Privacy Policy

Last updated: March 2026

Information We Collect

We collect: (a) Account information — email address, GitHub username, display name, and avatar via GitHub OAuth; (b) Payment information — processed and stored exclusively by Stripe (we never see or store your card or bank details); (c) Usage data — agents purchased, queries made, pages visited; (d) Technical data — IP address, browser type, and device information.

How We Use Your Information

We use your information to: provide and maintain the Platform; process transactions and send payment confirmations; communicate important updates about your account; improve the Platform and develop new features; prevent fraud and ensure security; comply with legal obligations.

Payment Processing

All payments are handled by Stripe, Inc. When you make a purchase, your payment information is sent directly to Stripe's PCI-compliant servers. RepoBall stores only Stripe reference IDs (customer ID, subscription ID) — never card numbers, CVVs, or bank account details. Seller payouts are processed through Stripe Connect. See Stripe's privacy policy at stripe.com/privacy for more details.

Cookies & Local Storage

We use: (a) Essential cookies/storage — authentication tokens (rb_token) and session data required to use the Platform; (b) Preference storage — cookie consent choice (rb_cookie_consent), UI preferences; (c) Analytics — anonymized usage data to improve the Platform. You can manage your cookie preferences through your browser settings or the cookie consent banner. Essential cookies cannot be disabled as they are necessary for the Platform to function.

Data Sharing

We do not sell your personal information. We share data only with: (a) Stripe — for payment processing; (b) GitHub — for authentication; (c) Cloud infrastructure providers — for hosting; (d) Law enforcement — when required by law. All third-party providers are bound by their own privacy policies and data protection obligations.

Code & Agent Data

Seller source code is processed to create AI agent knowledge bases. Raw source code is never shared with buyers or any third party. Only AI-generated responses derived from the code are provided to buyers. Sellers can delete their agent and all associated data at any time.

Data Retention

Account data is retained while your account is active. Purchase records are retained for 7 years for tax and legal compliance. You can request deletion of your account and personal data at any time — we will process the request within 30 days, subject to legal retention requirements.

Your Rights (GDPR / CCPA)

You have the right to: (a) Access — request a copy of your personal data; (b) Rectification — correct inaccurate data; (c) Erasure — request deletion of your data; (d) Portability — receive your data in a machine-readable format; (e) Objection — opt out of certain data processing; (f) Non-discrimination — you will not be penalized for exercising these rights. To exercise any right, contact us at privacy@repoball.com.

Security

We implement industry-standard security measures including: encryption in transit (TLS/HTTPS), encryption at rest for sensitive data, secure authentication via GitHub OAuth and JWT tokens, regular security reviews, and access controls for all systems.

International Data Transfers

Your data may be processed in countries outside your country of residence. We ensure appropriate safeguards are in place, including standard contractual clauses where required.

Children's Privacy

RepoBall is not intended for users under the age of 16. We do not knowingly collect personal information from children.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on the Platform. Continued use constitutes acceptance of the updated policy.

Contact

For privacy-related questions or to exercise your rights, contact us at privacy@repoball.com.