Privacy Policy
Effective 27 September 2026
This Privacy Policy explains how DeepGraph collects, uses, and protects personal data when you visit deepgraph.app, use the DeepGraph web app, or contact us. It also explains how we handle information about the contributors whose Git activity appears in the repositories you analyze.
In short:
- we collect only what we need to run DeepGraph and bill for it;
- we do not sell personal data or use it for advertising;
- we use no advertising or cross-site tracking cookies; and
- you can delete your account and its data yourself at any time.
Who we are
DeepGraph is operated by A.I. Victor Chicu, a sole proprietorship registered in the Republic of Moldova under IDNO 1026023023591, with its registered address at Bulevardul Moscova 9/5, Chișinău, Republic of Moldova (“DeepGraph”, “we”, “us”).
For your account, billing, and website data, we are the data controller. For contributor information inside the repositories you analyze, we process personal data on your behalf, as described in section 4.
Privacy questions and requests: support@deepgraph.app.
Data we collect
Account data
Your name, email address, and profile picture, the display name you choose, and, if you sign in with email, a securely hashed password. When you sign in with GitHub, GitLab, or Bitbucket, we receive your profile from that provider and store the connection so we can access the repositories you authorize. Provider access tokens are stored encrypted.
Repository data
The repositories you analyze, their Git history, and the reports we generate from them. This includes the contributor names and email addresses recorded in commits. For local analysis, your browser uploads the Git history (the .git directory) of the repositories you select, not your working files.
Billing data
Your plan, trial dates, billing status, and a history of plan changes and transactions. Payments are processed by Paddle, our merchant of record. We do not receive or store your card details.
Session and security data
For each signed-in session, we record when it started and was last used and the browser and device type reported by your browser, so you can review your sessions in Settings → Security. We use IP addresses temporarily to limit request rates and protect sign-in against abuse.
Product usage data
Events about how DeepGraph is used, such as starting an analysis or opening a report, linked to your account ID. We send these events to our product analytics provider without your IP address.
Messages you send us
The name, email address, and message you send through the contact support form or by email.
We do not intentionally collect special categories of personal data, such as health or political opinions.
How and why we use it
- To provide DeepGraph: creating your account, running analyses, showing reports, and keeping your sessions secure. Legal basis: our contract with you.
- To bill for plans: managing trials, plans, and cancellations, and keeping records required by accounting and tax law. Legal basis: our contract with you and our legal obligations.
- To send service emails: sign-in codes, security notices, and important changes to DeepGraph or these policies. Legal basis: our contract with you.
- To improve and protect DeepGraph: understanding which features are used, fixing problems, and preventing abuse. Legal basis: our legitimate interest in running a reliable and secure service.
- To answer you: replying to support messages. Legal basis: our legitimate interest in responding to people who contact us, or steps you ask us to take before entering a contract.
We do not send marketing emails today. If we start, we will ask for your consent where the law requires it, and every such email will include a way to unsubscribe.
Contributor information in your repositories
Commits contain the names and email addresses of the people who made them. When you analyze a repository, DeepGraph processes this information on your behalf and according to your instructions: to build contributor profiles, link identities, and show activity. You decide which repositories to analyze, can link or exclude contributor identities, and can delete analyses at any time.
If you are a contributor and want to know about or object to how your information is used in someone’s DeepGraph reports, please contact the person or organization that analyzed the repository. You can also write to us at support@deepgraph.app, and we will help direct your request.
Who we share it with
We share personal data only with the service providers that help us run DeepGraph, each limited to what it needs:
- Hosting and infrastructure: Cloudflare, which delivers the website and protects traffic to our API, and the provider of the server where the API and database run.
- Payments: Paddle, which processes purchases as merchant of record under its own privacy notice.
- Repository providers: GitHub, GitLab, and Bitbucket, when you sign in with them or connect repositories.
- Email delivery: our email service provider, which sends sign-in codes and service emails.
- Product analytics: Mixpanel, which receives the usage events described in section 2.
We may also disclose personal data:
- when the law requires it, such as a valid request from a court or public authority;
- to protect our rights, the safety of our users, or to investigate fraud or abuse; and
- to a buyer or successor if DeepGraph is sold or merged, under this Policy.
We never sell personal data.
International transfers
DeepGraph is operated from the Republic of Moldova, and some of our service providers process data in other countries, including the United States. Where the law requires it, we rely on appropriate safeguards for these transfers, such as the European Commission’s Standard Contractual Clauses offered by our providers.
How long we keep it
- Account, repository, and report data: until you delete the analysis or your account. Deleting your account in Settings permanently removes your analyses, reports, sessions, and account data.
- Sessions: signed-in and guest sessions expire after thirty (30) days, or earlier when you sign out.
- Local uploads: uploaded Git history is used to build your analysis and is deleted when the analysis is rebuilt or deleted, or when you delete your account; an upload that does not finish is deleted seven days after it last received data, and temporary copies used to build an analysis are removed.
- Billing records: Paddle, as merchant of record, keeps payment and invoice records under its own legal obligations. Our copy of your plan and transaction history is deleted with your account.
- Messages you send us: for as long as needed to handle your request and any resulting relationship.
Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate data, or delete your data;
- restrict or object to processing based on legitimate interest;
- receive your data in a portable format, where processing is based on contract or consent; and
- withdraw consent at any time, where processing is based on it.
You can update your name and delete your account yourself in Settings. For other requests, write to us at support@deepgraph.app. We will answer within the time required by law, usually within one month. We may need to verify your identity first.
If you believe we handle your data unlawfully, you can complain to the National Center for Personal Data Protection of the Republic of Moldova or, if you are in the European Union or European Economic Area, to the data protection authority where you live or work.
Cookies and browser storage
DeepGraph uses only cookies that are needed for the service to work. We do not use advertising, cross-site tracking, or third-party analytics cookies, so we do not show a cookie banner.
- Session cookies: keep you signed in, or keep your guest session, for up to thirty (30) days.
- Sign-in cookies: short-lived cookies that protect the sign-in flow with GitHub, GitLab, Bitbucket, or email.
- Security cookies: Cloudflare may set cookies that protect the website against bots and attacks.
DeepGraph also uses your browser’s local storage to remember preferences, such as your theme and report views, and to restore your last project after a reload. This data stays in your browser. You can clear it, and your cookies, in your browser settings; you will then be signed out and your preferences reset.
Security
We protect personal data with measures such as encrypted connections, encrypted provider tokens, hashed passwords and session tokens, and access limited to the data each part of the service needs. No system is perfectly secure, but we work to protect your data and will notify you and the authorities of a breach where the law requires it.
Children
DeepGraph is not intended for children under sixteen (16), and we do not knowingly collect their personal data.
Changes to this Policy
We may update this Policy. We will post the new version on this page with a new date, and notify you by email or in the app about material changes.
Contact
For any question about this Policy or your personal data, write to support@deepgraph.app, or by post to A.I. Victor Chicu, Bulevardul Moscova 9/5, Chișinău, Republic of Moldova.