cronwakeHome

Privacy Policy

Last updated: 18 July 2026

1. Who we are (data controller)

Cronwake is operated by Nicolas Dolegieviez EI, a sole trader (entrepreneur individuel, micro-entreprise) registered in France under SIREN 820 913 168, at 6 rue Désirée, 69001 Lyon, France, who is the data controller. For any question about this policy or your personal data, contact us at cronwake@gmail.com.

2. Scope

This policy explains what personal data Cronwake processes when you install and use the Cronwake GitHub App and dashboard (cronwake.com), why, on what legal basis, with whom we share it, and your rights. Cronwake is built around data minimisation.

3. What we process, why, and our legal basis

  • Your GitHub account information (account login, and the name and avatar GitHub returns when you sign in). Purpose: authenticate you and show you only your own installations. Legal basis: performance of the service you request, and our legitimate interest in securing access.
  • Installation and repository metadata (which orgs and repositories the App is installed on, repository full names). Purpose: know what to monitor. Legal basis: performance of the service.
  • Scheduled-workflow metadata (workflow name, file path, cron expression(s), timezone, current on/off state) and observed run history (run id, start time, conclusion, duration, and the GitHub link to the run). Purpose: detect late, missed, or silently disabled crons and build reliability history. Legal basis: performance of the service.
  • Your alert routing configuration (the destinations you enter yourself: a Slack or webhook URL, an on-call or chat integration key). Purpose: deliver alerts where you choose. Legal basis: performance of the service.
  • Your GitHub access token, held only inside an encrypted, httpOnly session cookie in your browser, never exposed to page scripts and never stored server-side in plaintext. Purpose: act on your behalf, read-only, for the duration of your session. Legal basis: performance of the service.
  • Technical data (IP address, timestamps) in hosting logs. Purpose: operate and secure the service. Legal basis: our legitimate interest.

We never collect or store your repository source code, your secrets, tokens or environment variables, or your workflow run logs (we only link to them on GitHub).

4. Cookies

We use a single, strictly necessary cookie: an encrypted, httpOnly session cookie that keeps you signed in. We do not use advertising or analytics/tracking cookies, so no consent banner is required.

5. Who we share data with (subprocessors)

  • Vercel: application hosting (dashboard and serverless functions). US-based.
  • Neon: managed PostgreSQL database storing the metadata above, encrypted at rest. US-based.
  • GitHub: the platform we read from, under the read-only permissions you grant at install.
  • Paddle: our reseller and Merchant of Record for paid subscriptions. Billing is not enabled yet, so no payment data exists today. Once paid plans launch, Paddle will collect and process the billing details of subscribing organizations as the seller of record, under its own privacy notice. We never see or store card details.
  • Your chosen alert destinations: when you configure an alert channel (e.g. Slack, a webhook, an on-call or chat tool), we transmit alert messages to that destination at your instruction. Those providers are your choice, not subprocessors we impose.

The up-to-date list of what we can access and store is on our Security page.

6. International data transfers

Our subprocessors Vercel and Neon are located in the United States. Where personal data of individuals in the EEA is transferred there, the transfer relies on the EU-US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses.

7. Retention

We keep the metadata listed above while the App is installed. When you uninstall, GitHub immediately revokes our access and we deactivate your stored monitoring metadata; we delete it on request and purge deactivated data we no longer need to run the service. Session cookies expire at the end of your session.

8. Your rights

You have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability. To exercise any of these, email cronwake@gmail.com; we respond within one month. You also have the right to lodge a complaint with a supervisory authority (in France, the CNIL).

9. Automated decision-making

Cronwake does not make automated decisions producing legal or similarly significant effects about you.

10. Is providing your data required?

To use Cronwake you need a GitHub account and to install our GitHub App; without this we cannot provide the monitoring service. Configuring an alert channel is optional.

11. Security

Read-only GitHub scopes (no write access), data encrypted at rest, access tokens kept only in an encrypted httpOnly cookie, and least-privilege access to the service.

12. Changes to this policy

We may update this policy; the “Last updated” date reflects the latest version. Material changes will be signposted on the dashboard.