// legal
Privacy policy
Last updated: July 2026
Readmify is a developer tool by Poletto 1976 S.L.U. that automatically generates documentation for your GitHub and Bitbucket repositories using AI. We collect only the data strictly necessary to provide the service. We do not sell your personal data.
Data controller
Poletto 1976 S.L.U., Plaza del Congreso Eucarístico, 2, 2-D, 03201 Elche (Alicante), Spain.
Contact: info@poletto.es
Data collected and purposes
| Data | Purpose | Legal basis |
|---|---|---|
| Username and email address | Authentication via GitHub / Bitbucket OAuth | Performance of contract |
| Repository names | Connect repositories to trigger documentation generation | Performance of contract |
| Generated documentation | Display docs within the service | Performance of contract |
| Bitbucket OAuth tokens (encrypted) | Read repositories and receive push events | Performance of contract |
| AI provider API key (encrypted) | Send requests to the AI provider you choose | Performance of contract |
| IP address | Security and fraud prevention | Legitimate interest |
Repository access
GitHub: The Readmify GitHub App requests read access to the repositories you explicitly connect. It listens to push events to trigger documentation generation. You can revoke access at any time from your GitHub settings under Settings → Third-party Access → GitHub Apps.
Bitbucket: When you connect Bitbucket, we request repository and webhook scopes to read your repositories and listen to push events. You can revoke access at any time from your Bitbucket workspace settings or from the Readmify settings page.
Data processors (sub-processors)
| Provider | Service | Country | Safeguards |
|---|---|---|---|
| Supabase Inc. | Database and authentication | USA | EU standard contractual clauses |
| Vercel Inc. | Hosting and edge functions | USA | EU standard contractual clauses |
| GitHub Inc. | OAuth authentication, repository access | USA | EU standard contractual clauses |
| Atlassian Pty Ltd | Bitbucket OAuth authentication, repository access | Australia | EU standard contractual clauses |
| Resend Inc. | Transactional email delivery | USA | EU standard contractual clauses |
| Stripe Inc. | Payment processing for donations | USA | EU standard contractual clauses |
| AI providers (user-chosen) | Documentation generation (OpenAI, Anthropic, Google, etc.) | USA | EU standard contractual clauses |
Your code is sent to the AI provider solely to generate documentation and is not retained or used for training by Readmify. Check the privacy policy of your chosen AI provider for their data handling practices.
Processing of donation data
Donors voluntarily provide their full name, email address, tax ID (NIF/CIF/VAT) and fiscal address. This data is used solely for issuing the invoice and sending the payment receipt via Stripe. It will never be used for marketing, profiling or any commercial communications. Payments are processed by Stripe Inc. (USA), PCI-DSS certified. Readmify never stores any payment method details.
Cookies
Readmify uses cookies exclusively for authentication, managed by Supabase. These cookies store your session and refresh token so you stay signed in across page loads. We do not use tracking, analytics, or advertising cookies of any kind. No cookie consent banner is required to use the service.
Data retention
Your data is retained as long as your account is active. You can request deletion of your account and all associated data at any time by contacting info@poletto.es. Documentation content and repository connections are deleted immediately upon your request.
Your rights
Under GDPR you have the right to access, rectification, erasure, data portability, restriction of processing, and objection. To exercise any of these rights, contact info@poletto.es.
You also have the right to lodge a complaint with your national data protection authority. In Spain: Agencia Española de Protección de Datos (aepd.es).
Contact
For any privacy-related questions or requests, contact us at info@poletto.es.