety of RepoGo, our Users, or others
- Investigate and prevent fraud, abuse, or security incidents
3.6 Business Transfers
If RepoGo is involved in a merger, acquisition, reorganization, financing, or sale of assets, your information may be transferred as part of the transaction, subject to customary confidentiality safeguards. We will notify you before your information becomes subject to a materially different privacy policy.
4. Code, Repository Files, Chat History, Attachments, and Environment Data
Because the Service depends on synchronizing source code and configuration between devices and sandbox environments, the following practices apply:
4.1 Transport and Storage of Code
To provide synchronization and related functionality, RepoGo may receive and store copies of your code, repository files, diffs, hashes, commit metadata, and related configuration on our systems and object storage used by us. This may include database records, cached copies, and content-addressable blob storage used for sync, offline access, conflict resolution, recovery, and continuity of the Service.
Depending on the feature, some copies may persist until you delete the relevant project, disconnect the integration, or close your account, subject to backups and provider retention.
4.2 Environment Files (.env) and Secrets
When you add an environment file to RepoGo, the environment file and its contents are stored by RepoGo and transmitted to the applicable sandbox provider when your sandbox starts, so that the environment values are available to processes running inside the sandbox. You acknowledge that:
- Environment files may contain sensitive credentials, API keys, and secrets
- You are responsible for the contents of your environment files and for ensuring that you have the right to transmit them to third-party sandbox providers
- After transmission to a sandbox provider, environment data is handled under that provider's security controls and retention practices
- You should rotate credentials that you believe may have been exposed and remove environment files you no longer wish RepoGo to transmit
RepoGo uses commercially reasonable technical and organizational measures to protect environment data in transit and at rest on our systems, including encryption, access controls, and audit logging, but cannot guarantee absolute security.
4.3 Prompts and AI Inputs
When you use chat or AI-agent features, prompts, responses, tool outputs, attachments, and message parts may be stored in our databases and object storage so that you can reload conversations, continue work across devices, and allow the Service to rehydrate large or offloaded message payloads. In some cases, large message parts or attachments may be stored in object storage and referenced by key from our database.
When you invoke an AI agent, the prompts you submit and the file contents included as context are transmitted to one or more of the known possible AI companies disclosed in the permission sheet. The app asks for permission before the first applicable transmission, and declining cancels the request. RepoGo may also process or retain this data for debugging, rate limiting, abuse prevention, and service reliability.
4.4 Local Device Storage and Offline Copies
RepoGo may store local copies of repositories, chats, attachments, caches, and configuration data on your devices to support offline use, previews, widgets, and background synchronization. Data stored locally is subject to your device security, backup providers, and operating system behavior.
5. Data Security
We implement a combination of technical and organizational measures to protect your information:
Technical Safeguards:
- Encryption in transit (TLS)
- Encryption at rest for sensitive stored data, including environment files and credentials
- Token scoping and least-privilege access
- Regular security reviews and vulnerability management
Operational Safeguards:
- Access controls and authentication requirements
- Incident-response, change-management, and service-reliability procedures
- Vendor review and permission management appropriate to the services we use
However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk. You are responsible for protecting your own account credentials and the credentials you submit for third-party integrations.
6. Data Retention
We retain your information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements:
- Account Data: Until you delete your account
- Code, Repositories, Diffs, and Sync Metadata: Until you delete them, disconnect the relevant integration, or close your account, subject to caches, backups, and provider retention
- Chat Histories, Messages, Tool Outputs, and Message Parts: Until you delete the relevant chat or close your account, or until they are removed automatically under our retention and TTL policies, whichever comes first — see Section 6.5 of the Terms of Service. RepoGo is not a system of record for conversations; chats and transcripts may be deleted automatically based on age, volume, size, plan tier, or inactivity
- Environment Files and Integration Credentials: Until you delete them from RepoGo; however, values already transmitted to sandbox, gateway, or AI providers are subject to that provider's retention
- Uploads and Attachments: Until you delete the relevant content or close your account, subject to backups and storage-provider retention
- Usage Logs and Diagnostics: Typically up to 90 days
- Payment Records: As required by tax and financial laws (typically up to 7 years)
- Backups: May persist for a commercially reasonable period after deletion (generally up to 90 days)
Planned chat cleanup. We do not plan to routinely delete your recent chat history. We do anticipate that a background service will clean up chat conversations older than approximately six (6) months. This is not implemented as of the Last Updated date above; it is disclosed here so you can expect it. The window may change, and may differ by plan tier. It describes what we currently intend, not a commitment to retain any conversation for a minimum period — a newer chat may still be removed under the other factors described below.
We may apply time-to-live ("TTL") and cleanup policies that delete transient data — chat conversations, agent transcripts, tool and terminal output, previews, caches, and temporary blobs — earlier than the periods above, based on age, volume, size, plan tier, inactivity, or operational need. Your source-control provider (GitHub) remains the authoritative record of your code, and CLI-agent sessions persist on disk in the environment where the agent runs, so they can typically be resumed with that provider's own tooling even after the conversation is removed from RepoGo.
7. Your Rights and Choices
7.1 Access and Portability
You have the right to access your personal information and to request an export in a portable format.
7.2 Correction and Deletion
You may update your account information, delete your projects and code, remove environment files, and request deletion of your account.
Account deletion is permanent and irreversible. When you delete your account, your data — projects, chats and transcripts, uploads, environment files, stored credentials and integration tokens, device records, and your account profile — is permanently deleted from our servers and cannot be retrieved by you or by us. There is no undo and no recovery process. Export or commit anything you want to keep first.
Three carve-outs apply, for the reasons described in Section 6:
- Residual copies in backups and logs are purged on our ordinary cycle (generally within 90 days) and are not used to re-create your account
- Records we are legally required to keep, such as payment and tax records or data subject to a legal hold, are retained only for the period the law requires
- Data already transmitted to third parties at your direction — GitHub, AI and gateway providers, sandbox and infrastructure providers — remains under that provider's own retention practices. Deleting your RepoGo account does not delete it there, and we cannot recall it. Rotate any credentials you transmitted
7.3 Opt-Out
You may opt out of:
- Marketing communications (via unsubscribe links)
- Non-essential analytics where offered
- AI-agent features (by not invoking them)
- Sandbox provisioning (by not launching sandboxes)
7.4 Third-Party Integrations
You may revoke GitHub OAuth access through your GitHub account settings and remove third-party credentials from RepoGo at any time. Doing so may disable portions of the Service.
7.5 Do Not Track
We do not currently respond to Do Not Track ("DNT") signals, as there is no industry standard.
8. Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Service, maintain sessions, remember preferences, and analyze usage. You can control cookies through your browser settings. Disabling certain cookies may impair functionality.
9. Children's Privacy
The Service is not directed to, and not intended for use by, children under 13 years of age. You must be at least 13 years old to use the Service. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will promptly delete it and terminate the account in accordance with the Children's Online Privacy Protection Act ("COPPA") and other applicable laws.
If you reside in the European Economic Area, the United Kingdom, or another jurisdiction with a higher age of digital consent, you must meet the minimum age of digital consent in your jurisdiction (typically 16) or obtain the consent of a parent or legal guardian.
If you are a parent or guardian and believe your child has provided information to us, please contact repogoapp@gmail.com so we can remove the information.
10. International Data Transfers
Your information may be transferred to, processed, and stored in countries other than the country in which you reside, including the United States. Where required by law (for example, transfers out of the EEA or UK), we use appropriate safeguards, such as Standard Contractual Clauses, to protect your information.
11. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the CPRA:
- Right to Know what personal information we collect, the sources, purposes, and categories of recipients
- Right to Delete your personal information, subject to legal exceptions
- Right to Correct inaccurate personal information
- Right to Opt-Out of Sale/Sharing (we do not sell personal information or share it for cross-context behavioral advertising)
- Right to Limit Use of Sensitive Personal Information
- Right to Non-Discrimination for exercising your rights
To exercise these rights, contact repogoapp@gmail.com.
12. European Privacy Rights (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the GDPR and UK GDPR.
Legal Bases for Processing:
- Performance of a contract (to provide the Service)
- Legitimate interests (security, product improvement, fraud prevention)
- Consent (for marketing and certain analytics, where required)
- Legal obligations
Your Rights:
- Access, rectification, and erasure ("right to be forgotten")
- Restriction of processing and objection to processing
- Data portability
- Withdraw consent at any time (without affecting prior processing)
- Lodge a complaint with a supervisory authority
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date and, for material changes, provide notice via email, in-app notification, or website banner. Continued use of the Service after changes take effect constitutes acceptance.
14. Third-Party Links and Services
The Service may contain links to, or integrate with, third-party websites and services. We are not responsible for the privacy practices of those third parties. Please review their privacy policies before providing them with your information.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us at:
Email: repogoapp@gmail.com
Website: https://repogo.app
16. Data Protection Contact
For EU/EEA, UK, and Swiss Users, or for any other privacy-specific inquiries, you can reach us at:
- Email: repogoapp@gmail.com
By using RepoGo, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, transmission, and disclosure of your information as described herein, including the transmission of your code, files, and environment variables to third-party sandbox and AI providers as necessary to provide the Service.