Privacy Policy
Last updated 29 August 2026 · applies to bnlgit.com and the hosted BNLGit service
1. Controller
Blue Note Logic Inc, 117 N Swain Street, Raleigh, North Carolina 27601, is the controller for the personal data described here. Contact privacy@bnlgit.com for anything on this page.
2. The short version
- We collect the minimum needed to run an account and take payment.
- We do not use your code or your content to train models.
- We do not sell personal data, and we do not run advertising or third-party analytics on this site.
- Your code is sent to an AI provider only when you connect one and you ask for generation.
3. What we collect and why
Account data
Your email address, forge username, password hash, and any profile details you choose to add. Purpose: to create and operate your account. Basis: performance of our contract with you.
Billing data
Subscription status, billing period, trial and grace dates, and the identifiers Stripe gives us for your customer and subscription. We never receive or store your full card number. Purpose: to charge you correctly and manage your subscription. Basis: contract, and our legal obligation to keep accounting records.
Repository content
The code, commits, issues, pull requests and other material you put into the service, and the
generated .llm summaries derived from it. This may incidentally contain personal data
(commit author names and email addresses, for example). Purpose: to provide the hosting and
summary features. Basis: contract.
Provider credentials
The API keys you save for your own LLM or Git providers, encrypted at rest with AES-256 under a dedicated key. Purpose: to call the providers you configured, on your instruction. Basis: contract. See BYOK connections and security.
Operational logs
Server and application logs including IP address, timestamp, request path and user agent, and records of summary generation (token counts, cost, model, outcome). Purpose: to keep the service secure and working, to investigate abuse, and to show you what your generation actually cost. Basis: our legitimate interest in operating a secure service, and contract.
Correspondence
Emails you send us and our replies. Purpose: to support you. Basis: legitimate interest.
4. This website
bnlgit.com is static. It sets no cookies, loads no fonts, scripts or assets from any third-party CDN, and runs no third-party analytics or advertising trackers. Web server access logs are kept as described above.
5. Who we share data with
| Stripe | Payment processing. Receives your email address and payment details directly. |
| Hosting providers | The infrastructure the service runs on. Our production infrastructure is located in the EU. |
| Email delivery | Sending account, billing and security emails to you. |
| Your AI provider | Only the one you connect. Receives the file contents needed for a summary, bake-off or analysis you requested. Their own privacy policy governs that processing. |
We do not sell personal data and we do not share it for advertising.
6. International transfers
Our own infrastructure is in the EU. If you connect an AI provider outside the EEA, your content goes there because you instructed it to — you choose the provider, and you can choose an EU-hosted one. Where our own processors are outside the EEA, transfers rely on the European Commission's standard contractual clauses.
7. How long we keep things
- Account and repository data — for as long as your account is active, then 30 days after cancellation, then removed. Deletion is confirmed by a person rather than fired automatically.
- Backups — cycled out on their own rolling schedule shortly after deletion.
- Billing and accounting records — kept as long as tax law requires, typically five years, even after your account is gone.
- Operational logs — a short rolling window, then discarded.
8. Security
Access is authorised per request against the permission model; provider credentials are encrypted at rest under a dedicated key and never returned in plaintext by any API; outbound requests are restricted from reaching internal and cloud-metadata addresses. The full picture, including what the shared beta does not isolate, is on the Security and data handling page — we would rather you read the honest version than a reassuring one.
9. Your rights
Under the GDPR you have the right to access your data, correct it, have it deleted, restrict or object to processing, and receive it in a portable form. To exercise any of these, mail privacy@bnlgit.com. We will respond within one month.
Portability is largely self-service: everything of substance is a Git repository, so
git clone gives you a complete, standard-format copy at any time.
You also have the right to complain to your national data protection authority.
10. Data in your repositories
If you store other people's personal data in a repository, you are the controller for it and we are your processor. You are responsible for having a lawful basis for putting it there, and for considering whether sending it to a third-party AI provider is appropriate before you request generation on it.
11. Children
The service is not directed at children and we do not knowingly collect their data.
12. Changes
If we change this policy materially we will email account holders before it takes effect. The "last updated" date above always reflects the current version.
13. Contact
privacy@bnlgit.com for privacy; hello@bnlgit.com for everything else.