Bonsai³ home

Privacy Policy
Last updated August 10, 2026

Privacy Policy

This policy applies to Bonsai³ for iPhone and iPad, including the Bonsai³ Widget.

Data Bonsai³ uses

Bonsai³ uses GitHub OAuth with read-only read:user access. After you authorize Bonsai³, the app retrieves your GitHub account ID, username, and contribution-calendar dates, levels, and counts through GitHub’s official GraphQL API. Depending on your GitHub settings, the calendar may include anonymized private-repository contribution counts.

Bonsai³ requests only the read:user scope because GitHub’s GraphQL contributionsCollection requires this read-only profile permission to include anonymized counts of contributions to private and internal repositories in the calendar it returns. It does not grant access to repository names, code, or your email address.

Bonsai³ does not receive your GitHub password, email address, repository names, repository contents, or permission to change anything on GitHub.

How GitHub requests work

GitHub sign-in and authorization happen in Apple’s secure browser session. GitHub returns an access token to Bonsai³. The app stores that token in the device Keychain and sends it only to GitHub over HTTPS for official GitHub API requests. GitHub receives these requests and may process information such as an IP address, device or browser information, and request time under the GitHub Privacy Statement. The Bonsai³ developer does not receive this information.

Bonsai³ has no developer-operated server, analytics, advertising, tracking, or third-party analytics SDKs.

Local storage and Widget sharing

Bonsai³ stores the GitHub access token only in the device Keychain. The GitHub account ID, username, downloaded contribution snapshot, and garden preferences are also stored locally. On iPhone and iPad, the app shares the connected GitHub username, contribution snapshot, and garden data needed to bind and draw the Bonsai³ Widget through Apple’s private App Group storage. The Widget does not receive the access token and does not contact GitHub.

The app refreshes activity while it is open. The cached snapshot is replaced when activity refreshes and is retained until you remove GitHub data or uninstall Bonsai³. WidgetKit controls when it rereads the locally shared snapshot.

Bonsai³ keeps up to twelve consecutive 90-day contribution snapshots on the device at a time, roughly three years of history, so the Bonsai³ Widget and the app’s garden archive can show past periods without a new GitHub request.

Removing data and withdrawing permission

Choose Remove GitHub Data in Settings to stop future requests, delete the Keychain token, GitHub account data, and contribution snapshots from this device, and reset the Widget. Bonsai³ also asks GitHub to revoke that individual token; if that cannot finish right away, for example because the device is offline, a copy stays in the device-only Keychain only to retry the revocation and is deleted once it succeeds. You can also revoke Bonsai³ manually at any time from GitHub Authorized Apps.

Postcards you share

Postcard sharing occurs only after you use Apple’s system share sheet. The preview shows the contribution dates, counts, and GitHub handle that will be included. Removing GitHub data cannot delete a postcard you already shared or a copy retained by a destination you selected.

Visiting this website

This is separate from how the Bonsai³ app works, described above: the app itself has no developer-operated backend. This website, including this page, is delivered through Cloudflare, and its font is loaded from the Fontshare CDN. Like most web infrastructure and content-delivery providers, Cloudflare and Fontshare may process standard access information, such as an IP address, browser information, and request time, to serve these pages and fonts. The Bonsai³ developer does not separately collect or receive this information.

Contact

Questions about this policy can be sent to support@bonsaicubed.app.

Bonsai³ is an independent app and is not affiliated with or endorsed by GitHub.