The data we store
Buildstats turns the numbers you send from CI or scripts into a metric history. That history needs a little context to be useful.
- Account details. Your GitHub numeric ID, username, and email when you sign in.
- Project and metric data. Metric names, values, units, repository details, and project settings.
- Commit context. Commit SHAs, messages, actor usernames, timestamps, branches, and workflow run details sent with your metrics.
- Service activity. Push logs, hashed IP addresses, image-fetch counts, and product events such as a project claim or trial start.
You can push metrics from GitHub Actions without creating an account. Signing in is for managing projects, access, API keys, and billing.
Public and private projects
Public project pages, metrics, charts, and badges are visible to anyone. Only send information you intend to share publicly.
Private project pages require an account with access to that project. Private chart and badge URLs work differently: they include an unguessable token so images can load in a README.
Anyone with the full URL can fetch the image. Rotating its token invalidates the old URL, but cached copies, including GitHub Camo copies, can remain until their cache expires.
How the data is used
We use this data to store metric history, draw charts, compare commits, control access to private projects, and manage subscriptions.
Service activity helps us investigate failed pushes, operate the service, and understand which features people use. Image-fetch counts measure requests, not unique people; caches can combine many views into a single request.
Services involved
These services support the planned buildstats application:
- GitHub + Firebase
- GitHub sign-in and account authentication.
- Cloudflare
- Website hosting, request handling, and image-fetch analytics.
- PostgreSQL
- Storage for accounts, projects, and metric history.
- Stripe
- Subscription payments through our billing service.
- SimpleAnalytics
- Website usage measurement.
How long data stays
Push logs are retained for 30 days. Public metric history is kept while the project remains available. Private metric history is available while its trial or subscription is active.
After a private trial or plan lapses, existing data is retained for 30 days and then deleted. New pushes during that period are not stored. Public projects are unaffected.
The GitHub owner's trial-start record is retained to prevent repeated trials. Broader account, backup, and service-log retention details will be finalized before this policy is published.
Your choices and questions
Project admins can manage members, revoke API keys, rotate private image tokens, and delete individual metric points. These controls affect the project, not copies already shared elsewhere.
For questions about your account or data, contact bart@bitgate.com. The final policy will include the operator's details and the applicable process for data-access and deletion requests.