Privacy Policy

Last updated: July 28, 2026

1. What we collect

When you sign in with GitHub OAuth, we receive your name, email address, and avatar URL. We also store the organizations, packages, and package archives you create or publish, and basic metadata about API tokens (name, type, last-used date — never the raw token itself).

2. How we use it

Your GitHub profile is used to authenticate you and identify you within your org. Your email is used to send transactional messages — org invites and account notices — via Resend. We don't run ads, don't use ad-tracking, and don't sell your personal data to anyone.

3. Where it's stored

Account and package metadata live in PostgreSQL (hosted on Supabase). Package archives are stored on Backblaze B2. The application itself runs on Fly.io. All three are commercial infrastructure providers bound by their own data-processing terms.

4. Cookies & analytics

Publy sets one strictly-necessary session cookie to keep you signed in. For site analytics we use Umami, a privacy-focused service that doesn't use cookies and doesn't track you across other websites — we only see aggregate, anonymized visit data (pages viewed, referrers, rough location). We don't use ad-tracking and don't sell your personal data to anyone.

5. Your rights

You can ask us to access, export, or delete the personal data we hold about you at any time — email the support address in the footer and we'll handle it manually. If you delete your GitHub-linked account's data, any orgs where you're the sole owner will need a new owner assigned first.

6. Changes to this policy

If this policy changes in a way that affects how we handle your data, we'll update the date above and, for material changes, email affected users directly.

7. Contact

Questions or complaints about how we handle your data go to the support email in the footer — we'll respond as soon as we can.