GitMD が収集・保存する情報は以下のみです。すべてお使いの端末内にのみ保存されます。
| 情報 | 用途 | 保存場所 |
|---|---|---|
| GitHub / GitLab OAuth アクセストークン | リポジトリへの読み書き認証 | 端末内(Android Keystore で暗号化) |
| 個人アクセストークン(PAT) | カスタム Git ホストへの認証 | 端末内(Android Keystore で暗号化) |
| Google Drive / Dropbox / Box OAuth アクセストークン(各サービスを保存先に設定した場合のみ) | クラウドストレージへのノート同期の認証 | 端末内(Android Keystore で暗号化) |
| AI API キー(Gemini / OpenAI / Anthropic。設定した場合のみ) | AI インライン生成の認証 | 端末内(Android Keystore で暗号化)。開発者のサーバーには送信されない |
| Pro 購入状態(エンタイトルメント) | 購入特典(3 つ目以降のリポジトリ)の有効化 | Google Play から取得し端末内に保持。決済情報(カード番号等)はアプリに渡らず Google Play が管理 |
| リポジトリ URL・ブランチ名・認証種別 | クローン・同期先の特定 | 端末内(DataStore) |
| Git コミット用の著者名・メールアドレス | コミットメタデータへの記録 | 端末内(DataStore) |
| Markdown ファイル | ノートの表示・編集 | 端末内(アプリ専用ストレージ) |
| ノート暗号化キー(設定で有効にした場合のみ) | ノートの End-to-End 暗号化 | 端末内(Android Keystore で保護)。ノートはリモートに暗号文のみ保存、平文は端末外に出ない |
| お気に入り / 最近開いたノートのパス | UI 状態の保持 | 端末内(DataStore) |
アプリの品質向上を目的として、以下を送信します。
| 情報 | 送信先 | 用途 |
|---|---|---|
| アプリの起動・主要操作(ノート作成・保存・Push 成功)のイベント名 | Firebase Analytics(Google) | 機能の利用状況の把握、不具合の検知 |
| クラッシュレポート(スタックトレース・端末モデル・OS バージョン・アプリバージョン) | Firebase Crashlytics(Google)/ Sentry(Functional Software, Inc.) | クラッシュ原因の特定 |
| 国名(おおまかな地域) | Firebase Analytics(Google) | 言語ローカライズの優先度判断 |
クラッシュレポートにユーザー識別子・ノート本文は含まれません。
収集しない情報(明示的に無効化済み):
本ウェブサイト(ymatsuzatech.com)では、訪問状況の把握のため Google Analytics 4(GA4)を使用します。GA4 は Cookie(_ga 等)を用いて、閲覧ページ・参照元・おおまかな地域などの情報を収集します(個人を特定する情報は含みません。IP アドレスは GA4 側で匿名化されます)。これは GitMD アプリ内の計測(Firebase Analytics)とは別のものです。収集を望まない場合は、ブラウザの Cookie 設定、または Google アナリティクス オプトアウト アドオン で無効化できます。
GitMD はいかなる個人情報も第三者に提供・販売しません。
アプリが通信する外部サービスは以下のみです。
これらの通信はすべて HTTPS / SSH で行われます。
プライバシーに関するご質問は、お問い合わせフォームまたはテスター向け Google グループまでご連絡ください。
GitMD collects and stores only the following information. All of it is stored solely on your device.
| Information | Purpose | Storage location |
|---|---|---|
| GitHub / GitLab OAuth access token | Authenticating repository read/write | On device (encrypted with Android Keystore) |
| Personal Access Token (PAT) | Authenticating with custom Git hosts | On device (encrypted with Android Keystore) |
| Google Drive / Dropbox / Box OAuth access token (only if you set that service as a storage backend) | Authenticating note sync to cloud storage | On device (encrypted with Android Keystore) |
| AI API key (Gemini / OpenAI / Anthropic; only if you set one) | Authenticating AI inline generation | On device (encrypted with Android Keystore). Never sent to the developer's servers |
| Pro purchase state (entitlement) | Unlocking the paid feature (a 3rd repository and beyond) | Fetched from Google Play and kept on device. Payment details (card numbers, etc.) never reach the app — Google Play handles them |
| Repository URL, branch name, auth type | Identifying the clone / sync target | On device (DataStore) |
| Author name & email for Git commits | Recording commit metadata | On device (DataStore) |
| Markdown files | Displaying and editing notes | On device (app-private storage) |
| Note encryption key (only when enabled in settings) | End-to-end encryption of note content | On device (protected by Android Keystore). Only ciphertext is stored remotely — plaintext never leaves the device |
| Favorite / recently opened note paths | Preserving UI state | On device (DataStore) |
To improve the quality of the app, the following is sent.
| Information | Sent to | Purpose |
|---|---|---|
| Event names for app launch and key actions (creating a note, saving, a successful push) | Firebase Analytics (Google) | Understanding feature usage and detecting problems |
| Crash reports (stack trace, device model, OS version, app version) | Firebase Crashlytics (Google) / Sentry (Functional Software, Inc.) | Identifying the cause of crashes |
| Country (approximate region) | Firebase Analytics (Google) | Prioritizing language localization |
Crash reports contain no user identifier and no note content.
Information we do NOT collect (explicitly disabled):
This website (ymatsuzatech.com) uses Google Analytics 4 (GA4) to understand visitor activity. GA4 uses cookies (such as _ga) to collect information like pages viewed, referrer, and approximate region (no personally identifying information; IP addresses are anonymized by GA4). This is separate from the in-app analytics (Firebase Analytics) of the GitMD app. To opt out, adjust your browser's cookie settings or install the Google Analytics opt-out browser add-on.
GitMD does not provide or sell any personal information to third parties.
The only external services the app communicates with are:
All such communication is performed over HTTPS / SSH.
For privacy-related questions, use the contact form or the tester Google Group.