Privacy Policy
Last updated: December 23, 2025
1. Introduction
Welcome to Makrly ("we," "our," or "us"). We are committed to protecting your privacy and ensuring you understand how we collect, use, and safeguard your information when you use our service at makrly.com (the "Service").
2. Information We Collect
2.1 Information from GitHub
When you authenticate with GitHub, we collect:
- Your GitHub username and profile information
- Your email address associated with your GitHub account
- Access to your public and private repositories (based on permissions you grant)
- Commit messages, diffs, and metadata from repositories you connect
- Commit author information: When you connect a repository, we collect commit metadata including author names and email addresses from your commit history. This may include data from other contributors to the repository.
2.2 Information You Provide
- Your content preferences and personality quiz responses
- Social media platform preferences
- Payment information (processed securely by Stripe)
2.3 Automatically Collected Information
- Usage data and analytics
- Device and browser information
- IP address and location data
2.4 Changelog Widget Analytics
If you embed our changelog widget on your website, we collect the following information from visitors who view the widget:
- Hashed IP address: We use a one-way hash (SHA-256) of visitor IP addresses for rate limiting and analytics purposes. We do not store raw IP addresses.
- User agent: Browser and device information
- Referrer: The URL of the page where the widget is embedded
- View timestamps: When changelog entries are viewed
This data is collected to provide view counts and analytics for your changelog entries. Rate limiting (one view per IP per hour) prevents abuse.
2.5 Image Processing
When you use our social media graphics features (code snippets, browser mockups, image editing), all image processing occurs in your browser. We do not upload, store, or process your images on our servers. The images you create remain entirely on your device until you choose to download or share them.
3. How We Use Your Information
We use the information we collect to:
- Generate social media posts from your GitHub commits using AI
- Personalize content based on your preferences and writing style
- Process payments and manage your subscription
- Improve and optimize our Service
- Communicate with you about your account and updates
- Detect and prevent fraud or abuse
4. AI Processing
We use third-party AI services to generate social media posts from your commit data. Your commit messages and related metadata are sent to these services for processing. We do not use your data to train AI models.
AI Providers we use:
- OpenAI - For GPT-4o and GPT-4o-mini models
- OpenRouter - A routing service that may connect to Anthropic (Claude), Google (Gemini), Meta (Llama), and other AI providers
- Straico - An AI platform providing access to multiple language models
If you provide your own API keys, the respective AI provider's terms of service and privacy policy apply to that processing. The AI providers process your data according to their respective privacy policies and data processing agreements.
5. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:
- Contract: Processing necessary to provide the Service you signed up for, including generating posts from your commits and managing your subscription.
- Legitimate Interest: Processing necessary for our legitimate interests, such as improving our Service, preventing fraud, and ensuring security, where these interests are not overridden by your rights.
- Consent: Where you have given explicit consent, such as for optional features or marketing communications.
6. Data Sharing
We do not sell your personal information. We may share your data with:
- Service Providers: Third parties that help us operate our Service (payment processing via Stripe, database hosting via Neon, analytics)
- AI Providers: To generate content as described above
- Legal Requirements: When required by law or to protect our rights
7. Data Security
We implement appropriate technical and organizational measures to protect your personal information. This includes encryption in transit and at rest (including API keys and access tokens), secure authentication, and regular security reviews. However, no method of transmission over the Internet is 100% secure.
8. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with our Service. Specific retention periods:
- Account data: Retained while your account is active. Deleted within 30 days of account deletion.
- Commit and post data: Deleted immediately when you delete your account or remove a repository.
- Payment records: Retained for 7 years as required by tax and accounting laws.
- Backups: Purged within 90 days of data deletion.
You can delete your account at any time from your Settings page, or by contacting us at hello@makrly.com.
9. Your Rights
Depending on your location (particularly if you are in the EU/EEA), you have the following rights under GDPR:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Delete your personal information ("right to be forgotten")
- Right to Data Portability: Export your data in a machine-readable format
- Right to Restrict Processing: Limit how we use your data
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Where processing is based on consent
To exercise these rights, visit your Settings page to export or delete your data, or contact us at hello@makrly.com.
11. Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for their privacy practices. We encourage you to review their privacy policies.
12. Children's Privacy
Our Service is not intended for children under 13 years of age (or 16 in the EU/EEA). We do not knowingly collect personal information from children under these ages.
13. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States where our servers are located. We ensure appropriate safeguards are in place for such transfers, including Standard Contractual Clauses where required.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we may also notify you via email.
15. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:
- Email: hello@makrly.com