Legal

Privacy Policy

What we collect, why we collect it, and what we never touch. Deliberately short, because we deliberately collect little.

Updated 1 Jan 2025

01Data you give us directly

  • Your name, as you enter it at signup, used to address you in the interface.
  • Your email address, used for sign-in, password resets and abuse notices.
  • A password, stored only as a salted hash by Supabase Auth. We never see it in plain text.
  • Your notification preferences.

02Data we receive from GitHub

When you connect GitHub we request the read:user and user:email scopes — nothing more. We cannot read your repositories, private or public, and we cannot act on your behalf.

  • Your numeric GitHub user id. This is the identity anchor, so renaming your GitHub account never affects your subdomains.
  • Your username, display name, avatar URL and profile URL.
  • Your GitHub account creation date, used only for the optional minimum-account-age check.
  • Your primary verified email address, if one is available.
  • Timestamps: when you authorised, and when we last confirmed the authorisation is still valid.

03The GitHub access token

We keep the OAuth access token so we can detect when you revoke authorisation — that check is only possible by presenting the token to GitHub.

It is encrypted with AES-GCM before it is written, stored in a table that no API route ever reads from, and is never included in any response to a browser. The OAuth code exchange happens entirely inside a Cloudflare Worker, so the token never exists in your browser at all.

Disconnecting GitHub deletes the stored token immediately.

04Data generated by using the service

  • The subdomains you register and their status history.
  • The DNS records you create, update and delete.
  • An audit log of security-relevant actions: sign-ins, GitHub connect/disconnect events, registrations, releases and DNS changes. Each entry records the IP address and user agent that made the request.
  • Rate-limit counters, which are keyed by account or IP and expire automatically within minutes.

05What we do not do

  • No advertising, no ad networks, no tracking pixels, no third-party analytics scripts.
  • No sale, rent or trade of personal data.
  • No profiling or automated decision-making beyond the anti-abuse checks described in the Acceptable Use Policy.
  • No access to your GitHub code, issues, organisations or private data.

06Processors we rely on

  • Supabase — database, authentication and session management.
  • Cloudflare — DNS hosting, the Worker that runs the API, and Turnstile bot protection.
  • GitHub — identity verification only, at your initiation.

07Retention

  • Account data is kept while your account exists. Deleting your account removes the profile and cascades to your subdomains, DNS records and stored GitHub credential.
  • Audit log entries are retained after account deletion in anonymised form (with the account reference cleared) because they are a security record.
  • Abuse reports are retained so repeat patterns remain visible.

08Your rights

You can view and correct your profile from the account settings page at any time, export nothing more than what is already shown there, and delete your account once you have released your subdomains.

For any request that the interface does not cover — including access, portability or erasure requests — contact support@itdev.eu.cc and we will respond within 30 days.

09Cookies and local storage

We set no advertising or analytics cookies. Your Supabase session and your light/dark theme preference are stored in your browser's local storage. Cloudflare Turnstile may set a short-lived cookie as part of the bot check.

10Contact

Privacy questions: support@itdev.eu.cc.