internal/web/templates/privacy.html

1ed9fb9399b21da8e6cf45be8389792aac82d5bc
gitbay/internal/web/templates/privacy.html history · blame · raw

43 lines · 2130 bytes

 1{{define "width"}}bounded{{end}}
 2{{define "title"}}privacy · {{.Site}}{{end}}
 3{{define "content"}}
 4<div class="landing">
 5<h1>Privacy</h1>
 6
 7<h2>The software</h2>
 8<p>This site runs <a href="https://gitbay.org/krz/gitbay">gitbay</a>, a
 9self-hosted, CLI-first git forge. The software makes no external
10requests from your browser: no analytics, no CDNs, no webfonts, no
11tracking of any kind. Everything you see is served from this host.</p>
12<p>What the server stores is what a forge needs to function: your
13account (username, email addresses, public SSH/PGP keys), the
14repositories and their contents, issues, merge requests, comments, and
15a security audit log of account and repository actions (recording the
16acting user, the action, and the public key fingerprint used). Web
17sessions use a single cookie, only after you log in. Private
18repositories are visible only to accounts you grant; to everyone else
19they are indistinguishable from nonexistent.</p>
20<p>Your data is portable by design: <code>gitbay auth export</code>
21downloads your account bundle, git data is yours by clone, and
22<code>gitbay migrate</code> moves everything to another instance.</p>
23
24<h2>The mobile client</h2>
25<p>The iOS app is a client for an instance you name at sign-in. It has
26no account of its own, no sign-up, and no server of ours behind it: it
27speaks only to that instance, over HTTPS.</p>
28<p>Signing in stores one API token in the device Keychain. Which account
29is active is kept in app preferences; nothing else is retained on the
30device. The app embeds no analytics, no crash reporting, and no
31third-party SDK, so there is nothing to opt out of. Removing the account
32deletes the token from the Keychain.</p>
33<p>Tokens are minted over SSH and can be revoked at any time with
34<code>gitbay auth token revoke</code>, which ends the app's access
35immediately.</p>
36
37<h2>This instance ({{.Host}})</h2>
38{{if .Notice}}{{range paragraphs .Notice}}<p>{{.}}</p>{{end}}
39{{else}}<p class="desc">The operator of this instance has not added
40instance-specific notes. Questions about backups, retention, or
41jurisdiction go to the operator.</p>{{end}}
42</div>
43{{end}}