Privacy Policy
Last updated: July 28, 2026
1. What we collect
When you sign in with GitHub OAuth, we receive your name, email address, and avatar URL. We also store the organizations, packages, and package archives you create or publish, and basic metadata about API tokens (name, type, last-used date — never the raw token itself).
2. How we use it
Your GitHub profile is used to authenticate you and identify you within your org. Your email is used to send transactional messages — org invites and account notices — via Resend. We don't run ads, don't use ad-tracking, and don't sell your personal data to anyone.
3. Where it's stored
Account and package metadata live in PostgreSQL (hosted on Supabase). Package archives are stored on Backblaze B2. The application itself runs on Fly.io. All three are commercial infrastructure providers bound by their own data-processing terms.
4. Cookies & analytics
Publy sets one strictly-necessary session cookie to keep you signed in. For site analytics we use Umami, a privacy-focused service that doesn't use cookies and doesn't track you across other websites — we only see aggregate, anonymized visit data (pages viewed, referrers, rough location). We don't use ad-tracking and don't sell your personal data to anyone.
5. Your rights
You can ask us to access, export, or delete the personal data we hold about you at any time — email the support address in the footer and we'll handle it manually. If you delete your GitHub-linked account's data, any orgs where you're the sole owner will need a new owner assigned first.
6. Changes to this policy
If this policy changes in a way that affects how we handle your data, we'll update the date above and, for material changes, email affected users directly.
7. Contact
Questions or complaints about how we handle your data go to the support email in the footer — we'll respond as soon as we can.