Privacy Policy

Last updated: February 1, 2026

Who we are

Cocommit is operated by Code Foundry, a company based in Belgium. We build tools that help engineering managers prepare for 1:1 meetings with their team members.

For privacy questions, contact us at hello@cocommit.app.

What we collect

We collect the following data:

  • Account information: Your name, email address, and profile picture from GitHub when you sign in.
  • Integration tokens: OAuth access tokens for GitHub and Jira to fetch activity data on your behalf.
  • Team member data: Names, GitHub usernames, and Jira user IDs of the people you manage.
  • Activity metadata: PR titles, commit messages, and Jira ticket summaries. We never access or store your actual source code.
  • Your notes: 1:1 prep summaries, personal notes, and action items you create in the app.
  • Usage data: Basic analytics to understand how the product is used (pages visited, features used).

What we do not collect

  • We do not access or store your source code.
  • We do not read the contents of your files, PRs, or commits.
  • We do not share your data with third parties for advertising purposes.

How we use your data

  • To generate 1:1 prep summaries and talking points.
  • To store your notes and action items for future reference.
  • To improve the product based on usage patterns.
  • To send you important updates about your account or the service.

Third-party services

We use the following third-party services:

  • GitHub API: To fetch PR, commit, and code review data for your team members.
  • Jira API: To fetch ticket and issue data for your team members.
  • OpenAI: To generate AI-powered summaries and talking points. We send activity metadata (not source code) to OpenAI for processing.
  • Clicky: For basic website analytics (page views, visitor counts).
  • Vercel: For hosting the application.

Data storage and security

Your data is stored in a PostgreSQL database. OAuth tokens are encrypted at rest. We use HTTPS for all data transmission. We do not sell your data to third parties.

Your rights

Under GDPR and similar regulations, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data.
  • Export your data in a portable format.
  • Withdraw consent for data processing.

To exercise these rights, email us at hello@cocommit.app.

Data retention

We retain your data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are required by law to retain it.

Cookies

We use essential cookies for authentication and session management. We use analytics cookies (Clicky) to understand how the product is used. You can disable cookies in your browser settings.

Changes to this policy

We may update this policy from time to time. We will notify you of significant changes by email or through the app.

Contact

For questions about this privacy policy, contact us at hello@cocommit.app.