Privacy policy

Effective

This explains what personal data Pulse handles, why, how long we keep it, and how you can delete it. It is written for members of Amirus’s engineering team. See also the terms of use.

Who we are

Pulse is an internal engineering tool run by Amirus (“we”). It shows CI/CD status, deployments and team activity from our GitHub repositories, on the web and in an Android app. Access is by invitation only. For this policy, Amirus is the controller of the personal data described below.

Data we collect

From your GitHub account when you sign in: your GitHub user id, username (login), display name, email address and avatar URL. We never see your GitHub password.

Session data: when you sign in we record the IP address, browser or device description (user agent) and, for the Android app, a device name, plus when each session was created and last used.

Push notification data (Android app): a Firebase Cloud Messaging device token, the platform, app version and device name for each phone you register, and your notification preferences.

Notifications: the title, text and link of each notification we create for you (for example “a deployment is waiting for your approval”), and whether you have read it.

Audit log: a record of security-relevant actions (sign-ins, role changes, re-running a workflow, approving a deployment, creating API keys). Each entry holds who did it, what, when and from which IP address.

Mirrored GitHub activity: Pulse copies public and private repository activity that our GitHub App receives: workflow runs, deployments, commits, pull requests, releases and issues. This includes the GitHub usernames and names of the people who did the work. This is repository data, not data about your use of Pulse.

GitHub access token: if you approve deployments from Pulse, we keep your GitHub user token so the approval is made as you. It is encrypted at rest.

Why we use it

  • To sign you in and decide what you may see and do (roles and repository access).
  • To show status and activity, and to send you the notifications you have enabled.
  • To keep the service secure: detecting misuse, investigating incidents, and keeping the audit trail.
  • To operate and fix the service.

We do not sell personal data, do not use it for advertising, and do not use analytics or advertising trackers in Pulse. Legal basis: [to be confirmed with our legal advisor; typically legitimate interests in running our engineering tooling and securing our systems, and performance of the working relationship].

How long we keep it

  • Sessions: 30 days from last use, and never longer than 90 days from sign-in. Signing out or revoking a session deletes it at once.
  • Notifications: 90 days, then deleted automatically.
  • Incoming GitHub webhook deliveries and outbound webhook logs: 30 days.
  • Device tokens, preferences and your GitHub token: until you remove them or delete your account.
  • Audit log: kept indefinitely, because it is our security and accountability record. When you delete your account, your name is removed from it (see below).
  • Mirrored repository activity: as long as the repository is tracked in Pulse.

Operators can shorten the delivery and notification periods; the values above are the defaults.

Who else handles it

We use a small number of service providers who process data on our behalf:

  • GitHub (sign-in, and the source of repository activity).
  • Google Firebase Cloud Messaging (delivering push notifications to the Android app; it receives the device token and the notification text).
  • Our hosting provider (servers, database and backups on which Pulse runs).

Members of Amirus with the right role can see the audit log and the member list. We do not otherwise share personal data unless the law requires it.

How we protect it

All traffic uses encryption in transit (HTTPS). GitHub tokens and outbound webhook secrets are encrypted at rest. Session tokens and API keys are stored only as one-way hashes, so we cannot read them back. Access is limited by role, and cookies are HTTP-only. No system is perfectly secure; if we learn of a breach affecting you, we will tell you as the law requires.

Your rights and deleting your account

You can view your profile, sessions and devices in Pulse under Your profile, and revoke any of them.

To delete your Pulse account, use Delete account (also linked from the Android app’s Settings). Deletion signs you out everywhere and removes your sessions, devices, GitHub token, notification preferences and notifications, revokes your API keys, and clears your name, email, avatar and GitHub id from your record. Audit entries you appear in are kept (what happened and when) but relabelled with an anonymous id, and the IP addresses and any username, name or email stored in them are removed. Repository activity that GitHub sent us stays, as it is GitHub’s data.

Depending on where you live you may also have the right to access, correct, export or object to the use of your data. Contact us and we will respond within a reasonable time. You can also complain to your data protection authority.

Children

Pulse is for our engineering team and is not directed at children.

Changes to this policy

If we change this policy in a way that matters, we will update the effective date above and, for larger changes, tell members in the app.

Contact

Questions or requests about your data: amirusbyrig@gmail.com.