Privacy policy
Last updated 5 October 2026
Not configured
The operator of this deployment hasn't filled in their details yet, so this page is incomplete. Missing: LEGAL_OPERATOR_NAME, LEGAL_OPERATOR_ADDRESS, LEGAL_CONTACT_EMAIL.
This policy explains what ReleaseCrew stores when you use it, why, and what you can do about it. The controller is [operator name not configured], [operator address not configured]. Questions and requests: [contact email not configured].
What we store
- Your account: your GitHub name, username, email and avatar, from signing in with GitHub.
- Your product: its name, description, site address and the repository you connect.
- What you shipped: titles, descriptions and diffs of releases and merged pull requests in that repository, so ReleaseCrew can judge and describe them.
- Your launches: the assets drafted for each release, every version of them, your approvals, and a log of what ReleaseCrew did on your behalf.
- Connections: credentials for the services you connect (X, Resend, Stripe, PostHog) are stored encrypted in Supabase Vault and are only readable by our server. They are never shown back to you or included in exports.
- Your results: when you connect Stripe or PostHog, we read revenue, new customers and signups from your accounts to show what a launch earned. For your own customers we act on your behalf, and only you see this data.
- Billing: if you upgrade, Stripe handles payment. We keep only the Stripe customer and subscription ids and the plan status.
AI generation
Drafts are written by a runner on your own computer, using the Claude or ChatGPT subscription you are signed in to there. The prompt (built from your release and product details) goes to your runner, which sends it to your AI provider under your account and terms. We never receive or store your AI credentials, and your AI provider is not our subprocessor.
Who processes data for us
| Service | Why | Data |
|---|---|---|
| Supabase | Database, sign-in sessions, encrypted credential storage (Vault) | Everything stored for your workspace |
| Vercel | Hosting and serving the app | Request data such as IP address and user agent |
| Resend | Emails ReleaseCrew sends to you | Your email address and the message |
| PostHog | Product analytics on this site, only if you allow it; error reports from our servers | Analytics: pages visited, device and browser details, a pseudonymous id. Error reports: what failed, where, and internal ids |
| Stripe | Payments for the paid plan | Billing details and payment method (held by Stripe, not us) |
| GitHub | Sign-in, and reading releases from the repository you connect | Your GitHub profile; release titles, descriptions and diffs |
| X | Publishing the posts you approve, from your account | The approved posts and your X account id |
Cookies and analytics
A sign-in cookie keeps you signed in; it is necessary for the app to work. PostHog analytics runs only if you choose “Allow analytics” on the banner; until then it isn't loaded at all. Your choice is remembered in your browser, and you can change it any time from “Cookie settings” at the bottom of every page.
Legal basis
We process your account, product, launch and connection data to provide the service you signed up for (contract). Analytics runs on your consent. Security logs and abuse protection, such as rate limiting by hashed network address, rest on our legitimate interest in keeping the service safe.
How long we keep it
As long as your account exists. Deleting your account removes your workspace, every stored credential and your sign-in immediately; copies in our database provider's backups expire on its backup schedule.
Your rights
You can export everything we hold about your workspace as JSON, and delete your account, from the app's settings. You also have the right to access, correct, restrict or object to processing, and to complain to a data protection authority. For anything else, write to [contact email not configured].