Legal
Privacy Policy
What we collect, why, who else sees it, and for how long. Last updated 29 July 2026.
What we collect
From GitHub, about your repositories: repository ids, names and visibility; branch names; pull request numbers and head commit SHAs; the GitHub logins of people who act in Fwozen; and the branch rules that determine whether a freeze would hold.
From you, as text you write: freeze reasons, exception reasons, schedule names, and organisation settings. These appear on pull requests, in Slack, and in your audit log, so don’t put secrets in them.
About your account: name, email address, and organisation membership, through WorkOS.
Usage: a small number of named product events (an install completed, a freeze created) through PostHog, with autocapture switched off. We do not send repository names to the analytics provider.
What we never collect
Source code, diffs, commit messages, pull request titles or bodies, and committer email addresses. This is not a policy promise layered over a system that could do otherwise: incoming GitHub webhooks are projected at ingest, commits are reduced to SHAs, and those fields are dropped before anything is written to the database. There is a test over real GitHub payloads asserting the keys are absent.
Why we collect it
To operate the freeze engine — writing check runs to the right commits, verifying enforcement, running schedules in the right timezone — and to keep an audit log you can answer questions from six months later. There is no other purpose. We do not sell data, and we do not train models on it.
Who else processes it
| Subprocessor | What it does | What it sees |
|---|---|---|
| Railway | Application hosting and Postgres, US region | Everything Fwozen stores |
| WorkOS | Authentication, sessions, SSO and directory sync | Name, email, GitHub login, org membership |
| Stripe | Payments, invoices, tax | Billing contact, address, card token (Stripe holds the card, we never see it) |
| Slack | The Slack app and freeze notifications | Workspace and channel ids, freeze reasons posted to your channel |
| GitHub | The product itself | Repository, branch, and pull request metadata; check run results |
| PostHog | Product analytics on explicit events, autocapture off | Anonymous usage events, org id, no repository names |
Where it lives
Railway, United States region. Encrypted at rest, TLS in transit. Tokens are encrypted with a dedicated key and never logged. No production data on developer machines.
How long we keep it
Freeze history follows your plan: 7 days on Free, 90 days on Team, unlimited on Business. Retention is applied when reading rather than by deleting, so upgrading restores the full history. Delete your organisation and everything goes. After cancellation, private data is purged within 30 days.
Your rights
Access, correction, export, and deletion — mail [email protected] and we will action it. Most of it you can do yourself in the app, which is faster than asking us.
Support access
If we need to look at your organisation to help you, the session is read-only and it is recorded in your own audit log. Nobody here can create or lift a freeze in your organisation.
Security
Details, including every GitHub permission we request and what it does not allow, are on the security page. Report a vulnerability to [email protected]; we acknowledge within 72 hours.
Cookies
One session cookie for the dashboard, and a localStorage entry remembering whether you chose the light or dark theme. The marketing pages you are reading now set nothing until you sign in.