Privacy Policy
Effective: September 2, 2026
ReleasesHQ (“we”, “us”) is a release-notes publishing tool at releaseshq.com. This page explains what data we handle, why, and what we will never do with it. It is written to be read, not skimmed past.
ReleasesHQ is a registered business in India. Full registration details are in section 11.
Questions any time: support@releaseshq.com.
1. Who this covers
Two groups of people interact with ReleasesHQ, and we treat their data differently:
- Customers. Founders and teams with a ReleasesHQ account.
- Audiences. People who read a customer’s release-notes page, or subscribe to a customer’s release emails. For this data, the customer is the controller and we act on their instructions.
2. What we collect from customers
- Account details. Your name and email address, via Google sign-in or email and password. Passwords are handled by our authentication provider and are never visible to us.
- Your content. The release notes you write, your workspace settings, and the drafts generated for each channel.
- Integration connections. When you connect Slack, X, LinkedIn, or GitHub, we store the access credential for that connection encrypted at rest (AES-256-GCM). The access is deliberately narrow:
- ✓ Slack: post messages and list channels. No DMs, files, or member lists.
- ✓ X: read your handle and post. No DMs, followers, or timeline.
- ✓ LinkedIn: read your profile name and post. No messages, connections, or analytics.
- ✓ GitHub: read-only access to pull requests, commits, and metadata on repositories you choose. Never code write access.
- Billing. Payments are processed by Dodo Payments, our merchant of record. Card details go directly to them; we never see or store your payment card information.
3. What we collect from audiences
- Email subscribers. An email address and optional first name, collected when someone subscribes to a customer’s release notes. These are stored encrypted at rest with a separate encryption key per workspace. We use them for exactly one thing: sending the release emails that workspace publishes.
- Unsubscribes. Every email includes a one-click unsubscribe that works forever. Unsubscribed and bounced addresses go on a suppression list scoped to that workspace so they are not emailed again.
- Page visitors. Hosted release-notes pages and embeds require no account and collect no personal information. We measure product usage with privacy-respecting analytics; we do not run ads or sell data to anyone.
4. How we use data
- To run the service: host your pages, send your emails, post to your connected channels when you publish.
- To draft content: when you use AI drafting, the relevant release content (and, if connected, merged pull-request titles and descriptions) is sent to Anthropic to generate the draft. It is not used to train their models.
- To notify you: transactional emails about your account, deliveries, and billing.
- We never sell personal data. We never use your content or your audience’s data for advertising.
5. Who processes data for us
We use a small set of infrastructure providers, each for a specific job:
| Provider | Job |
|---|---|
| Supabase | Database and authentication (US East) |
| Vercel | Application hosting |
| Amazon Web Services | Email delivery (SES) and encryption-key management (KMS) |
| Resend | Transactional email |
| Cloudflare | CDN for public pages and embeds |
| Upstash | Rate limiting |
| Inngest | Background job processing |
| Anthropic | AI draft generation |
| Dodo Payments | Billing (merchant of record) |
| PostHog | Product and website analytics |
| Website analytics on releaseshq.com (Google Analytics) |
6. Cookies
What gets set depends on where you are:
- In the app. A session cookie to keep you signed in. That is all.
- On releaseshq.com, our marketing site. Google Analytics sets two first-party cookies (
_gaand_ga_<id>) so we can count visits and see which pages people actually read. It only loads if you accept: decline on the banner and the script is never fetched, and any of those cookies you already have are deleted. PostHog runs alongside it and is cookieless: it keeps nothing between page loads, and both honour Do Not Track. If your browser sends Do Not Track we skip the question entirely and treat it as a decline. - On hosted release-notes pages and embeds. Nothing. They need no account, set no cookies, and carry no analytics of ours.
No third-party advertising cookies, no ad networks, and no cross-site tracking anywhere, on any of them.
Change your mind whenever you like: clearing site data for releaseshq.com in your browser erases both your stored answer and the _ga cookies, and we will ask again on your next visit.
7. Security
Integration credentials and subscriber personal data are encrypted at rest (AES-256-GCM, with per-workspace keys managed through AWS KMS). All traffic is encrypted in transit. Database access is enforced with row-level security, so one workspace’s data is never visible to another. Sensitive actions are recorded in an audit log.
8. Retention and deletion
We keep your data while your account is active. Deleting a workspace deletes its content and subscriber list. Suppression records are retained so that unsubscribe requests keep being honored. That one is a promise to your audience we will not break. To delete your account entirely, or to request a copy of your data, email support@releaseshq.com and we will complete it within 30 days.
9. Your rights
Wherever you are, you can ask us to access, correct, export, or delete your personal data. Audience members can do the same, though for workspace data we may route the request through the customer who controls it. Email support@releaseshq.com.
10. Changes
If this policy changes in a way that matters, we will note it here with a new effective date and let account holders know by email.
11. Who we are, and how to reach us
- Trade name: ReleasesHQ
- Udyam (MSME) registration: UDYAM-TS-09-0232809
- GSTIN: 36BTEPV3032R1Z2
- Place of business: Telangana, India
- Grievance contact: Gagan Varma, support@releaseshq.com
For anything in this policy (access, correction, export, deletion, or a complaint), email support@releaseshq.com.