Back to buildstats

THE SMALL PRINT

Privacy policy

What buildstats stores, what others can see, and how your data is used.

Draft for reviewOctober 1, 2026

01

The data we store

Buildstats turns the numbers you send from CI or scripts into a metric history. That history needs a little context to be useful.

  • Account details. Your GitHub numeric ID, username, and email when you sign in.
  • Project and metric data. Metric names, values, units, repository details, and project settings.
  • Commit context. Commit SHAs, messages, actor usernames, timestamps, branches, and workflow run details sent with your metrics.
  • Service activity. Push logs, hashed IP addresses, image-fetch counts, and product events such as a project claim or trial start.

You can push metrics from GitHub Actions without creating an account. Signing in is for managing projects, access, API keys, and billing.

02

Public and private projects

Public project pages, metrics, charts, and badges are visible to anyone. Only send information you intend to share publicly.

Private project pages require an account with access to that project. Private chart and badge URLs work differently: they include an unguessable token so images can load in a README.

A private image URL is a shareable link.

Anyone with the full URL can fetch the image. Rotating its token invalidates the old URL, but cached copies, including GitHub Camo copies, can remain until their cache expires.

03

How the data is used

We use this data to store metric history, draw charts, compare commits, control access to private projects, and manage subscriptions.

Service activity helps us investigate failed pushes, operate the service, and understand which features people use. Image-fetch counts measure requests, not unique people; caches can combine many views into a single request.

04

Services involved

These services support the planned buildstats application:

GitHub + Firebase
GitHub sign-in and account authentication.
Cloudflare
Website hosting, request handling, and image-fetch analytics.
PostgreSQL
Storage for accounts, projects, and metric history.
Stripe
Subscription payments through our billing service.
SimpleAnalytics
Website usage measurement.
05

How long data stays

Push logs are retained for 30 days. Public metric history is kept while the project remains available. Private metric history is available while its trial or subscription is active.

After a private trial or plan lapses, existing data is retained for 30 days and then deleted. New pushes during that period are not stored. Public projects are unaffected.

The GitHub owner's trial-start record is retained to prevent repeated trials. Broader account, backup, and service-log retention details will be finalized before this policy is published.

06

Your choices and questions

Project admins can manage members, revoke API keys, rotate private image tokens, and delete individual metric points. These controls affect the project, not copies already shared elsewhere.

For questions about your account or data, contact bart@bitgate.com. The final policy will include the operator's details and the applicable process for data-access and deletion requests.

Still have a question?Talk to us