Clear about the data that moves through the product.
This policy explains how Branch Manager for Git processes information when you use the web app or native iOS and Android apps.
The information Branch Manager processes.
Branch Manager processes the information needed to authenticate you, save the Git connections you choose, show current provider information, and perform the repository actions you request.
Git connection information
Provider metadata and actions
Product-use analytics
To operate the workspace you ask us to provide.
We use this information to provide authenticated access, maintain your saved connections, retrieve current Git-provider context, and carry out actions you initiate.
Authenticate and scope the session
The signed-in account determines which saved server records and API operations you can access in Branch Manager.
Connect to the Git host you selected
Branch Manager uses the connection credential only when it needs to make a provider request for a feature you initiated.
Show current repository context
The product retrieves provider metadata so it can list repositories, filter by server or organization, and show repository details and recent commits.
Carry out a requested action
Repository creation, supported setting updates, and deletion requests are sent to the selected provider. That provider remains the durable system of record for its resources.
Understand product use with constrained analytics
If you choose to allow analytics, we use manually selected, non-content events to understand broad navigation and feature adoption. We do not configure session replay, click or touch autocapture, error capture, marketing attribution, or account-level analytics profiles.
Where information is processed to deliver the product.
The following services are involved in the current architecture. Each operates under its own terms and privacy practices.
Clerk — authentication and sessions
Clerk handles the sign-in and session layer. Branch Manager uses the authenticated user ID it supplies to scope application data and API requests.
Read its privacy policyCloudflare Workers and D1 — application delivery and storage
Cloudflare Workers runs the public Branch Manager web and API application, and Cloudflare D1 stores saved connection records. Cloudflare may process network, request, and application-storage data according to the configured services and its policies.
Read its privacy policyPostHog — product analytics
When you allow it, PostHog receives limited pseudonymous device or browser, app, and event information for the product-use analytics described above. Branch Manager does not identify PostHog with a Clerk user ID or send Git content or connection details to it.
Read its privacy policyBranch Manager application records
The Branch Manager Worker and Cloudflare D1 database process the saved connection record associated with your account, including encrypted credential material and timestamps.
The Git host you choose
GitHub, GitLab, Gitea, or another Git host you connect receives the credential and request needed to complete a provider action. Your provider's own policy governs its account, repository, and audit data.
Credential and account safeguards.
- Personal access tokens are encrypted with authenticated AES-256-GCM before database persistence.
- Stored tokens are decrypted in server memory only when needed for a Git-provider request and are not returned by the public API.
- Protected API operations and saved connections are scoped to the authenticated Branch Manager account.
- Production Git connections require HTTPS; local, private, link-local, multicast, and reserved network targets are blocked by default.
What the reviewed application database keeps.
- One saved server record can contain the user ID, server label, type, URL, appearance choices, encrypted token material, and timestamps.
- The reviewed database does not have separate repository, organization, commit, or Clerk-profile tables.
- Repository, organization, and commit information is retrieved from the selected provider for the active view and may remain subject to provider-side retention.
- When you expressly copy a clone URL, the device or browser controls the clipboard; Branch Manager does not make an additional network request for that copy.
Product analytics are optional.
Branch Manager does not start PostHog product analytics or send product-use events until you make an affirmative choice to allow them. Declining does not limit the core Git-management features.
Change or withdraw consent at any time.
In the web app, open Analytics privacy in the sidebar. In the iOS and Android apps, open Account and change the Product analytics preference. Turning it off stops future PostHog capture and clears the local analytics state on that browser or device.
The web choice is saved locally for that browser. On mobile, the local choice is scoped to the signed-in account on that device and is not synced to Branch Manager servers. You may need to set it again after using a different device or clearing local app/browser data.
Remove a connection, or close your account.
A saved connection remains in the active Branch Manager application database until you remove it or delete your account. The product’s self-service flow is designed to remove the application data it owns without changing resources at your Git provider.
Account deletion is self-service.
After you sign in and type DELETE, Branch Manager deletes the matching saved server records and encrypted credential material, then requests deletion of the associated Clerk account. It never contacts a Git provider as part of this flow.
This does not delete Git-provider accounts, organizations, repositories, provider audit records, or data held under a provider’s own retention policy. If the Clerk account deletion cannot complete, the saved connection records have already been removed and you can retry the request.
Account deletion clears the local analytics identifier from the browser or device. Because Branch Manager does not send a Clerk account identifier to PostHog, existing analytics events are not joined to the deleted Branch Manager account; their separate retention is described below.
Delete accountBackup and operational records.
This policy describes deletion from the active application records. A precise retention and deletion schedule for database backups, infrastructure logs, Cloudflare logs, PostHog analytics, and any other observability services has not yet been established in the production operating process. Those systems may retain records on a separate schedule until that process is published.
Questions and privacy requests.
Email branch-manager-support@cyberstreamstudios.app for privacy questions or requests to access, correct, or delete Branch Manager application data. We may need to verify your identity before acting on a request, and rights vary by the laws that apply to you.
First-pass policy status
This policy will continue to mature with the product.
The product data practices above reflect the current Cloudflare Workers and Cloudflare D1 deployment. Before a broader public store release, Branch Manager will add the legal publisher name, any required mailing address, confirmed regional and retention details for infrastructure logs and backups, PostHog project region and retention, applicable regional notices, and final iOS/Android SDK disclosures. We will update the date above when this policy changes.
For the current account-deletion process, use https://branch-manager.cyberstreamstudios.app/account-deletion.