Legal
Privacy Policy
Last updated: June 28, 2025
1. Overview
HivarSoft(“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share information when you use our products — including Notes AI and PulseWatch — and when you connect third-party services via OAuth (Google, GitHub, GitLab, Bitbucket).
We follow the principle of data minimisation — we only collect what is strictly necessary to provide the service you requested.
2. Information We Collect
2.1 Account Information
When you sign up or sign in via OAuth, we receive basic profile information including your name, email address, and profile picture — used solely to create and manage your account.
2.2 OAuth Data — By Provider
We receive the following data from Google upon authorisation:
- •
openid— Verify your identity - •
email— Your email address for account identification - •
profile— Your name and profile picture
What we do NOT access: Gmail, Google Drive, Google Calendar, Contacts, or any other Google service data.
🐙 GitHub
For GitStats users who connect GitHub:
- •
read:user— GitHub username, avatar, and public profile - •
repo (read-only)— Repository names, commit history, branch names, author metadata, and file statistics
What we do NOT access: repository secrets, GitHub Actions, Issues, Pull Request content, billing information, or SSH keys.
🦊 GitLab
For GitStats users who connect GitLab:
- •
read_user— GitLab username, email, and avatar - •
read_repository— Commit logs, branch names, and contributor metadata
What we do NOT access: Merge Requests, CI/CD pipelines, container registry, or deployment keys.
🪣 Bitbucket
For GitStats users who connect Bitbucket:
- •
account— Bitbucket account username and avatar - •
repositories— Repository list, commits, branches, and file history (read-only)
What we do NOT access: Bitbucket Pipelines, Deployments, Jira integrations, or team billing data.
2.3 Usage Data
We may collect anonymous usage data such as page views and feature interactions to improve our products. This data is aggregated and cannot identify individual users.
2.4 User-Generated Content
For Notes AI, the notes and files you create are stored securely and associated with your account. This content is private to you and never shared without your explicit consent.
3. How We Use Your Information
- •To create and authenticate your account.
- •To provide and improve our services (e.g., generate Git analytics, serve your notes).
- •To communicate with you about your account or service updates.
- •To detect and prevent fraud, abuse, or security incidents.
- •To comply with legal obligations.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
4. Data Storage and Security
Your data is stored on secure servers with industry-standard protections, including:
- •HTTPS encryption for all data in transit.
- •Encrypted storage for OAuth access tokens.
- •Access controls limiting data access to authorised personnel only.
- •Regular security reviews of our codebase and infrastructure.
5. Data Retention
We retain your account data for as long as your account is active. Git repository data imported for analytics is processed in-session and not permanently stored beyond your dashboard. Upon account deletion, your personal data is removed within 30 days, except where retention is required by law.
5. Data Retention
For PulseWatch we retain the response code with timestamp for the health route provided by user for a service, these logs are stored untill the account is active. Upon account deletion, your personal data is removed within 30 days, except where retention is required by law.
6. Your Rights
You have the right to:
- •Access the personal data we hold about you.
- •Request correction of inaccurate data.
- •Request deletion of your account and associated data.
- •Withdraw OAuth consent at any time via your provider's app authorisation settings.
- •Object to or restrict certain processing of your data.
- •Lodge a complaint with a data protection authority.
To exercise any of these rights, contact us at hello@hivarsoft.com.
7. Revoking OAuth Access
You can revoke our access to your connected accounts at any time:
8. Cookies and Tracking
We use essential cookies to maintain your authenticated session. We do not use third-party advertising cookies or cross-site tracking.
9. Third-Party Services
Our services may rely on trusted third-party infrastructure providers bound by data processing agreements. We do not integrate advertising networks or sell data to data brokers.
10. Children's Privacy
Our services are not directed to children under 13. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected in the “Last updated” date. Continued use of our services constitutes acceptance.
12. Contact Us
If you have questions or requests regarding this Privacy Policy, please contact us: