Privacy
releasedapp is an open-source project run by one person and kept alive by donations. It does not sell data, show ads, or track you across the web. This page says exactly what it does keep — and every claim here can be checked against the code.
What we store
read:user and user:email scopes and nothing else — we never see your repositories.We do not record your IP address. There is no analytics script, no advertising pixel, and no cookie other than the one that keeps you signed in.
Why
To show you your watchlist, to answer your agent when it asks what changed, and — only if you turn it on — to send you one email on days something you watch shipped. Nothing else. There is no profiling and no use of your data for anything you did not ask for.
Who else sees it
- Cloudflare hosts the service, stores the database, and sends the email. Your data lives on their infrastructure.
- GitHub handles sign-in. What GitHub knows about that is covered by GitHub's own privacy statement.
- Package registries (npm, PyPI, crates.io, NuGet, Packagist, RubyGems, pub.dev, Hex.pm) are asked about packages, never about people. A request to a registry carries a package name and nothing that identifies you.
Nobody else. We do not sell, rent or share your data, and there are no advertisers because there are no ads. Sponsors who help pay for the service are thanked by name on the site; they receive nothing about you — not a count, not an address, not a package name.
For how long
- Your account and watchlist: until you delete them.
- Digests: seven days, then a scheduled job removes them.
- Sessions: thirty days of inactivity.
- Agent tokens: fifteen minutes for access, until disconnected for refresh; the consent until you disconnect it.
- Sign-in state that was never completed: ten minutes.
What you can do
- See everything — the dashboard and your agent's
list_packagesshow all of it. Ask and we will send you an export. - Delete everything — Settings → Delete everything. It is immediate, it takes the watchlist, the digests, the sessions and the agent consents with it, and there is no soft-delete we keep around.
- Stop the email — one click in any digest, or the switch in Settings. The account stays.
- Disconnect an agent — Settings → Connected agents.
- Complain — if you are in the EU you can contact your data protection authority. We would rather you wrote to us first.
Changes
This page is versioned with the code. If it changes in a way that matters, the change is in the repository's history with the reason next to it.