Privacy Policy
Last updated: 2 October 2026
This policy describes what Pipemesh (the service at pipemesh.io) collects when you use it, why, and what we do with it.
What we collect
Your account. When you sign in with GitHub we receive your GitHub user id, login, display name, avatar and the email address GitHub shares. We use them to identify you, to show who did what, and to contact you about the Service.
Your repositories. For the repositories you enable, the Pipemesh GitHub App reads commits, branches, pull requests, check runs and webhooks, and the repository's contents when a job checks it out. We read what the pipelines you declare need, and nothing from repositories you have not enabled or declared.
What your pipelines produce. Job logs, artifacts, images and the state of every run and revision: which commit each job executed, when, and with what result. Secrets you store are encrypted at rest and shown to no one, including us; they are decrypted only inside the job that reads them.
How you use the Service. Standard server logs (requests, IP addresses, user agent, timings) and application telemetry (errors, latencies, resource use), used to run and improve the Service. We do not use advertising trackers.
Visits to our public pages. On the landing page, the documentation and the sign-in page we count visits with Plausible Analytics: which page, where the visitor came from, their country and the kind of device. It sets no cookies and builds no profile that follows you. It does not run once you are signed in, with one exception: the first time an account signs in we record that a sign-up happened, so we know which of our pages led to it, and nothing after that. A visit to a repository's page is counted without the repository's name.
How we use it
To run your pipelines, show you their state, send you the notifications you turn on, keep the Service secure and reliable, meet legal obligations, and, with your consent, tell you about changes to the Service. We do not sell your data and do not use your code or logs to train models.
Who else sees it
- GitHub, which the Service talks to on your behalf, under GitHub's own terms.
- Infrastructure providers that host the Service and store its data: Amazon Web Services (compute, storage, databases) and Grafana Labs (telemetry: metrics, logs and traces of the Service itself, not your job logs). They process data for us under their data-processing terms.
- Plausible Analytics, which counts the visits to our public pages described above.
- People your repositories' access allows. A pipeline is visible to those who can see its repository; a public pipeline is visible to anyone with the link.
- Authorities, where the law requires it.
We do not share your data with anyone else.
Where it is kept
The Service runs in Amazon Web Services in the United States. Your data is encrypted in transit and at rest. The visit counts of our public pages are processed by Plausible in the European Union.
How long
Run state and revision history are kept while the repository is enabled. Logs and artifacts are kept for the retention periods shown in the product, then deleted. When you remove a repository or delete your account, its data is deleted within 30 days, except for records we must keep to meet a legal obligation and for backups, which expire on their own schedule.
Your rights
You can see and export your data through the Service and its API, correct your account details on GitHub, and delete your account from Settings or by asking us. Depending on where you live you may have further rights under data-protection law, including to object to or restrict processing and to complain to a supervisory authority. Write to us at the address below to exercise them.
Changes
We may update this policy; the date at the top says when. For material changes we will notify you in the product or by email before they apply.