Who can see a project
A project follows its repository. Public repositories make public projects that anyone can view, and private repositories make private projects that only their members can see. Every push carries the repository's visibility in the workflow's OIDC token, and buildstats re-checks public projects every 24 hours. Projects outside GitHub get the visibility you pick when you create them.
Everyone else sees the same page as for a project that doesn't exist. Private projects stay out of the sitemap, and their link previews show no names or values.
Members
A private project has no members until someone claims it, and the claimer becomes its admin. Admins add people by GitHub username as viewers or admins. Viewers see the project, and admins also manage its settings, members, API keys and billing. People see the project once they sign in to buildstats with that GitHub account. Members are unlimited.
Free trial
The first push from a private repository starts a 14-day trial for its GitHub owner, the user or organization, with no card. The trial covers all of that owner's private projects and never restarts. Admins with an email address get a reminder on day 12.
Pro
Pro is $9 a month per GitHub owner and covers up to 25 private projects. Any admin of one of the owner's projects can subscribe on the billing page, and whoever pays manages the subscription. Public projects stay free, up to 100 per owner, and never lock.
When a trial or plan ends
The owner's private projects lock. Pushes still succeed but store nothing: each result comes back with stored: false and error: "locked", which the Action reports as a warning unless strict: true is set. Charts and badges show a locked placeholder.
Existing data is kept for 30 days. Subscribing in that window unlocks the projects with their history, but values pushed while they were locked are gone. After that, the projects and their data are deleted.
Private chart images
Image URLs of a private project carry its token in t, so charts and badges work in a private README or wiki without signing in. Anyone with the full URL can see the image.
Admins find the token, and rotate it, in the Keys tab of the project settings. Rotating breaks every old URL at once. Private images are cached for 60 seconds and never in shared caches.