arrow_backBack to RunnerHub

Privacy Policy

Last updated: July 2026

databaseData We Collect

Account Information

When you register, we collect your email address. This information is used to identify your account and communicate with you about the service.

Usage Data

We collect data about how you use RunnerHub, including build logs, job history, workspace configurations, and pipeline definitions. This also includes repository and commit metadata (repository name, branch, commit SHA and message, and pull-request number), support tickets (subject, messages, and any attachments you upload), team-invite email addresses, and the notification targets you configure (email addresses or webhook URLs). This data is essential for providing the CI/CD service.

Technical Data

We automatically collect technical information including your IP address, browser type and version, operating system, and access timestamps. This information is used for security monitoring and fraud prevention.

cookieCookies & Local Storage

  • circlerunnerhub_auth — httpOnly access-token cookie (SameSite Lax, 15-minute expiry) used for session authentication. It is never accessible to JavaScript.
  • circlerunnerhub_refresh — httpOnly refresh-token cookie (SameSite Lax, 30-day expiry) used to renew the access token without re-entering credentials. It is never accessible to JavaScript.
  • circlerunnerhub_session — a non-httpOnly session-marker cookie (SameSite Lax, 30-day expiry) set to the value "1" so the dashboard can detect that a session is active. It is readable by JavaScript by design and contains no token or personal data.
  • circlerh_locale — a non-httpOnly preference cookie (SameSite Lax, 1-year expiry) storing your chosen language. It is only set when you change the language in settings.
  • circlerh_cookie_consent — stored in localStorage to remember your cookie consent preference. No expiry; cleared when you clear browser storage.
  • circleLocal storage — we store rh_theme (theme preference), rh_locale (language preference), and rh_onboarding_completed (onboarding wizard flag) in your browser's localStorage. Transient entries are also kept in sessionStorage during registration, password reset, and OAuth sign-in, and are cleared when the tab is closed.
  • circleWe use no third-party or tracking cookies. No advertising networks, analytics scripts, or fingerprinting tools are loaded.
  • circleWe do load a small number of third-party resources: the Paddle.js checkout script from Paddle's CDN (used only for billing) and the Material Symbols icon font from Google Fonts. Neither is used for tracking, and no analytics or advertising scripts are loaded.

settingsHow We Use Your Data

Provide CI/CD Services

Your data is used to operate and deliver the core RunnerHub platform — running builds, storing artifacts, managing agents, and processing pipeline definitions.

Improve the Platform

Aggregated and anonymized usage data helps us understand how the platform is used and guides product development decisions.

Security and Fraud Prevention

We use technical data and audit logs to detect and prevent unauthorized access, abuse, and security incidents on the platform.

shareThird-Party Services

GitHub / GitLab / Bitbucket

OAuth tokens are exchanged for repository access, webhook delivery, and commit status reporting. Tokens are stored encrypted at rest and are never logged or exposed in plaintext.

Paddle

Your email address and user ID are shared with Paddle at checkout for billing processing. RunnerHub does not store or have access to your credit card numbers — all payment data is handled directly by Paddle.

Apple App Store Connect

When you configure Apple signing for an app, API key credentials (issuer ID, key ID, and private key) are sent to Apple App Store Connect for certificate and provisioning profile management. These credentials are stored encrypted at rest and are only used when signing is explicitly configured by you.

Google Play

When you configure a Google Play deploy, the service-account JSON you provide is used to publish builds to Google Play. It is stored encrypted at rest and is only used for deploys you configure.

Firebase App Distribution

When you configure a Firebase App Distribution deploy, the token you provide is used to distribute builds to testers. It is stored encrypted at rest and is only used for deploys you configure.

Cloud Object Storage

Build artifacts and support-ticket attachments are stored in S3-compatible cloud object storage.

Email Delivery

Transactional emails — verification codes, build and pipeline notifications, and account emails — are delivered through a third-party SMTP provider.

shieldSecurity Measures

  • circleAES-256-GCM encryption at rest for all sensitive data including OAuth tokens, signing credentials, and API keys.
  • circlebcrypt password hashing — passwords are never stored in plaintext and cannot be recovered by RunnerHub staff.
  • circleAutomatic secret masking in build logs — environment variables and secrets injected into pipelines are redacted from stored log output.

scheduleData Retention

  • circleAccount data is retained while your account is active. When you delete your account, your account and associated data — workspaces, apps, jobs, build logs, artifacts, signing credentials, variables, notification configs, and subscription — are permanently removed via a hard delete. Audit log entries are retained but anonymized (your user reference is removed) and then expire under the normal 90-day audit retention.
  • circleIndividually deleted workspaces are soft-deleted — hidden and excluded from usage but retained in the database — until they are permanently removed on request (support@runnerhub.net) or when your account is deleted.
  • circleBuild artifacts (IPA/APK files) are deleted according to your subscription tier: immediately after the job completes on Free, 7 days on PAYG, 30 days on Pro, and 90 days on Business.
  • circleBuild logs (log output) are retained for 30 days by default, after which the log content is deleted. Job history (status, timing, and metadata) is retained while your account is active.
  • circleAudit logs are retained for 90 days by default for security and compliance purposes. Webhook events are retained for 30 days.

verified_userYour Rights

Access Your Data

You can export a copy of your personal data at any time from Account Settings. The export includes your account, workspaces, jobs, usage, and audit-log entries, and never includes secrets or encrypted credentials.

Delete Your Account

You may permanently delete your account and associated data from Account Settings. Before deletion, your Paddle subscription is cancelled and any outstanding metered usage is settled. Deletion is blocked while jobs are running, so you may need to wait for them to finish or cancel them first. Deletion is a permanent hard delete and is irreversible; audit log entries are retained but anonymized, and your email address becomes available for re-registration.

Update Your Information

You can update your account information and password at any time via your account settings.

mailContact

If you have questions about this Privacy Policy or how we handle your data, please contact us at support@runnerhub.net.

RunnerHub © 2026Terms of Service