Holy Files

Privacy Policy

Last updated August 11, 2026 · Early access

Holy Files ("we") provides a GitHub App and web dashboard that enforce steward approval on protected code paths. This policy explains what we collect and why while the product is in early access.

Data we process

  • Account data from GitHub OAuth (name, email, GitHub username, avatar).
  • Organization, membership, invitation, and steward-team configuration you create in the dashboard.
  • Repository enrollment metadata (owner/name, installation ids, settings).
  • Approvals, audit events, and optional derived scan cache (symbol/metadata hashes) used to evaluate checks.
  • Billing identifiers and subscription status via Stripe if paid billing is enabled later.
  • Product analytics and error diagnostics via PostHog (when you consent in the browser).
  • Transactional email (invites / notifications) via Resend when configured.

Source code

We read repository file contents at specific Git SHAs through the GitHub API to find holy markers and evaluate pull requests. We do not operate a durable product store of your full source trees. Derived scan metadata may be cached briefly to run checks. Approvals and audit records are stored in our database.

Cookies and analytics

Client-side PostHog analytics load only after you accept analytics cookies. You can decline and continue using the product. Server-side error capture may still record failures needed to operate the service.

Contact

Questions: hello@holyfiles.dev