Last updated 2026-07-29
GitSpider ("we") reads your GitHub Actions data to show CI analytics, recommendations, and alerts. This explains what we collect, why, and your rights. GitSpider is independently operated from the United States; for privacy or data-protection requests, contact privacy@gitspider.com.
We use the information we collect to provide, maintain, improve, secure, and support GitSpider: compute analytics, generate config recommendations, and send the alerts you set up. We also compute anonymized, aggregated benchmarks across all monitored repos (e.g. typical CI failure rates and durations) so you can see how your CI compares — these are pure aggregate numbers, contain no repo names or identifiers, and are only generated from sufficiently large groups of repositories that no individual repository can reasonably be identified — this aggregation is not a "sale" or "sharing" of personal information. We do not sell your data or use it for advertising. Recommendations are produced by our own rule-based analysis — we do not send your repository data to any third-party AI or LLM provider.
We set a small number of first-party cookies, and use no advertising or cross-site tracking cookies: an essential session cookie to keep you logged in; two short-lived flow cookies that only exist to complete an action you started (remembering which repo you clicked Install from, and which plan you chose before signing in); and a referral cookie (30 days) that records which link first brought you to the site — a badge, a blog post — so we can attribute signups and Install-button clicks to their source. The referral cookie contains only that source tag, is never shared with anyone, and is not used for advertising. For aggregate traffic stats we use Cloudflare Web Analytics, which is cookieless and collects no personal data — no cookies, no fingerprinting, no cross-site tracking. We also record our own Install-button clicks (see "Product analytics" above); these set no cookies of their own and store no IP address.
You sign in with GitHub (OAuth). GitHub provides us your username, user ID, and — if your grant includes it — your email. We use these only to identify your account as described here; your use of GitHub is governed by GitHub's own privacy policy.
Sub-processors strictly to run the service: GitHub (source of the data — at install you grant the App read access to Actions, repository contents, and metadata, plus read & write access to pull requests (used solely to post our CI-summary comment). We use contents access only to read your workflow configuration files — we do not read or store your application source code — and the App is not granted access to your Actions secrets. We never modify your code), Stripe (billing), and — only if you enable them — Slack and Resend (alert delivery). Hosting/database are on Fly.io and Neon, and Cloudflare provides cookieless web analytics. Our own product-analytics events are processed only on our infrastructure (Fly.io and Neon) and are not shared with any analytics provider. See our full subprocessor list.
Data is encrypted in transit (TLS). Secret-like patterns in free-text fields are scrubbed (best-effort) before storage, and workflow files are stored redacted. Access is limited to operating the service. No system is perfectly secure, but we work to keep your data safe.
Individual workflow runs (and their per-job details) are kept for about 30 days, then deleted. Your redacted workflow config files and the aggregated daily rollups built from your run history are retained while your installation is active; fully anonymized benchmark statistics (containing no repo identifiers) may be retained indefinitely. Public-scanner results are cached for up to 90 days; an email address you give the public scanner is kept until you unsubscribe. Login sessions expire after 30 days. Uninstalling the GitHub App stops all further collection, and repository data associated with your installation is scheduled for deletion within 30 days of uninstall — unless retention is reasonably necessary to comply with legal obligations, resolve disputes, prevent fraud or abuse, or maintain billing records. Product-analytics events (Install-button clicks) are kept for 90 days, then deleted.
If we become aware of a security incident affecting your personal data, we'll investigate and notify affected users without undue delay where required by applicable law.
Wherever you live, you can uninstall the GitSpider GitHub App at any time to revoke access and halt collection, and email privacy@gitspider.com to request access to, correction of, or deletion of your stored data — we respond within 30 days. We do not sell or share your personal data for advertising. California residents (CCPA/CPRA) and EU/UK users (GDPR) have these rights; send data-protection requests to the email above. Our legal bases for processing are: providing the service you request (contract), maintaining and improving it (legitimate interests), and complying with legal obligations where applicable.
If you live in California (CCPA/CPRA), Virginia, Colorado, Connecticut, or Utah, you have rights to know, access, correct, and delete your personal information, and to opt out of its sale or sharing for targeted advertising. We don't sell or share your personal information or use it for targeted advertising. The categories we collect are listed under "What we collect" above. To exercise a right, email the address above — you may use an authorized agent, and we won't discriminate against you for exercising your rights.
We set no advertising or cross-site tracking cookies, so there's nothing to opt out of. No uniform standard for Do-Not-Track (DNT) or Global Privacy Control signals exists yet, so we don't respond to them; if one is adopted, we'll follow it.
We process and store data in the United States (Fly.io, Neon). For transfers of personal data from the EEA, the UK, or Switzerland to the United States, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), available on request, and our sub-processors are contractually bound to equivalent protections.
GitSpider is a developer tool not intended for children under 13, and we do not knowingly collect personal information from children.
We may update this policy from time to time. Material changes will be posted on this page (with a new "last updated" date) and, where appropriate, communicated through the service.
Questions or privacy / data-protection requests: privacy@gitspider.com