Who this notice covers
This notice explains how Testkit Cloud handles personal data when you visit the website, create an account, connect a GitHub repository, or publish Testkit release evidence. “Testkit Cloud”, “we”, and “us” refer to the Testkit Cloud service.
Data we collect
Account data
When you sign in, we receive your WorkOS user identifier, email address, name, profile picture, and organization identifier when one exists. If you choose Google, Google authenticates you through WorkOS. Testkit Cloud does not request custom Google scopes and does not receive or store Google access or refresh tokens.
Project and GitHub data
When you connect a project, we store the project name, GitHub repository name, GitHub App installation identifier, project membership, and a protected digest and short prefix of each project token. A short-lived GitHub user token is used to check repository access during setup and is not stored.
Release evidence
When you publish a Testkit run, we store the sealed run bundle and the evidence you selected, including run identifiers, source commit, branch, pull request number, repository identity including the host, owner, and name, dirty-state information, CI provider and run identifiers, actor and event name, test outcomes, logs, artifacts, receipts, and regression state. Testkit removes local paths, remote URLs, hostnames, and usernames before bundles are sealed.
Service data
Like most hosted services, our infrastructure may process request metadata such as timestamps, IP addresses, user-agent strings, and error details to operate, secure, and troubleshoot the service.
How we use data
We use this data to authenticate users, authorize project access, accept and preserve release evidence, produce receipts and GitHub checks, recognize regressions, prevent abuse, secure the service, and diagnose failures. We do not sell personal data or use it for third-party advertising.
Cookies
Testkit Cloud uses essential cookies for the sign-in flow, authenticated session, GitHub authorization flow, and one-time interface messages. These cookies are required for the service to work. We do not currently use analytics or advertising cookies.
Services that process data
We use service providers to run Testkit Cloud: WorkOS for authentication, Google when you choose Google sign-in, GitHub for repository authorization and checks, Fly.io for application hosting, Neon for PostgreSQL, and Tigris for evidence storage. Each provider processes data under its own terms and privacy commitments.
Retention and deletion
We keep account, project, and release-evidence data while it is needed to operate your account, preserve the release record, meet security requirements, or resolve disputes. Testkit Cloud does not currently offer self-service account deletion or publish a fixed deletion schedule. Contact us to request access, correction, export, or deletion; we will assess the request against any legal, security, and integrity obligations that require us to retain specific records.
Security
We use safeguards appropriate to the service, including hashed project tokens, short-lived provider credentials where supported, authenticated access controls, and encrypted connections. No online service can guarantee absolute security.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to complain to your local data-protection authority. We may need to verify your identity before completing a request.
Changes to this notice
We may update this notice when the service or its legal obligations change. The effective date above shows when this version took effect.
Contact
For privacy questions or requests, email george.dlr@icloud.com.