Privacy Policy

Last updated: July 2026

1. Who we are

EmitCI is a software-as-a-service platform that measures and reports the carbon footprint of CI/CD pipelines. References to "EmitCI", "we", "us", or "our" in this policy refer to the EmitCI service.

2. What data we collect

When you install the EmitCI GitHub App and use our service, we collect the following:

GitHub organisation or account name, GitHub username, and avatar URL (from OAuth login) · Repository names, default branches, and primary programming language · Workflow run IDs, workflow names, trigger events, branch names, and Git commit SHAs · Job names, runner labels (e.g. ubuntu-latest), job start and end times · Step names and durations within each job · Calculated energy estimates (kWh) and CO₂ estimates (grams) per run, job, and step · Billing email address (collected at checkout) · Stripe customer ID and subscription status — we never store card numbers or payment details.

We do not collect or store application source code, commit messages, pull request diffs, GitHub secrets, or environment variables. We do read workflow YAML files (.github/workflows/*.yml) and Dockerfiles from your repositories to generate CI optimisation recommendations — these files are analysed in memory and are not stored; only the resulting recommendations are saved.

3. Legal basis for processing (GDPR)

We process your data under the following lawful bases:

Contract (Article 6(1)(b)): To provide the EmitCI service you have signed up for, including energy estimation, alerting, and report generation.

Legitimate interests (Article 6(1)(f)): To improve our emission estimation models using anonymised, aggregated benchmark data; to detect and prevent abuse; and to send product-related communications to existing customers.

Legal obligation (Article 6(1)(c)): To retain billing and financial records as required by applicable tax law.

4. How we use your data

We use the data we collect to:

Estimate and display energy consumption and CO₂ emissions per CI run · Send budget alerts, anomaly notifications, and billing reminders · Generate ESG and annual impact reports at your request · Provide runner optimisation recommendations · Improve our carbon estimation models using anonymised benchmark contributions (see Section 9) · Manage your subscription and process payments via Stripe.

5. Data sharing

We do not sell your data. We do not share your data with advertising networks or data brokers. Data is shared only with the subprocessors listed in Section 6 and any ESG webhook endpoints you configure yourself in Settings → Integrations.

6. Subprocessors

We use the following third-party subprocessors to operate the service:

Fly.io (United States) — cloud infrastructure and database hosting · Stripe, Inc. (United States) — payment processing and billing · SendGrid / Twilio (United States) — transactional email delivery · Anthropic (United States) — AI-powered workflow analysis (only when you use EmitCI-funded AI reviews; not used for BYOK customers) · GitHub, Inc. (United States) — integration platform; data retrieved via GitHub App API.

Each subprocessor is bound by a Data Processing Agreement and is required to maintain appropriate security standards.

7. International data transfers

EmitCI's servers are operated by Fly.io and located primarily in the United States (Virginia, us-east). If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, your data is transferred to the United States when you use the service.

We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for these transfers. Copies of the applicable SCCs are available on request at [email protected].

8. Data retention by plan

Workflow run data (energy estimates, CO₂ values, job and step breakdowns) is retained for the following periods based on your subscription plan, after which it is permanently and irreversibly deleted:

Free plan: 30 days · Starter plan: 90 days · Team plan: 1 year · Enterprise plan: 2 years

Billing records (invoices, payment history) are retained for 7 years as required by applicable tax and financial record-keeping law. These records are held by Stripe and are subject to Stripe's own retention obligations.

Personal account data (GitHub username, billing email) is retained for as long as your account is active. See Section 10 for what happens when you delete your account.

9. Benchmark programme

To improve the accuracy of our carbon estimation models, we contribute anonymised and aggregated benchmark data from workflow runs to a shared dataset. This means we may record the average energy per run for a given language, runner type, and workflow category — with no information that identifies your organisation, repository name, or workflow name.

You can opt out of benchmark contributions at any time in Settings → Advanced → Benchmark sharing. Opting out does not affect your access to benchmark comparisons in the dashboard.

10. Account deletion

You can permanently delete your account at any time from Settings → Account → Delete Account. Deletion is immediate and irreversible.

On deletion, we permanently erase: your GitHub username and billing email · all workflow run records, job data, step data, and CO₂ estimates for your repositories · all generated ESG reports and annual impact reports · all carbon goals, budgets, anomaly records, and recommendations.

Stripe billing records are not deleted — they are retained as required by financial law. Anonymised benchmark contributions (which do not identify your organisation) are also not deleted as they form part of an aggregated dataset.

11. Service discontinuation

In the event that we discontinue the EmitCI service, we will provide at least 30 days' advance notice by email to the billing address associated with your account and via a prominent notice on our website and status page.

During the notice period, you will be able to export all your data in CSV format from Settings → Exports and download any generated ESG or annual impact reports. We strongly recommend downloading your data promptly upon receiving a discontinuation notice.

After the export window closes, all personal data and workflow run data will be permanently deleted from our servers. Billing records held by Stripe will be retained for the legally required period.

If you have an active paid subscription at the time of discontinuation, you will receive a prorated refund for any unused portion of your billing period.

12. Security

Data is encrypted in transit using TLS 1.3 and at rest using AES-256. Access to production systems is restricted to authorised personnel via multi-factor authentication. See our Security page for full details.

13. Cookies

We use a single session cookie to keep you logged in. We do not use tracking cookies, analytics cookies, or third-party advertising cookies. No cookie consent banner is required because the session cookie is strictly necessary for the service to function.

14. Your rights

Under GDPR (and equivalent laws in the UK and other jurisdictions), you have the following rights:

Access: request a copy of the personal data we hold about you · Correction: request correction of inaccurate data · Deletion: delete your account and all associated data instantly via Settings → Account → Delete Account · Portability: export your workflow run data in CSV format at any time from Settings → Exports · Objection: object to processing based on legitimate interests · Restriction: request that we restrict processing while a dispute is resolved.

To exercise any of these rights, contact [email protected]. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.

15. Changes to this policy

We will notify you of material changes to this policy via email at least 14 days before they take effect. Minor changes (such as clarifications or updated subprocessor lists) will be noted at the top of this page with a new effective date. The current version is always available at this URL.

16. Contact

For privacy-related requests or questions, contact [email protected]. For general enquiries, contact [email protected].