Privacy
Last updated: September 2026
The short version: the Git Tree app sends no telemetry and your repositories stay on your computer. The app asks you to sign in with your Git Tree account, and this page lists exactly what that account stores.
The Git Tree app
Git Tree runs entirely on your computer. It has no telemetry, analytics or crash reporting that sends data anywhere. Your Git Tree account, created on this website, stores only what is listed below.
With default settings, the only network connections the app makes are to the Git remotes you fetch from or push to, the hosting accounts you choose to connect, and a check for updates that you can switch off. Because you sign in to your Git Tree account from the app, it also contacts the Git Tree account service described below.
Credentials
Connecting a GitHub or Bitbucket account in the app is optional. Tokens, passwords and passphrases are stored only in your operating system’s keychain — the macOS Keychain, the Windows Credential Manager or, on Linux, the system keyring through the freedesktop Secret Service (GNOME Keyring or KeePassXC) — and are sent only to the provider they belong to. On Linux, if no Secret Service is running or it is locked, the app tells you what to install or unlock and keeps nothing: no token, no sign-in session and no plaintext file.
Your Git Tree account
You create your account on this website by signing in with a provider account — today GitHub, which is asked only for your public profile and your email addresses (the read:user and user:email permissions). Git Tree’s servers complete that sign-in with the provider themselves; the website and the app only ever receive a Git Tree session, and the Git Tree service never keeps a provider access token. Connecting GitHub for repositories and pull requests in the desktop app is a separate, optional step; that token is stored only in your computer’s keychain.
For each account we store: your display name, username, primary verified email address and avatar URL; the provider you signed up with; whether you use Git Tree as an individual or an organization; when the account was created, when you last signed in and how many times you have signed in; and, when you sign in from the desktop app, the app version and operating system you last used.
For each provider account linked to your Git Tree account we store the provider, your user id and username there, your email address and avatar URL, when it was linked and when you last signed in with it.
The desktop app signs in through this website: once you confirm, the site hands the app a one-time code that works once and expires after five minutes. Such codes, and the tickets that finish a new sign-up, are short-lived, and we store only a one-way hash of them.
If you create or join organizations, we store each organization’s name and address, its members and their roles, and when each member joined. Other members of an organization can see your username, name, avatar and role in it.
Invitations are stored with the organization, the role offered, the invited GitHub username or email address, who sent it, when it expires and how often it has been used. Email invitations are delivered through Firebase’s email extension. Invitation links carry a secret token; we store only a one-way hash of it.
This data lives in Google Cloud Firestore and Firebase Authentication in the Git Tree Firebase project. Only Git Tree’s own servers read it; the website and the app never access the database directly. We do not sell it or share it with advertisers.
Deleting your account
You can delete your account at any time from your dashboard on this website (Account settings). Deletion removes your Git Tree profile, your linked provider accounts, your organization memberships and your Firebase sign-in record; your personal data is not retained afterwards.
If you are the last owner of an organization, make another member an owner or delete the organization first, so that no organization is left without an owner.
This website
This website sets one functional cookie that remembers your language. It contains no personal data.
If you sign in, Firebase Authentication keeps your session in this browser’s storage, and the site keeps a small flag in local storage so the header can show your account menu. Signing out removes both. While a sign-in is in progress, its one-time values stay in this tab’s session storage until you return from the provider.
If you accept the analytics notice, the site loads Google Analytics through Firebase to count page views and learn which pages are useful. Google sets its own analytics cookies for this. If you decline, or never answer, no analytics code is downloaded. You can change your mind by clearing this site’s data in your browser.
We do not use advertising trackers. Our hosting provider, Firebase App Hosting on Google Cloud, may keep standard server logs, such as IP addresses and requested pages, for security and reliability.
Download links take you to GitHub, whose own privacy policy applies there. The Linux installers (.deb and AppImage) are unsigned; the SHA256SUMS.txt published with each release is how you check a download.
Contact
Questions about privacy? Open an issue on the project’s GitHub repository.