Legal
Privacy policy
What Apex Actions collects, why, on what basis, where it is processed, how long it is kept, and the rights you have over it.
This policy is in force from 4 September 2026. It describes what we do with personal data as the operator of apexactions.com and app.apexactions.com. Where you use the service to process personal data of your own — in your code, your logs, your commits — we process it on your behalf under the data processing agreement, and this policy describes what we do with data about you.
Who we are
The service is operated by Pristine Technology, doing business as Apex Actions, a Texas company ("Apex Actions", "we"); our postal address is the one on our invoices. For data protection law we are the controller of the data this policy describes. Write to privacy@apexactions.com about anything in it.
What we collect, and why
| What | Where it comes from | Why we process it | Basis |
|---|---|---|---|
| Account data — your GitHub account id, login, display name and avatar | GitHub, when you sign in | To sign you in and show you your account and your runs | Performing our contract with you |
| Installation data — which organisation installed the App, on which repositories, and who did it | GitHub's webhooks | To know whose workflows to run and who may act for an account | Performing our contract |
| Repository data — workflow files, the commits, branches and pull requests that trigger them, job logs, check-run results, caches and artifacts | Your repositories, through the App | To run your workflows and show you the results. This is your content; we process it on your instructions | Performing our contract; the DPA where it holds personal data of others |
| Secrets | You, when you set them | Provided to the job that needs them and nowhere else. Never logged, stored in a log, displayed or snapshotted | Performing our contract |
| The agreement record — who accepted which version of the terms, for which account, when, and from which network address | The app, when a trial is started | To prove the agreement was made, and by whom | Our legitimate interest in evidencing a contract |
| Usage and billing data — plan, minutes used, jobs run, invoices, payment status | The service and our payment provider | To bill you, enforce plan limits, and answer billing questions. We never see your card number; our payment provider holds it | Performing our contract; legal obligation to keep accounting records |
| Audit and security data — privileged actions taken in the app, with actor, time and network address; request logs; abuse signals | The service | To keep the service secure, investigate incidents, and detect abuse | Our legitimate interest in security, and yours |
| Support correspondence | You, when you write to us | To answer you | Performing our contract; our legitimate interest in keeping a record |
| This website — server logs for apexactions.com with network address, user agent and page | Your browser | To keep the site running and to see what is read | Our legitimate interest in operating a website |
We set no advertising cookies and use no third-party analytics on either site. The app sets one session cookie, needed to keep you signed in, and one short-lived cookie during sign-in to prevent login forgery. Neither is used for anything else.
Where it is processed
The service runs on Amazon Web Services in the US East (N. Virginia) region, and our payment provider processes payments in the United States. If you are in the United Kingdom, the European Economic Area or Switzerland, this means your data is transferred outside those territories. The transfer is made under the standard contractual clauses approved for the purpose (and the UK addendum, where it applies), with the providers listed at subprocessors.
Who we share it with
- Our subprocessors — the providers that host the service and collect payment — under contracts that restrict them to those purposes. They are listed, with what each does, at subprocessors, and we give notice before adding one.
- GitHub, because the service is built on it: we send check runs and their annotations back to your repositories and, when you ask us to pin actions, a branch and a pull request; and we read from GitHub what the App is permitted to read.
- Anyone you direct us to — a notification rule that posts to your Slack sends what it says to the destination you configured.
- Authorities, where the law requires it, with notice to you where the law allows.
- A successor to our business, on notice to you.
We do not sell personal data, and we do not share it for anybody's advertising — including as "sell" and "share" are defined in United States state privacy laws.
How long we keep it
| Data | Kept for |
|---|---|
| Logs, artifacts and caches | The retention period of your plan, then deleted |
| Repository data needed to run and show a workflow | While the repository is installed, then deleted within thirty days |
| Account and installation data | While you have an account, then deleted within thirty days of closing it |
| The agreement record and audit data | Six years from the event, for the limitation period on contracts |
| Billing data and invoices | As long as accounting law requires — normally six or seven years |
| Website server logs | Ninety days |
| Support correspondence | Three years from the last message |
How we protect it
The security page describes the measures: every job runs in a fresh, isolated container; fleet machines take further jobs and are terminated after five minutes idle; a job holds no cloud identity of ours; secrets are write-only values; no long-lived cloud keys exist for people, CI or workloads; privileged actions are recorded in an append-only audit log. The measures we commit to contractually are set out in the DPA.
Your rights
Depending on where you are, the law gives you rights over data about you: to be told what we hold, to have a copy of it, to have it corrected or deleted, to restrict or object to its processing, to take it with you in a usable form, and to complain to a supervisory authority. Where we rely on legitimate interests you may object, and we will stop unless we can show a compelling reason not to.
You can exercise most of them yourself: uninstalling the App stops all processing of a repository, and closing your account from the app deletes account data within thirty days. For anything else, write to privacy@apexactions.com. We answer within one month, and we will ask you to prove who you are before we act on a request. We do not treat you differently for exercising a right.
If you are in the EEA or the UK you may complain to the supervisory authority where you live or work. We would rather you wrote to us first, and we will answer.
Children
The service is for business use and is not directed at anyone under eighteen. We do not knowingly collect data from children, and if we learn that we have we delete it.
Changes
We will post changes here and update the date above. For a change that reduces your rights we will write to the address on the account at least thirty days before it takes effect.