Draft privacy notice

How the current RepoShip preview handles data

This draft maps the data flows visible in the current implementation. It does not yet define every disclosure, right, or operating process required for public use.

01

Account and authorization data

The current sign-in and repository authorization path uses two external identity systems.

  • WorkOS AuthKit handles account authentication. RepoShip uses the resulting account identity to scope repositories, deployments, and policy limits.
  • A GitHub App installation controls repository access. A separate GitHub user authorization grant confirms that the signed-in user can access the installation and selected repository.
  • RepoShip encrypts expiring GitHub user access and refresh credentials before storing them. Credentials are refreshed and rechecked for later repository operations.
02

Repository and deployment processing

Connecting a repository allows the current workflow to inspect and build the source you select.

  • RepoShip reads selected repository metadata and source files to detect project paths, dependencies, build commands, output folders, and environment-variable names.
  • Repository source, build output, and command logs pass through RepoShip-controlled build infrastructure. Deployment records, build steps, logs, artifact metadata, and build artifacts may be stored to operate and troubleshoot the workflow.
  • Supported static React/Vite output is published to Cloudflare Pages. That output receives a public pages.dev URL even when the source repository is private.
03

Operational controls

The early-access service applies controls that are visible in the current implementation.

  • Repository allowlists and account, repository, job, retry, resource, and estimated-cost limits are evaluated before deployment work is accepted.
  • RepoShip records deployment-plan estimates and operational state. Those estimates are planning inputs, not provider invoices or guarantees of final cloud charges.
  • Do not place secret values in source files or example environment files. RepoShip may necessarily process secrets supplied to an authorized build or publishing integration, but a production retention and deletion policy is not yet defined.
04

Launch information still missing

The operator and counsel must define these details before this notice can support a public launch.

  • Operator legal identity, privacy contact, effective date, covered territories, age limits, and the process for verified access, correction, export, or deletion requests.
  • Complete data categories and purposes, legal bases where applicable, retention periods, deletion timing, backup handling, security-incident notice process, and any cookie or analytics disclosures.
  • A complete subprocessor and international-transfer disclosure, including the roles of WorkOS, GitHub, Cloudflare, database, build, artifact, logging, and secret-storage providers used in the launch environment.

A working legal contact and verified deletion-request process are still operator-defined; the current contact page does not publish an operator address.

Review the current contact status