Legal
Privacy Policy
Effective August 19, 2026 · Applies to RepoBoss 1.x for Windows and macOS
RepoBoss is source control that runs on your own machines. We never receive your code, your history, or your project names. This page says exactly what does leave a computer running RepoBoss, and who is on the other end of each connection.
The short version. There is no account and no telemetry. RepoBoss contacts us for one thing only: checking your licence, roughly once a month, carrying a serial number, an anonymous machine identifier, and a version number. Everything else it does on the network is between your computer and machines you chose — your collaborators, a relay you nominated, or a Git host you configured.
1 We do not have your code
This is the part most people want answered first, so it goes first. CTRL Colab has no copy of, and no access to:
- Your repositories, your commit history, your branches, or any file in them.
- Your project names, folder names, or file names.
- Your Safety Vault locations, or the contents of any vault.
- Your Access Cards, or a list of who you work with.
- Anything about what you are working on, at all.
None of that is a policy choice we could quietly reverse in an update. There is no server of ours that receives it, no account to attach it to, and no analytics service in the application.
2 The licence check — the only thing that reaches us
RepoBoss activates online once, then verifies your licence locally at every launch. Roughly once a month, when it happens to be online, it re-checks with our activation service in the background.
Each of those requests carries exactly three things:
| What is sent | Why |
|---|---|
| Your serial number | To identify which licence is being checked. |
| An anonymous machine identifier | A one-way hash of a machine ID, salted per product. It cannot be reversed into a machine, a name, or a person, and the same computer produces a different value for each of our products, so purchases cannot be correlated across them. |
| The app version | So we can tell which release a support question refers to. |
We store the serial, the machine identifier, and the time of the most recent check, so that the seat limit in the EULA can be counted and so support can free a seat when your hardware changes. We keep those records for as long as the licence exists.
Your IP address is visible to our host at the moment of the request, as it is for any web request. We do not log it against your licence.
If the check cannot reach us, nothing happens: RepoBoss keeps working. It only ever stops on a correctly signed answer saying the licence was revoked, which happens when a purchase is refunded — see the Refund Policy.
3 The network paths RepoBoss uses, and who is on the other end
RepoBoss connects computers to each other, so it genuinely uses the network. Every path is listed here, and none of them route through us:
- Hosting your projects. With a server licence, and only when you turn it on, collaborators connect to your machine to fetch and push. That traffic goes between their computers and yours. We are not a party to it and cannot see it.
- Opening a port. To make hosting reachable, RepoBoss may ask your router to forward a port using UPnP. That request goes to your own router on your own network. RepoBoss tells you when it has done this and what it opened, and you can decline and configure the router yourself.
- A relay, if you use one. Where a direct connection is not possible, traffic can be routed through a relay so collaborators can still reach you. A relay forwards encrypted traffic: the encryption terminates on your machine and theirs, so a relay — including one we operate — carries ciphertext it cannot read. You choose whether to use a relay and which one.
- Publishing to GitHub, or any other Git remote you configure, when you ask for it. Your credentials for that remote are held by your operating system's credential store, not by us.
- Update checks, if enabled, which ask our server whether a newer version exists and carry only the current version.
What your collaborators can reach on your machine is what you have chosen to host, and nothing else. You are responsible for who you give an Access Card to and for what you make reachable from the internet.
4 Diagnostics and crash reports
Diagnostic logs and crash reports are written to disk on your own machine. They are never sent automatically. If you use a bug-report option, it prepares a report for you to review and you decide whether to send it. Nothing goes anywhere without that decision.
5 When you buy
Purchases are handled by Paddle.com Market Limited, our merchant of record. Paddle runs the checkout, takes the payment, and calculates and remits tax. Your card details go to Paddle and never reach us. Paddle is the data controller for the payment itself and handles it under its own privacy policy.
From a purchase we receive your email address, your name if you gave one, the country Paddle used for tax, and the transaction reference. We use those to send your serial numbers, to answer support requests, and to keep the records a business is required to keep. We do not sell them, rent them, or use them for advertising, and we do not add you to a mailing list you did not ask for.
Email is sent through Resend, which delivers it on our behalf.
6 Cookies and the website
The RepoBoss pages on ctrlcolab.com do not set advertising or tracking cookies. The checkout is provided by Paddle and sets what it needs to process a payment, described in Paddle's own policy.
7 Your rights
Depending on where you live you may have the right to ask what personal data we hold about you, to have it corrected, to have it deleted, or to receive a copy. Email hello@ctrlcolab.com and we will answer.
In practice the answer is short, because the list is short: an email address, a name if you gave one, and the licence records described in section 2. Deleting the licence records means the licence can no longer be validated or supported, so we will say so before doing it rather than quietly breaking your installation.
8 Children
RepoBoss is a developer tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
9 Changes
If we change this policy we will update the date at the top. A change that meaningfully reduces your privacy will be announced alongside the release that introduces it, rather than made quietly to a page nobody re-reads.
10 Contact
CTRL Colab LLC — a New Mexico limited liability company
Email: hello@ctrlcolab.com
For legal service or postal correspondence, contact us by email and we will provide a physical address on request.