Privacy · Draft
Privacy policy. Draft for review.
This website
drivekarts.si is a set of static pages. It sets no cookies, runs no analytics and has no forms that send data.
It keeps one log: each download of the Karts CLI, meaning the install script and the release files. Each entry holds the time, the file, your IP address with its last part removed (for example 203.0.113.x), and the name of the tool or browser that asked. We use it only to count downloads. Visits to the pages themselves are not logged.
What we store when you sign in
Sign-in to the Karts dashboard is with GitHub. When you sign in, we store these details from your GitHub account and refresh them each time you sign in:
- your GitHub user id
- your GitHub login
- your name
- your primary verified email address
- your avatar URL
If you ask for early access through the dashboard, we also store your answers on the request form.
We ask GitHub only for permission to read your profile and email addresses (the read:user and user:email scopes). We don't get access to your repositories through sign-in.
Cookies on the dashboard
The dashboard at app.karts.kartikey.fyi uses one cookie to keep you signed in, and a short-lived one during GitHub sign-in to check that the sign-in you finish is the one you started. Neither is used for tracking or advertising.
Hosted environments that use the internet
A project can let its hosted environments reach the internet, using the internet: setting in karts.yml. This is off unless the project turns it on. When it's on, we log each connection those environments make: the time, the environment, the address and port it went to, how many bytes went each way, and whether we allowed or refused it and why. The log never holds what was sent or received. Your team can read it with karts egress log. We use it to apply usage limits and to look into abuse.
A project can also record its calls to outside services so it can replay them later, using the recordings: setting. A recording holds the requests and answers, with the passwords, keys and tokens we can recognise removed. We store recordings encrypted until your team deletes them or deletes the project.
How long we keep it
- Early-access requests are kept until we approve or decline them, and then for 90 more days.
- Your account details are kept while you have an account. When you delete your account, we remove them within 30 days.
- The download log is kept for 90 days.
- The connection log of hosted environments is kept for up to 30 days.
Asking us to delete your data
Anyone can ask us to delete the data we hold about them, whether or not they have an account. Email hello@karts.kartikey.fyi from the address we have for you, or tell us your GitHub login.
Before this policy is approved
Until this draft is approved, public sign-up is off: only existing members can sign in, and the early-access page shows an email address instead of a form. Nothing is collected from the public through the website or the dashboard.
Changes
If this policy changes, we will update this page and tell members by email before the change applies.