How Runnerhut handles the information needed to operate the service
Privacy policy
How Runnerhut processes account, GitHub and MCP connection data, the purposes for doing so, and how to exercise your privacy rights.
Oppdatert 2026-08-26
Controller and contact
Information we process
- GitHub account and installation information: your GitHub numeric ID, login, and verified primary email address; the installation ID and account name for the connected GitHub App; and the names, IDs, private/public status, and Runnerhut compatibility status of repositories that installation makes available.
- Runnerhut workspace information: selected repositories, runner profile settings, migration campaign state, and limited operational status needed to show the dashboard and serve the read-only MCP tools.
- Authentication and security information: a hashed Runnerhut session token, OAuth state and PKCE verifier in short-lived browser cookies, and security-relevant request data needed to prevent abuse and diagnose failures.
- MCP authorization information: a registered client name and redirect URI in a signed, short-lived client identifier; a one-time authorization-code hash; and an access token held by the MCP client. We do not store the client identifier, authorization code in plaintext, or access token in D1.
- Messages you send to us through our support channels, including the contact details and information you choose to include.
How and why we use it
- To authenticate you with GitHub, set up and protect your Runnerhut session, and provide the dashboard and service you request. Where applicable, this is necessary to perform a contract or take steps at your request before entering one (GDPR Art. 6(1)(b)).
- To operate, secure, debug, and improve the service; protect against misuse; and establish, exercise, or defend legal claims. We rely on our legitimate interests for these activities (GDPR Art. 6(1)(f)).
- To meet legal obligations that apply to us (GDPR Art. 6(1)(c)).
- Where we ask for consent for a separate activity, to carry out that activity. You may withdraw consent at any time; this does not affect processing that occurred before withdrawal.
What the MCP server can return
Oppbevaring
Recipients and transfers
Dine rettigheter
Changes to this notice
Neste bygg kan gå dobbelt så fort, til halve prisen
Start gratis. Å bytte bort er den samme ene linjen, og den diffen publiserer vi også.
