Privacy Policy
How ActionWatch handles your information.
Last updated: August 14, 2026
Overview #
ActionWatch provides GitHub Actions observability. We collect and process the information needed to authenticate users, connect GitHub accounts and installations, ingest GitHub Actions data, operate the service, and improve reliability and security.
Information We Collect #
- Account information such as your GitHub login, GitHub user ID, and associated billing account records.
- Repository, workflow, run, job, step, and installation data that GitHub makes available to ActionWatch.
- Operational information such as logs, task execution records, webhook delivery state, and usage diagnostics.
- Billing information provided through Stripe, including subscription state and invoice/payment event metadata.
How We Use Information #
- To authenticate users and authorize access to repositories and dashboards.
- To ingest, store, and analyze GitHub Actions data so we can provide dashboards, diagnostics, alerts, and related product features.
- To operate, secure, troubleshoot, and improve the service.
- To manage subscriptions, billing, quota enforcement, and account lifecycle workflows.
- To compute aggregate, de-identified statistics, and to show them to other customers as comparative benchmarks. See Aggregate and De-Identified Data.
Sharing #
We do not sell personal information. We share data with infrastructure and payment providers that help us operate ActionWatch, including hosting, database, logging, and billing services, subject to appropriate contractual and operational safeguards.
Cookies and Measurement #
ActionWatch uses no third-party analytics or advertising scripts. Nothing on our pages reports to anyone but us.
- Session cookies. Signing in sets cookies that carry your ActionWatch session. They are required for the application to work and are cleared when you sign out.
- A visitor cookie. When you first reach the application we set a cookie containing a random identifier. It is generated at random, is not derived from anything about your browser or device, and expires after 180 days. We use it for one purpose: counting how many people who arrive go on to connect a GitHub account, so we can tell whether changes to that process helped. It records the step, not the person — an operator can see how many visitors reached each step, and cannot see who they were. Clearing it in your browser removes it.
Aggregate and De-Identified Data #
ActionWatch may compute and retain aggregate, de-identified statistics derived from the GitHub Actions telemetry it processes for your account, and may present those aggregates to other customers as comparative benchmarks — for example, how one organization's workflow queue delay compares with the median for organizations of a similar size.
What these aggregates contain. Counts, durations, rates, and distribution summaries such as medians and percentiles — how many workflow runs completed, how long they took, how often they failed, how long they waited to start.
What they never contain. Repository names, commit messages, commit contents, branch names, workflow file contents, secrets, environment variables, log output, or the identity of any user or commit author. These are excluded at the point the aggregate is computed, not removed from it afterwards.
How long they are kept. Aggregates are derived from your data but are not a copy of it. ActionWatch retains them independently of the records they were computed from, so they survive the deletion of that underlying data and the closure of your account. They cannot be traced back to it.
Why no customer is identifiable in them. A comparative statistic is only shown when its peer group contains enough distinct organizations that no single one can be inferred from the result. Where a peer group is too small, ActionWatch shows nothing rather than a statistic that would describe one customer.
This section describes what ActionWatch is permitted to do with your data. Comparative benchmarks are not a feature of the service today, and ActionWatch does not sell your data or supply these aggregates to third parties as a product.
Retention #
We keep information for as long as needed to operate ActionWatch, meet legal obligations, resolve disputes, and enforce agreements. Some operational and billing records may be retained after account deletion where reasonably necessary for security, compliance, or financial recordkeeping.
Aggregate, de-identified statistics are retained separately and are not deleted with the data they were derived from. See Aggregate and De-Identified Data.
Security #
We use reasonable administrative, technical, and organizational safeguards designed to protect information handled by ActionWatch. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.
Your Choices #
You can stop using the service, disconnect repositories or installations through GitHub, or request account deletion through ActionWatch where available. Some GitHub-sourced data may continue to exist in system backups or retained operational records for a limited period.
Deleting your account does not withdraw aggregate, de-identified statistics already computed from your telemetry, because they contain nothing that identifies you or your organization and cannot be traced back to either.
Contact #
Questions about this Privacy Policy can be sent through our contact form.
Messages sent through the contact form, and the email address you submit with them, are stored in a private issue tracker used to route and respond to inquiries.