Privacy policy

This notice explains what Chronik does with personal data, who receives it, and what you can ask us to do about it. It describes the service as it actually runs; where something is not yet decided, it says so rather than describing an intention.

Who is responsible

PUSHERY, ℅ ElementarySupplies UG (haftungsbeschränkt), Ringbahnstr. 42, 12099 Berlin, Germany. Contact: [email protected], +49 (0) 30 / 398 216 398. Full details are in the imprint.

We have not appointed a data protection officer; we are below the threshold in § 38 BDSG. Requests under Articles 15 to 22 GDPR reach a person at the address above.

What Chronik is, and why that shapes everything below

Chronik watches releases in the GitHub repositories you connect and turns them into messages in the places you choose. Two consequences run through this whole notice:

You decide who receives the announcements. Connecting a Slack workspace, naming a webhook endpoint or making a changelog page public are your choices, and each one sends release content — including the name of whoever published the release — somewhere we do not control. We deliver where you point us; we cannot judge whether that destination was the right one.

Release data is other people's data too. A release carries the GitHub identity of the person who published it. That person is usually not you, and usually has no account here.

Data we hold, and why

Your account. Name, email address, and — if you use one — a password hash, two-factor secret and recovery codes. Language, time zone and session length are settings you chose. We need these to give you an account and to keep it yours. Legal basis: Article 6(1)(b) GDPR (performing the contract) and Article 6(1)(f) (securing the account).

Signing in. Chronik uses your GitHub account to sign you in. Two-factor codes sent by email are stored only as a hash and expire. Devices you have signed in from are remembered as a one-way fingerprint, never as a stored IP address or browser string — enough to notice a new device, not enough to reconstruct where you were.

What you connected. The GitHub installation, the account it belongs to, its avatar, and the repositories it covers, each by its GitHub identifier, name and owner. Legal basis: Article 6(1)(b) GDPR.

Releases and the events behind them. The webhook payload GitHub sends us, kept as received, and the release we derive from it. The payload names the release author. Legal basis: Article 6(1)(f) GDPR — our and your legitimate interest in a reliable, replayable record of what was announced; a delivery that cannot be replayed cannot be corrected.

Changes to your account. Name and email changes are recorded with a timestamp so an unexpected change can be traced. Legal basis: Article 6(1)(f) GDPR.

Consent records. When you accept the terms or acknowledge this notice, we store the fact, the document version and the time, in a tamper-evident ledger. That record exists so we can demonstrate what you were shown, which Article 7(1) GDPR requires of us.

Cookies

Chronik sets no tracking cookies and shows no cookie banner, and those two facts belong together. The only cookies are the ones that keep you signed in and protect forms against cross-site request forgery. They are strictly necessary under § 25 (2) TDDDG, which is why no consent is asked for them.

Analytics

We measure page views with Matomo, on our own server, from the request that already happened. No script runs in your browser, nothing is stored on your device, and no third party is involved. This is the reason the previous paragraph can be as short as it is.

Who receives data

The list below is generated from a single machine-readable register in this application, so that it and our record of processing activities cannot drift apart.

  • GitHub, Inc. — the platform Chronik reads releases from. Where: USA. Basis for transfer: see below.
  • Sentry (Functional Software, Inc.) — error reports. Where: Germany — Sentry's EU region. Basis for transfer: none needed.
  • Flare (Spatie BV) — error reports. Where: Belgium. Basis for transfer: none needed.
  • Nightwatch (Laravel Holdings Inc.) — performance monitoring. Where: USA. Basis for transfer: see below.
  • Cloudflare, Inc. — delivery and denial-of-service protection. Where: USA. Basis for transfer: see below.
  • Matomo — usage analytics. Where: Germany — our own server. Basis for transfer: none needed; no third party.

Destinations you chose are not in this list, because we did not choose them. A Slack workspace, a Telegram chat or a webhook endpoint receives what you told Chronik to send there, and the operator of that destination decides what happens to it.

Transfers to the United States rest on the European Commission's adequacy decision for the EU–US Data Privacy Framework where the recipient is certified under it, and otherwise on standard contractual clauses. We are confirming the exact basis for each US recipient and will name it here rather than leave a general sentence standing in for it.

Email delivery has no provider yet. Chronik currently writes mail to a local log instead of sending it. When a provider is chosen it becomes a recipient of your address and will be named here before the first message goes out.

How long we keep things

Your account and what you connected: for as long as you have an account. Release events and releases: for as long as the repository is connected, so that a changelog stays complete. Two-factor codes: until they are used or expire. Consent records: for as long as we may need to demonstrate them, which outlives the account itself — that is their purpose.

Delete your account and the account data goes with it. What was already published to a destination you chose is beyond our reach; you would have to remove it there.

Your rights

You can ask us for a copy of your data (Article 15), to correct it (Article 16), to erase it (Article 17), to restrict its use (Article 18), to receive it in a portable form (Article 20), and to object to processing we base on legitimate interests (Article 21). Chronik can produce your data as a file from within the application.

You can also complain to a supervisory authority. Ours is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin.

Changes to this notice

We publish a version number with every change. A change that affects you materially is announced rather than quietly deployed.