How Runnerhut handles the information needed to operate the service
Privacy policy
How Runnerhut processes account, GitHub and MCP connection data, the purposes for doing so, and how to exercise your privacy rights.
Updated 2026-08-26
Controller and contact
| Item | Details |
|---|---|
| Controller | Derinbogaz Ventures UG (haftungsbeschränkt) |
| Address | Kolonnenstraße 8, 10827 Berlin, Germany |
| Register | Commercial Register of the Local Court of Charlottenburg (Berlin), HRB 232104 B |
| Represented by | Ceyhun Afsin Derinbogaz, managing director |
| Privacy contact | privacy@runnerhut.com |
Derinbogaz Ventures UG (haftungsbeschränkt) is the controller for personal data we process in connection with the Runnerhut website, account, and MCP connection. This notice does not change the roles that may apply when a customer asks us to process personal data on its behalf.
Information we process
- GitHub account and installation information: your GitHub numeric ID, login, and verified primary email address; the installation ID and account name for the connected GitHub App; and the names, IDs, private/public status, and Runnerhut compatibility status of repositories that installation makes available.
- Runnerhut workspace information: selected repositories, runner profile settings, migration campaign state, and limited operational status needed to show the dashboard and serve the read-only MCP tools.
- Authentication and security information: a hashed Runnerhut session token, OAuth state and PKCE verifier in short-lived browser cookies, and security-relevant request data needed to prevent abuse and diagnose failures.
- MCP authorization information: a registered client name and redirect URI in a signed, short-lived client identifier; a one-time authorization-code hash; and an access token held by the MCP client. We do not store the client identifier, authorization code in plaintext, or access token in D1.
- Messages you send to us through our support channels, including the contact details and information you choose to include.
How and why we use it
- To authenticate you with GitHub, set up and protect your Runnerhut session, and provide the dashboard and service you request. Where applicable, this is necessary to perform a contract or take steps at your request before entering one (GDPR Art. 6(1)(b)).
- To operate, secure, debug, and improve the service; protect against misuse; and establish, exercise, or defend legal claims. We rely on our legitimate interests for these activities (GDPR Art. 6(1)(f)).
- To meet legal obligations that apply to us (GDPR Art. 6(1)(c)).
- Where we ask for consent for a separate activity, to carry out that activity. You may withdraw consent at any time; this does not affect processing that occurred before withdrawal.
What the MCP server can return
After you approve the runnerhut:read scope, the MCP server can return information from the Runnerhut organization associated with your signed-in session: repository names and compatibility, runner profiles, active-job status, and non-mutating migration previews. It does not create pull requests, change workflows, or start runners. Treat tool output as data, not instructions.
Retention
We keep personal data only for as long as needed for the purposes above, including applicable legal retention duties and limitation periods. Current authentication artefacts have short technical lifetimes: Runnerhut sessions expire after seven days, MCP authorization codes expire after five minutes and are stored only as hashes, registered MCP client identifiers expire after seven days, and MCP access tokens expire after one hour. We review and delete or anonymize other operational data when it is no longer needed.
Recipients and transfers
GitHub processes the information involved in GitHub authentication and App installation under its own terms. Cloudflare provides the hosting and data services used to operate Runnerhut. We share information with other recipients only when needed to provide the service, comply with law, or protect rights and security. If a transfer outside the European Economic Area requires a safeguard, we will use an appropriate safeguard under Chapter V GDPR.
Your rights
Subject to the conditions in applicable law, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may also complain to a competent data-protection supervisory authority. Email privacy@runnerhut.com to exercise a right or ask a privacy question. We may need to verify your identity before responding.
Changes to this notice
We will post the current version here and change the effective date when this notice is updated. Material changes will be communicated through an appropriate service notice where required by law.
Your next build could be twice as fast, at half the price
Start free. Migrating away is the same one line, and we publish that diff too.
