When you register, we collect your email address. This information is used to identify your account and communicate with you about the service.
We collect data about how you use RunnerHub, including build logs, job history, workspace configurations, and pipeline definitions. This also includes repository and commit metadata (repository name, branch, commit SHA and message, and pull-request number), support tickets (subject, messages, and any attachments you upload), team-invite email addresses, and the notification targets you configure (email addresses or webhook URLs). This data is essential for providing the CI/CD service.
We automatically collect technical information including your IP address, browser type and version, operating system, and access timestamps. This information is used for security monitoring and fraud prevention.
Your data is used to operate and deliver the core RunnerHub platform — running builds, storing artifacts, managing agents, and processing pipeline definitions.
Aggregated and anonymized usage data helps us understand how the platform is used and guides product development decisions.
We use technical data and audit logs to detect and prevent unauthorized access, abuse, and security incidents on the platform.
OAuth tokens are exchanged for repository access, webhook delivery, and commit status reporting. Tokens are stored encrypted at rest and are never logged or exposed in plaintext.
Your email address and user ID are shared with Paddle at checkout for billing processing. RunnerHub does not store or have access to your credit card numbers — all payment data is handled directly by Paddle.
When you configure Apple signing for an app, API key credentials (issuer ID, key ID, and private key) are sent to Apple App Store Connect for certificate and provisioning profile management. These credentials are stored encrypted at rest and are only used when signing is explicitly configured by you.
When you configure a Google Play deploy, the service-account JSON you provide is used to publish builds to Google Play. It is stored encrypted at rest and is only used for deploys you configure.
When you configure a Firebase App Distribution deploy, the token you provide is used to distribute builds to testers. It is stored encrypted at rest and is only used for deploys you configure.
Build artifacts and support-ticket attachments are stored in S3-compatible cloud object storage.
Transactional emails — verification codes, build and pipeline notifications, and account emails — are delivered through a third-party SMTP provider.
You can export a copy of your personal data at any time from Account Settings. The export includes your account, workspaces, jobs, usage, and audit-log entries, and never includes secrets or encrypted credentials.
You may permanently delete your account and associated data from Account Settings. Before deletion, your Paddle subscription is cancelled and any outstanding metered usage is settled. Deletion is blocked while jobs are running, so you may need to wait for them to finish or cancel them first. Deletion is a permanent hard delete and is irreversible; audit log entries are retained but anonymized, and your email address becomes available for re-registration.
You can update your account information and password at any time via your account settings.
If you have questions about this Privacy Policy or how we handle your data, please contact us at support@runnerhub.net.