deployhealth

Privacy

Last updated: 30 September 2026

The hosted deployhealth service is run by Utsav Mishra (India). This page says what it stores about you, for how long, where, and how to have it deleted. The technical detail is on Security.

What we store

  • Your account: your GitHub id, login, name, email address and avatar URL, from GitHub sign-in. Sign-in reads your GitHub profile (id, login, name and avatar) and your email address, even if it is private on GitHub (GitHub scopes read:user, user:email). Sign-in gets no access to your repositories; the optional GitHub App is separate.
  • Environment variable names and file:line for each deploy the scanner reports (commit sha, branch and time), the findings (missing, unused, out of sync), and the names each env file defines.
  • Endpoint URLs you add, and for each check its time, status code, latency and a short error reason.
  • Alerts (when they opened and resolved, and the message) and your alert webhook URL. Logs show only the webhook's host.
  • Ingest tokens, as a SHA-256 hash only.
  • Pull request check summaries, if you install the GitHub App: the pull request number, its author, whether a coding agent wrote it, variable names with file:line, the names of committed env files and a count of secret-shaped strings.
  • What you type in: clients, their contact emails, notes and deploy notes.

What we never store

  • The values of your environment variables.
  • Response bodies from the endpoints we check.
  • The contents of your files (the GitHub App discards them when a check finishes).
  • Secret strings found in pull requests (only how many there were).

How we use your email address

To tell you about a security incident that affects your data, and later for alert and account emails you choose to receive. Never for marketing, and it is never shared with anyone.

How long we keep it

Raw checks are deleted after 30 days; daily totals are kept for monthly reports. Uninstalling the GitHub App deletes its pull request checks. Everything else is kept while your account exists, until you ask us to delete it.

Where it is stored, and who processes it

The service and its database run on Railway, in its Singapore region. These companies process data for the service:

  • Railway: hosting and the database.
  • Cloudflare: DNS and the proxy in front of the site.
  • GitHub: sign-in, and the optional GitHub App for pull request checks.

Cookies and tracking

No analytics, no advertising and no tracking of any kind. The only cookies are the ones sign-in needs: your session cookie, and short-lived ones the sign-in library uses while you sign in (CSRF protection and the OAuth state).

Deleting your data

Ask at a private security advisory on GitHub from the email address on your GitHub account, and we will delete your account and everything it owns within 30 days. Self-serve deletion in the app is planned.

Contact

Questions about this page, or about your data: a private security advisory on GitHub.