FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Analytics
  4. Gitea
image/svg+xml

Gitea

AnalyticsWebsite

Related services

34SP.com

34SP.com is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 34SP.com supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 34SP.com enables informed decisions that improve experience and drive results.

Analytics
5

51.LA

51.LA is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 51.LA supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 51.LA enables informed decisions that improve experience and drive results.

Analytics

52Degrees

52Degrees is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. 52Degrees offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, 52Degrees empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

a3 Lazy Load

a3 Lazy Load is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, a3 Lazy Load delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Analytics
A

Able CDP

Able CDP is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. Able CDP supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, Able CDP enables informed decisions that improve experience and drive results.

Analytics
A

Abralytics

Abralytics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. Abralytics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, Abralytics empowers organizations to optimize strategy and maximize return on investment.

Analytics
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Gitea do?

Lightweight, self hosted Git service written in Go that sets strictly necessary session and CSRF cookies when an end user signs into the web interface.

What is Gitea

Gitea is an open source, self hosted Git service written in Go. Organisations install it on their own infrastructure to host repositories, manage issues, run CI pipelines and review code internally. Because every Gitea instance is operated by the deploying organisation, the controller and the data location are entirely defined by that operator and not by an external vendor.

Cookies and data collected

When a user authenticates against the Gitea web interface, the server sets cookies named i_like_gitea (the session cookie), _csrf (CSRF protection token), lang (language preference) and gitea_incredible (remember me token when enabled). Gitea also stores commit metadata, repository activity, issue comments and access logs. These are processed under the responsibility of the operating organisation.

GDPR and ePrivacy implications

The Gitea session, CSRF and language cookies are strictly necessary to deliver the service requested by the user, so they fall under the ePrivacy exemption of Article 5(3) and do not require prior consent. The remember me cookie is functional and may also be exempt as long as it is enabled at the explicit request of the authenticated user. Standard user account data is processed on the basis of contract performance or legitimate interest, depending on context.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers

Because Gitea is self hosted, there is no automatic transfer to a third country. The data location is fully determined by the operator. If you host the instance in the EU on your own hardware or with an EU based cloud provider, all processing stays within the EEA. If you choose a non EU hosting provider, you must apply the usual Chapter V safeguards.

How to implement compliance

Restrict the Gitea web interface to authenticated users, enforce HTTPS and Secure HttpOnly cookies, configure short session timeouts and limit access logs to the retention period your security policy requires. Document Gitea in your record of processing activities, mention it in the employee or contributor privacy notice and provide an internal procedure for data subject requests.

GDPR consent category

Analytics

Websites using Gitea must obtain user consent under GDPR regulations.

Legal basisConsent (GDPR Art. 6(1)(a)) and ePrivacy Directive Art. 5(3) for cookie storage
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive, TTDSG, LIL, LOPDGDD

DPIA considerations

A full DPIA is rarely required for an internal Gitea instance because cookies are strictly necessary and data stays under the operators control. A DPIA may still be needed when Gitea is exposed publicly, processes special category data or is hosted by a non EU cloud provider.

Sample consent text

This site uses Gitea, a self hosted Git service. It sets strictly necessary session and CSRF cookies when you sign in to your account. No consent is required for these cookies, but you can review our privacy notice for more details.

Technical details

Tracking methodSelf hosted Git platform written in Go that sets first party authentication, CSRF and preference cookies on the visitor browser when the web interface is used
Server locationOperator dependent (self hosted; data location is the server chosen by the operator)

Third-party domains contacted

gitea.comgitea.iodl.gitea.com

Cookies placed

NameTypeDurationPurpose
i_like_giteanecessarySessionPrimary session cookie that authenticates the user against the Gitea web interface and links subsequent requests to the active session.
_csrfnecessarySessionCross site request forgery protection token used by Gitea to validate that form submissions originate from the legitimate authenticated session.
langpreferences1 yearStores the language preference selected by the user so the Gitea interface is displayed in the same language on subsequent visits.
gitea_incrediblefunctional30 daysRemember me token set only when the user activates the Stay signed in option; it keeps the session valid across browser restarts.

Gitea collects user analytics data — you legally need a consent banner. Try FlowConsent free.

Get started freeScan your site

Frequently asked questions

What cookies does Gitea set?

Gitea sets i_like_gitea for the active session, _csrf for CSRF protection, lang for the language preference and gitea_incredible for the remember me option when the user enables it. All are first party cookies on the domain of the Gitea instance.

Is user consent required before loading Gitea?

No prior consent is required for the strictly necessary cookies because they are essential to deliver an authenticated session. The remember me cookie is functional and is only set after the user actively requests it, so no consent banner is needed for a typical Gitea deployment.

What is the legal basis for processing personal data via Gitea?

User account data is usually processed on the basis of contract performance under Article 6(1)(b) of the GDPR for employees and contributors, or legitimate interest under Article 6(1)(f) for internal security and audit logs. Cookies rely on the ePrivacy exemption.

Does Gitea transfer data outside the EU, especially to the US?

Gitea itself does not transfer data anywhere. If you host the instance in the EU you stay inside the EEA. Transfers only happen when you choose a non EU hosting provider or use external integrations such as webhooks pointing to third country services.

Is a DPIA required when using Gitea?

A DPIA is generally not required for an internal Gitea instance because cookies are strictly necessary and the volume of personal data is limited. A DPIA may be triggered when Gitea hosts repositories that contain personal data on a large scale, sensitive categories or is exposed publicly.

How do I correctly implement Gitea in a GDPR compliant way?

Host the instance on EU infrastructure, enforce HTTPS, set Secure and HttpOnly flags on every cookie, configure SSO with strong authentication, restrict logs to a defined retention period and document the processing in your record of processing activities.

Are there privacy friendly alternatives to Gitea?

Other self hosted Git platforms such as Forgejo, GitLab Community Edition or cgit also keep data on infrastructure you control. They share the same favourable privacy profile because the operator decides where data is stored and which cookies are activated.

How should I update my cookie policy to mention Gitea?

List the four Gitea cookies, mark them as strictly necessary or functional, indicate the retention period configured on your instance and explain that they are required to deliver the authenticated Git web interface. Add a link to the operator privacy notice.