Privacy
Last updated July 21, 2026.
Data Purple receives
When you install the Purple GitHub App, GitHub sends installation metadata and workflow job events for repositories you select. Purple stores the installation identifier, account and repository names, workflow job identifiers, requested runner labels, job timing, and conclusion. Purple does not receive repository source code through its webhook.
How data is used
We use this information only to authenticate the installation, match queued jobs to Lupine Cloud capacity, operate ephemeral runners, diagnose failures, and improve the service.
Credentials and retention
The GitHub App private key and webhook secret are stored as encrypted Cloudflare secrets. Cloud nodes receive one-job JIT runner configuration rather than the App private key. Operational metadata is retained only as long as needed to operate and troubleshoot Purple.
Contact
For deletion or privacy requests, contact the Lupine Machines maintainers through the project repository.