Back to home

Privacy Policy

Last updated: July 13, 2026

Introduction

This Privacy Policy explains how OpsSignal ("we", "us", or "our") collects, uses, and protects information when you use the Service at https://opssignal.dev.

OpsSignal is a software-as-a-service that monitors GitHub Actions workflow failures through a GitHub App and delivers notifications to Discord channels you configure. The Service may be offered in beta, early access, or preview form, including during our MVP period, as described in our Terms of Service.

By using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.

Information We Collect

We collect only the information needed to operate OpsSignal as a notification aid for GitHub Actions workflow failures. The categories below describe what we collect and what we do not collect.

Consistent with our Terms of Service, OpsSignal does not access, store, or analyze your source code, commit contents, or GitHub account passwords, and does not store Discord message bodies.

GitHub OAuth

When you sign in with GitHub OAuth, we receive information that GitHub shares with authorized applications.

Information we may collect:

  • GitHub user ID
  • GitHub username
  • Display name
  • Email address (if available from GitHub)

Information we do not collect or store:

  • GitHub password
  • Personal access tokens
  • Private source code

We use this information to authenticate you, create and manage your OpsSignal account, and associate your integrations with the correct user.

GitHub App

When you install the OpsSignal GitHub App and grant repository access, we receive webhook events and repository metadata needed to monitor workflow failures.

Information we may collect:

  • GitHub App installation ID linked to your account
  • Repository ID and repository name (repository metadata)
  • Repository enable/disable preferences you set in OpsSignal
  • GitHub Actions workflow failure events, including workflow name, branch, status, repository reference, and related metadata from the webhook payload

Information we do not collect, store, or analyze:

  • Source code
  • Commit contents or commit diffs
  • Repository files or file contents

We process installation and repository data to determine which repositories to monitor and which notifications to send. Workflow failure events are processed only to generate Discord alerts.

Discord

If you configure Discord notifications, we store the destination needed to deliver alerts.

Information we store:

  • Discord webhook URL you provide

Information we do not store:

  • Discord message bodies
  • Discord channel history
  • Discord user accounts or user profiles

Webhook URLs are treated as sensitive credentials. We do not publish them or use them for any purpose other than delivering notifications you request. You are responsible for keeping webhook URLs confidential and rotating them if compromised.

Usage Data

When you access the Service, we may automatically collect technical and operational information, such as:

  • Access logs and timestamps
  • IP address and approximate region (for example via hosting or CDN logs)
  • Browser type and version
  • Device and operating system information
  • Error logs and diagnostic data

We use this information to operate, secure, troubleshoot, and improve the Service, and to prevent abuse.

Notification Logs

OpsSignal is a supplementary notification aid. Notifications may be delayed or fail due to network issues, GitHub, Discord, Cloudflare, hosting providers, or other events beyond our reasonable control, as described in our Terms of Service.

We do not store Discord message bodies. To operate the Service, we may retain limited notification logs, such as:

  • Notification timestamps
  • Delivery status (success or failure)
  • Error information
  • Troubleshooting logs related to notification delivery

We use these limited logs for troubleshooting, security, and service operation, and retain them only as long as reasonably needed.

Cookies

We use cookies and similar technologies for essential functions such as authentication, session management (including Laravel Sanctum session cookies), and security.

We do not use cookies for third-party advertising. You can control cookies through your browser settings, but disabling essential cookies may prevent you from signing in or using the Service.

How We Use Information

We use the information we collect to:

  • Authenticate users and manage accounts
  • Provide GitHub OAuth and GitHub App integrations
  • Process GitHub Actions workflow failure events and send Discord notifications
  • Protect the Service, detect abuse, and investigate security issues
  • Respond to customer support requests and communicate about the Service
  • Improve reliability, usability, and features of the Service
  • Process subscription payments when Stripe billing is enabled
  • Comply with applicable legal obligations

Legal Basis for Processing

If applicable data protection laws such as the GDPR apply to you, we process personal data under one or more of the following legal bases:

  • Performance of a contract: to provide the Service you request, including authentication, GitHub integration, and Discord notifications
  • Legitimate interests: to secure, operate, and improve the Service, prevent abuse, and maintain service reliability
  • Legal obligations: to comply with applicable laws and respond to lawful requests
  • Consent (where required): for specific processing activities where consent is needed under applicable law

Data Retention

We retain account, integration, and related data while your account is active and as needed to provide the Service.

If you disconnect GitHub, remove a Discord webhook URL, uninstall the GitHub App, or request account deletion, we will delete or anonymize associated data within a reasonable period, unless retention is required by law or needed for legitimate purposes such as security, fraud prevention, or dispute resolution.

Usage logs and limited notification logs are retained for a limited time for security and troubleshooting, then deleted or aggregated.

Data Security

We implement reasonable technical and organizational measures to protect your information, including HTTPS encryption in transit, access controls, protection of sensitive credentials such as Discord webhook URLs, and webhook signature verification for GitHub events.

No method of transmission or storage is completely secure. We cannot guarantee absolute security. You remain responsible for safeguarding your GitHub account, Discord webhook URLs, and devices used to access the Service.

International Data Transfers

OpsSignal is available to users worldwide. Your information may be processed and stored in Japan and in other countries where our infrastructure providers operate, such as Cloudflare or Hetzner.

When information is processed across borders, we take reasonable steps appropriate to the circumstances and applicable law to protect it.

Third-Party Services

We rely on third-party services to operate OpsSignal. These providers process information as needed to provide their services. We currently use or may use:

  • GitHub — OAuth, GitHub App, and webhooks
  • Discord — webhook delivery for notifications
  • Cloudflare — CDN, DNS, and security
  • Hetzner — hosting and infrastructure
  • Stripe — planned for subscription billing when enabled

We do not currently use Google Analytics or Sentry. If we introduce analytics or error-monitoring tools in the future, we will update this Privacy Policy.

Third-party APIs and products may change over time. Changes by GitHub, Discord, Stripe, Cloudflare, Hetzner, or other providers may affect which data is available to us or how integrations work. Your use of those services is also subject to their own terms and policies.

Your Rights

Depending on your location, you may have rights to access, correct, delete, or export your personal data, or to object to or restrict certain processing.

To ask a question or request deletion of your data, contact us at [email protected]. We may need to verify your identity before responding.

You may also revoke GitHub App access, disconnect OAuth, or remove Discord webhook URLs through GitHub, Discord, or your OpsSignal settings where available.

Children's Privacy

The Service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at [email protected] and we will take appropriate steps to delete it.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the revised Policy on this page and update the "Last updated" date. Material changes may be communicated through the Service or by email where appropriate.

We encourage you to review this Policy periodically.

Contact

For privacy-related questions or requests, contact us at [email protected].