Legal

Privacy Policy

Last updated:

RepoMuse (https://repomuse.com) generates social posts from prompts and connected data you provide. This policy explains what we collect and why.

Data controller

Ferracuti Gabriele

Via Svarchi, 63824, Altidona (FM), Italy

VAT number: IT02023040443

Data we process

  • Account email, name, and authentication data (via Better Auth)
  • Project inputs (site or repository URL, prompts, author-voice samples) and the generated posts and generation metadata produced from them
  • Connected GitHub repository contents (README, releases, merged pull requests, commits) when you link a repo - read-only, never published to on your behalf
  • Credit ledger and payment references (processed by Dodo Payments as merchant of record)
  • API tokens and OAuth access tokens (stored hashed / opaque) and optional webhook endpoints you configure
  • Aggregate page views and selected product-interaction analytics events
  • Operational error and performance telemetry used to diagnose service failures

Analytics and operational telemetry

We use a self-hosted Rybbit instance for website analytics and a typed product-event system for selected interactions, including tool-page views, CTA clicks, and conversion events. Rybbit does not set cookies. Product events that originate on the server (for example an MCP tool call or a completed purchase) are sent to the same analytics endpoint with only the event name and non-personal properties. Operational telemetry may include route, request, browser, performance, and error context. Product-event payloads are designed not to include prompts, email addresses, or API tokens.

AI, research, and integration providers

To generate content, your prompts and connected data are sent to third-party providers. Generation and research may use one or more of:

  • AI model providers - Anthropic, DeepSeek, Google, OpenAI, or Z.AI (Coding Plan). Do not include secrets or personal data you are not comfortable sharing with these providers.
  • Research connectors - Serper, Tavily, or Firecrawl - used to fetch competitor and context pages for a generation. Crawls and searches are capped and time-limited, and the returned text is treated as untrusted input.
  • GitHub - when you connect a repository, RepoMuse reads repository contents via a short-lived installation token minted from your GitHub App installation. No GitHub user credential is stored.

Retention

When you delete your account, we remove projects, posts, connected repositories, API tokens, and authentication data. Payment, subscription, and credit-ledger records may be retained for financial, tax, fraud, refund, and chargeback obligations.

Contact

Questions: privacy@repomuse.com