1. Introduction
This Privacy Policy describes how Secret Headquarters, LLC (“Company”, “we”, “us”) collects, uses, and protects information when you use the Prodgator platform (“Service”). We are committed to protecting your privacy and handling your data transparently. By using the Service, you consent to the practices described in this policy.
2. Information We Collect
2.1 Account Information
When you sign up through our identity provider (WorkOS AuthKit), we receive and store:
- Name and email address
- Organization membership and role (reader, operator, editor, or admin)
- Profile information associated with your identity provider account
2.2 CI/CD Pipeline Data
When you connect source control providers (e.g., GitHub) to the Service, we collect and process:
- Pipeline run metadata (status, duration, timestamps, branch and commit references)
- Pipeline stage and job information
- Deployment records (environment, status, timestamps)
- Repository metadata (name, organization, visibility)
- Webhook payloads from your CI/CD provider
- Security alert information from connected repositories
2.3 Usage Data
We automatically collect limited technical data when you use the Service:
- WebSocket connection metadata (connection ID, timestamps) for real-time updates
- Notification delivery and read status
- Feature usage patterns within the application
3. How We Use Your Information
We use the collected information to:
- Provide and operate the Service, including real-time pipeline monitoring and analytics
- Generate DORA metrics, failure analysis, and engineering performance insights
- Power AI-driven failure classification and anomaly detection
- Deliver notifications and alerts based on your configured preferences
- Enforce role-based access control within your organization
- Track compliance policies and generate audit records
- Maintain and improve the reliability and security of the Service
4. AI and Machine Learning
The Service uses AI-powered features for failure classification, anomaly detection, and intelligent alerting. We want to be explicit about how your data relates to these features:
- We do not use your data to train AI models. Your pipeline data, logs, repository information, and any other customer data are never used as training data for artificial intelligence or machine learning models.
- AI features analyze your data in real time to provide insights but do not retain data beyond what is necessary for the Service to function
- AI-generated classifications and alerts are derived from your data at the time of analysis and are not used to build generalized models
5. Data Storage and Security
5.1 Infrastructure
The Service runs on Amazon Web Services (AWS). Data is stored in United States regions and is encrypted at rest with AES-256. All data in transit is encrypted with TLS 1.2 or higher.
5.2 Data Isolation
Customer data is logically isolated by organization. Each organization’s data is partitioned using unique organization identifiers, ensuring that one organization cannot access another’s data. Role-based access controls further restrict data visibility within an organization.
5.3 Access Controls
Access to the Service is authenticated via WorkOS AuthKit and authorized through a JWT-based Lambda authorizer. Administrative access to infrastructure is restricted to authorized personnel and subject to audit logging.
6. Data Retention
We retain data according to the following practices:
- Account data is retained for the duration of your account and deleted upon account termination, subject to any legal retention requirements
- Pipeline and deployment data is retained for as long as your organization’s account is active, to support historical analytics and trend reporting
- Webhook payloads are stored with automatic time-to-live (TTL) expiration and are deleted automatically after processing
- WebSocket connection records are transient and are removed when connections are closed
- Notifications are retained in accordance with your organization’s retention settings
You may request deletion of your data at any time by contacting us. Organization administrators can also manage data through the Service’s settings.
7. Data Sharing and Disclosure
We do not sell your personal information or customer data. We may share data only in the following circumstances:
- Service providers: We use third-party services (AWS for hosting, WorkOS for authentication) that process data on our behalf under appropriate data processing agreements
- Third-party integrations: When you connect platforms like GitHub, data flows between those services and Prodgator as necessary to provide the Service. This is initiated and controlled by you
- Legal requirements: We may disclose data if required by law, subpoena, court order, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others
- Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you of any such change
8. Cookies and Tracking
The Service is a single-page application that uses authentication tokens stored in browser storage to maintain your session. We do not use third-party advertising cookies or cross-site tracking technologies. Any cookies used are strictly necessary for the Service to function (e.g., session management and authentication state).
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain processing of your data
- Request portability of your data in a machine-readable format
- Withdraw consent where processing is based on consent
To exercise any of these rights, please contact us at privacy@prodgator.io. We will respond to requests within 30 days or as required by applicable law.
10. International Data Transfers
The Service is hosted on AWS infrastructure primarily in the United States. If you access the Service from outside the United States, your data may be transferred to and processed in the United States. We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy and applicable data protection laws.
11. Children’s Privacy
The Service is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice in the Service. The “Last updated” date at the top of this page indicates when the policy was most recently revised. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at privacy@prodgator.io.