LEGAL

Privacy

Last updated July 21, 2026.

Data Purple receives

When you install the Purple GitHub App, GitHub sends installation metadata and workflow job events for repositories you select. Purple stores the installation identifier, account and repository names, workflow job identifiers, requested runner labels, job timing, and conclusion. Purple does not receive repository source code through its webhook.

How data is used

We use this information only to authenticate the installation, match queued jobs to Lupine Cloud capacity, operate ephemeral runners, diagnose failures, and improve the service.

Credentials and retention

The GitHub App private key and webhook secret are stored as encrypted Cloudflare secrets. Cloud nodes receive one-job JIT runner configuration rather than the App private key. Operational metadata is retained only as long as needed to operate and troubleshoot Purple.

Contact

For deletion or privacy requests, contact the Lupine Machines maintainers through the project repository.