Privacy Policy

Last updated 5 October 2026

This policy explains what personal data Paddo Tech Pty Ltd ("we", "us") collects when you use ushr.io, the hosted control plane at cp.ushr.io, and the ushr agent connected to them. It also explains why we collect it, who receives it, and your rights.

Who we are

Paddo Tech Pty Ltd, ABN 94 625 633 285, 2/290 Boundary Street, Spring Hill QLD 4000, Australia, controls this data. We are based in Australia, and we access the data from there. Contact: hello@paddo.tech.

We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). If a data breach is likely to cause you serious harm, we will tell you and the Office of the Australian Information Commissioner (OAIC).

What we do not collect

The ushr agent runs on your hardware. Your GitHub App private key stays there. The Service does not receive your source code, build logs or repository secrets. Your runners connect to GitHub directly. The agent does send short error messages about updates and host setup, as described below.

What we collect

Account and workspace. Your name, email address and profile image. Your workspaces, members, roles, and the email addresses of people you invite. Our sign-in provider, Neon Auth, may also store the access token that GitHub or Google issues when you sign in with them. We do not use that token to call GitHub or Google.

Sessions. For each signed-in session: the IP address and browser user agent. We look up an approximate city and country for the IP address and show it in your sessions list. You can see and end your sessions in the dashboard.

GitHub verification. For each GitHub scope you verify: the organisation login, or for a personal account the owner and repository names, and the App installation ID. We use a GitHub access token only during verification and do not store it.

Host enrollment. Each host's name, the GitHub scopes it serves, and a hash of its enrollment token. Who approved the host and from which IP address. For the ushr login handshake: the host name, a confirmation code, and the IP address that started it. We show an approximate city and country for that IP address when you approve a host. For hosted GitHub App setup: the App ID, App slug and webhook secret for each host.

Fleet telemetry. The agent sends a heartbeat with its version, update state and update errors, labels, slot capacity and use, queued jobs (scope, priority, job ID, labels and wait time), disk free and total space, and whether it is refusing work. When a job cannot start, the agent sends the error message. We keep update errors in host status, and job start errors in server logs. For each job the Service schedules, we record the host that ran it, its status, and its timestamps. GitHub sends us workflow job webhooks with the organisation, repository and workflow names, run and job IDs, runner labels, conclusion and timings.

Alerts. Open alert conditions for your hosts (for example, a host that is out of disk space), and when we last emailed your workspace admins about them. The alert channels your admins add: each Slack or webhook URL, and the signing secret for each webhook.

Audit log. For each admin action in a workspace: the email address of the person who acted, the action, what it applied to, and the time.

Email domains. The email domains your workspace claims and their verification status. When someone with a verified address on a claimed domain asks to join, their user ID and email address until an admin approves or dismisses the request.

Terms acceptance. When you accept our terms, we record your user ID, the workspace, the terms version and the time.

Billing. Your Stripe customer and subscription IDs, plan, subscription status, number of paid hosts, current period end, and when a payment first failed. Stripe holds your card and billing address. We never see your full card number.

Former waitlist. If you joined our earlier waitlist: your email address, and the name and note you gave us, if any. The waitlist no longer takes sign-ups.

Where we get it

  • From you, when you sign up, use the dashboard or run the ushr CLI.
  • From your workspace admins, when they invite you, give you a role, or act in the workspace (audit log).
  • From Google or GitHub, when you sign in with them.
  • From GitHub, when you verify a scope and through workflow job webhooks.
  • From the ushr agent on your hosts.
  • From Stripe, about your subscription and payments.

IP location

We look up IP locations on our own server, in a copy of the DB-IP "IP to City Lite" database. No IP address goes to a third party for this. The result is an approximate city and country. We keep it in memory only, for at most 500 IP addresses at a time, and never write it to the database. Private or unknown IP addresses show no location. IP Geolocation by DB-IP, licensed under CC BY 4.0.

Website analytics

We use Google Analytics 4 only on our public pages: the home page, pricing, security, the GitHub runner fee page, status, our legal pages, the docs and the comparison pages. It runs only on ushr.io. We do not add it to the dashboard or any other signed-in page. If you open a signed-in page from a public page in the same tab, Google's script stays loaded in that tab.

For each page view we send the page's route pattern (for example https://ushr.io/docs/billing), never IDs or query strings. We send the previous route pattern, or only the domain of an outside referring site. We also send two events: clicks on "Start free" and on "Sign in". Google signals and ad personalisation are off. We show no ads. Google Analytics does not store or log IP addresses.

If Google places you in the European Economic Area, the United Kingdom or Switzerland, analytics cookies are off until you accept them. Google decides this from your IP address. Before you choose, or if you decline, Google receives cookieless pings with your IP address (which Google may use to estimate your region), browser user agent, timestamp, referrer, consent state and a random number per page load. No Google Analytics cookies are set until you accept. Elsewhere, Google Analytics sets its cookies when you load a public page.

We show a cookie banner on public pages when your browser time zone is in Europe or in a nearby EEA region, for example Iceland, Cyprus or Réunion. You can change your choice at any time with "cookie settings" at the bottom of each public page. You can also block Google Analytics with your browser settings or with Google's opt-out add-on.

Cookies and browser storage

  • Sign-in cookies keep you signed in.
  • A short-lived cookie links a GitHub App setup to the browser that started it.
  • Google Analytics sets its own first-party cookies (_ga) on ushr.io, as described above.
  • Your browser stores your analytics cookie choice locally. It is never sent to us.
  • Your browser stores your light or dark theme choice locally. It is never sent to us.
  • During CLI sign-in, GitHub setup or linking a sign-in method, your browser stores the login session ID, the workspace ID or your user ID for the current tab only. It removes them when that step ends or when you close the tab.

Why we use it, and our legal basis

  • To provide the Service: sign-in, scheduling, the dashboard, alerts, terms acceptance and billing. Basis: our contract with you.
  • To secure the Service: approving hosts, showing where a sign-in or host request came from, the audit log, and preventing abuse. Basis: our legitimate interest in protecting accounts and hosts from unauthorised access.
  • To understand how people use our public pages, so we can improve them. Basis: your consent where the law requires it, otherwise our legitimate interest in improving the website.
  • To meet legal, tax and accounting obligations. Basis: legal obligation.

You have the right to object to processing based on our legitimate interests. Email hello@paddo.tech to object.

Where we rely on your consent, you can withdraw it at any time with "cookie settings". This does not affect processing before you withdraw it.

You must give an email address to create an account. Without it we cannot provide the Service. All other data is optional, or the Service needs it to work.

We do not make decisions with legal or similarly significant effects on you only by automated means. One step is automatic: if a renewal payment stays unpaid for 7 days, the system applies the free plan limits to the workspace, based on its billing status.

We do not sell personal data. We do not use it for advertising.

Who receives it

These service providers process personal data for us:

  • Neon (USA (us-east-1)): Postgres database and sign-in service (accounts, sessions, workspaces). Stores all data listed above.
  • Fly.io (USA (iad, Ashburn, Virginia)): Hosts the web app, the control plane and the install script at get.ushr.io. Keeps server logs.
  • Resend (USA): Sends sign-in links, workspace invitations, host alert emails and failed-payment notices. Receives the recipient address and message.
  • Stripe (USA and other countries where Stripe operates): Takes payments, stores card and billing details, and calculates tax.
  • Google (USA and other countries where Google operates): Google Analytics on our public pages, as described above.

These recipients act on their own account:

  • Google and GitHub sign-in: If you sign in with them, they share your name, email address and profile image with us. Their own privacy policies apply.
  • GitHub: Organisation and repository verification, workflow job webhooks, and agent release downloads. Your runners and agent connect to GitHub directly. GitHub's privacy policy applies.
  • Stripe: Also acts on its own account for fraud and compliance checks. Stripe's privacy policy applies.
  • Slack and your webhook endpoints: Only if a workspace admin adds an alert channel. They receive host alerts, which include host names, at the URL the admin chose.

So we disclose personal data outside Australia, mainly to the United States. We use our providers' data processing terms, which require them to protect personal data. Where the GDPR or UK GDPR applies, those terms include the EU standard contractual clauses or the UK addendum, or another transfer tool that the law allows. Email us for a copy. Where Australian law applies, we remain accountable for how these providers handle your personal information.

How long we keep it

  • Live dispatch event feed: 30 days.
  • Job records (repository, workflow, job IDs, host name and timestamps): 13 months after the job ends.
  • Host tokens, including who approved them and from which IP address: 90 days after the token is revoked or replaced. A replaced token that a running host's GitHub App record still uses is kept until that host is revoked, then 90 days.
  • Host status and hosted GitHub App records: while the host is enrolled, then 90 days after its last token is revoked.
  • ushr login handshakes: they expire after 10 minutes. We delete them when the CLI collects its token, at the next login, or by a daily clean-up 1 day after expiry. So we keep them for at most about 2 days.
  • IP locations: in server memory only, never stored.
  • Sign-in sessions: until the session ends or expires. Our sign-in provider, Neon Auth, manages these records.
  • Alert records: until the condition clears.
  • Alert channels: until an admin removes them.
  • Join requests: until an admin approves or dismisses them.
  • Account, workspace, membership, audit log and terms acceptance records: while your account or workspace exists.
  • Server logs: for the period that Fly.io keeps them.
  • Google Analytics: event-level data for up to 14 months. Google keeps aggregated reports longer.
  • Former waitlist entries: we will delete them within 90 days after ushr launches.
  • Billing records: 5 years, as Australian tax law requires.

You can ask us to delete your account or workspace. We do this by hand. We will then delete its data, except data the law requires us to keep.

Your rights

You can ask to see or correct the personal data we hold about you. Depending on where you live, you may also have the right to delete or export it, to restrict or object to how we use it, and to withdraw consent. To use these rights, email hello@paddo.tech. We reply within 30 days.

To complain about how we handle your personal data, email us first. We acknowledge the complaint within 7 days and give you our answer within 30 days. If our answer does not satisfy you, you can complain to the OAIC at oaic.gov.au. If you live elsewhere, you can also complain to your local data protection authority.

Security

  • The website and control plane use HTTPS.
  • Our enrollment token records hold only a SHA-256 hash of each token.
  • When you run ushr login, the approved token passes through our database to your CLI. With CLI versions after v0.2.10, we store it encrypted to a key that only your CLI holds. The CLI keeps that key in memory only. With v0.2.10 or older, we store it in plain text until we delete the handshake, as described above.
  • We never receive your GitHub App private key, an installation token or a runner registration token. During hosted App setup, we hold GitHub's one-time setup code until your host finishes setup or starts a new setup for the same scope. If neither happens, we delete it 90 days after the host's last token is revoked. With CLI versions after v0.2.10, the code is encrypted to a key that only your host holds. With v0.2.10 or older, it is in plain text. GitHub accepts the code for 1 hour only.
  • We store each App's webhook secret, which GitHub issues, so we can check that webhooks come from GitHub.

Children

The Service is for businesses. It is not for children.

Changes

We will post changes to this policy on this page. We will email the workspace owners at least 30 days before a material change takes effect. See also our Terms of Service.

Contact

Privacy questions and requests: hello@paddo.tech. Post: Paddo Tech Pty Ltd, 2/290 Boundary Street, Spring Hill QLD 4000, Australia.