Privacy Policy
What Envgrid stores, why it stores it, who else processes it, and how to get a copy or have it deleted. Envgrid runs no analytics and no advertising trackers.
Last updated 2026-09-11
Who is responsible
GULIN BOGDAN P.F.A. is the data controller for personal data processed through Envgrid. Registration details are at the foot of this page, and you can reach us about anything here at support@envgrid.dev.
One thing worth stating plainly: where you connect your own GitHub, GitLab or Jira account, you decide what Envgrid reads and who in your organization can see it. For that content we act on your instruction.
What we collect
Your account. Your email address, and which method you signed in with. If you sign in with GitHub we receive your email and basic profile from them. We never receive your password.
Your organization. Its name, who belongs to it, each member’s role, and pending invitations including the email addresses invited.
What you point Envgrid at. The services, repositories and environments you configure, and the deployment records your pipeline reports — commit SHA, version label, timestamp, and whatever identifier your pipeline sends as the deployer.
Content read from connected systems. Commit messages, commit author names and dates, and the summary, status and type of Jira tickets referenced in those commits. This is the part most likely to contain other people’s personal data — a commit author is a person — and it exists in Envgrid because you connected the repository it came from.
Billing. Your plan, subscription status, renewal date and our payment provider’s customer identifier. Card numbers and billing addresses are held by Paddle, not by us; we never see them.
Operational logs. Ordinary server logs of requests to envgrid.dev, including IP address, kept briefly to investigate errors and abuse.
Why, and on what legal basis
- To provide Envgrid — running the dashboard, the diffs and the history is the contract you entered into with us.
- To take payment — a legal obligation for invoicing and tax, and necessary to perform the contract.
- To keep the service working and secure — investigating errors, preventing abuse. Our legitimate interest, and yours.
- To contact you about the service — billing problems, security notices, material changes to these documents. We do not send marketing email.
Systems Envgrid reads from
These are not our processors. Data flows from them to Envgrid, on your instruction, when you connect an account. Envgrid sends them nothing and writes nothing back.
| GitHub | Commits, comparisons between commits, and deployment events for the repositories added as services. |
|---|---|
| GitLab | Commits, comparisons between commits, and environment deployments for the projects added as services. |
| Atlassian Jira | Summary, status, type and URL of the tickets whose keys appear in connected commit messages. |
Who else processes your data
We use a small number of providers to run Envgrid. Each is bound by a data processing agreement and may only act on our instructions. Where a provider is outside the European Economic Area, transfers rely on the European Commission’s standard contractual clauses.
| SupabaseDatabase and authentication | Everything Envgrid stores: accounts, organizations, services, deployments, commit messages, ticket titles.European Union |
|---|---|
| VercelApplication hosting | Requests to envgrid.dev, including IP address and pages visited, held briefly in operational logs.Global edge network |
| Amazon Web Services (KMS)Encryption keys | No customer data. Holds the key used to encrypt stored access tokens; the data itself never leaves Envgrid.European Union |
| PaddlePayments and invoicing, as merchant of record | Billing name, address, VAT number and payment details. Envgrid never receives or stores card details.United Kingdom, United States |
We do not sell personal data, and we do not share it with anyone else except where the law requires it.
How it is protected
Specifics, rather than an assurance that we take security seriously:
- Every table is protected by row-level security keyed to organization membership, enforced by the database rather than by application code.
- Access tokens for connected accounts are encrypted with a key held in AWS KMS before they reach the database, and are bound to the organization they belong to — a ciphertext moved into another organization's row will not decrypt.
- Token and webhook-secret columns additionally have read access revoked, so they cannot be read through the API even by an organization's own owners.
- The GitHub connection stores no credential at all: short-lived tokens are minted per request and never written down.
- Card details never reach us.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify the supervisory authority within 72 hours where required, and tell you directly where the risk to you is high.
How long it is kept
- Account and organization data: until you delete your account or the organization.
- Services, deployments, commits and tickets: until you delete the service or the organization. Archiving a service keeps its history — that is the point of archiving rather than deleting.
- Billing records: as long as tax law requires us to keep them, which is longer than your subscription.
- Server logs: a short operational retention period, then discarded.
Deleting an organization removes its services, environments, deployments, commits and changelogs. Deleting your account removes your membership, and removes organizations where you were the only owner and only member.
Cookies
Envgrid sets cookies for exactly one purpose: keeping you signed in. There is no analytics, no advertising, and no third-party tracking on this site or in the application — which is also why you have not been asked to dismiss a consent banner.
Your rights
Under the GDPR you may ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. Write to support@envgrid.dev and we will respond within one month.
If you are unhappy with how we have handled your data you can complain to your local supervisory authority. Ours is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), at dataprotection.ro.
If your personal data is in Envgrid because a colleague connected a repository you contributed to, the organization holding it decides what happens to it. Write to us anyway and we will help you reach them.
Changes
When this policy changes the date at the top changes with it, and we will email organization owners before anything material takes effect.
Trader identification
GULIN BOGDAN P.F.A.
Strada Dinu Lipatti nr. 2, sc. B, et. 3, ap. 8, Timișoara, jud. Timiș, România
CUI 51176169 · Reg. com. F2025002109001
EUID ROONRC.F2025002109001 · VAT RO51176169