# Privacy Policy

- Section: Imprint > Privacy Policy
- Canonical: https://covdbg.com/imprint/privacy/

---

Last updated: September 2026

Liasoft GmbH ("we", "us") makes covdbg and runs the services behind it. This policy explains what personal data we collect, why, how long we keep it, and what your rights are under the General Data Protection Regulation (GDPR). It is written to match what the software actually does; the technical detail is on the [Data and Telemetry](/docs/reference/data-and-telemetry/) page.

## Who is responsible

Liasoft GmbH, Morsbacher Str. 8, 51597 Morsbach, Germany. For anything about your data, write to [our team](/company/contact/#email-addresses).

## Data the covdbg software sends

covdbg never sends your source code, file names, paths, or coverage data. It contacts our servers at three moments.

### Signing in

When you run `covdbg login`, you sign in with GitHub in your browser. We receive your GitHub user id and the email addresses you have verified with GitHub, and nothing about your repositories or organizations. We keep the id, the addresses, a display name, when your account was created, and when it was last active. This is what recognizes you when you sign in again and what matches your commits to you.

We keep a hash of each sign-in session, the name the client gave it, and when it was created, last used, and ended. Sessions expire after one year. You can end any of them on your profile.

Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR).

### License checks

Each run sends the repository's git remote URL, the email address in your git configuration, and, for a repository with no remote, the hash of its root commit, together with your sign-in or your team's project token. We record each decision: the time, the repository (normalized to host, owner, and name), the email address, whether the caller was a person or a project token, the outcome, and the reason. We also keep the repository and whether it is public.

To learn whether a repository is public, our service asks the repository's host the same anonymous question a `git clone` asks. The answer is cached for fifteen minutes.

Purpose: deciding whether a run is covered, attributing seats to the right people, and showing you and your team's owners what was decided. Legal basis: performance of the contract (Art. 6(1)(b)) and our legitimate interest in enforcing the license terms (Art. 6(1)(f)).

Decisions are kept while you have an account, because they are the record your dashboard and a team's adoption view are built from.

### Run telemetry

After a run, covdbg sends its own version, the Windows version, how long the program ran, and the program's exit code, attributed to your account through the license decision. We use this to see which versions are in use, to spot crashes, and to show you your own runs. Events are deleted after 180 days.

You can turn this off at any time by setting `COVDBG_TELEMETRY=off` or `telemetry: false` in `.covdbg.yaml`. Legal basis: our legitimate interest in maintaining the product (Art. 6(1)(f)), with the switch above as your objection.

## Teams and seats

When you create a team, invite somebody, or buy seats, we keep the team's name, its owners and members, the addresses invitations were sent to, and the seat count Paddle reports. A commit author a team's CI sees without a seat is listed for that team's owners with the address and the repository, so they can invite the person.

## Payments

Seats are sold through [Paddle](https://www.paddle.com/), our merchant of record. Paddle collects your name, billing address, and payment details, handles VAT, and is a separate controller with its own [privacy policy](https://www.paddle.com/legal/privacy). Paddle sends us the subscription state and the number of seats a team has paid for. We never receive your card details.

## Email

We send email in two cases: an invitation to a seat, and a sign-in link you requested. We do not send newsletters, and we do not share addresses with anyone.

## Support

When you write to us, we keep the correspondence for as long as needed to answer and to handle any follow-up.

## This website

covdbg.com serves pages built with Astro. Contact and quote forms temporarily store the details you enter in our database. We first email a verification link to the address you provide. Only after you confirm do we forward your request to our team. Links expire after one hour. A cleanup job removes expired message content within five minutes; successful or failed delivery attempts clear the message content immediately. Minimal request records, including a hash of the verification token and delivery status, expire after 24 hours and are removed by the next cleanup run.

The forms use a session cookie to protect submissions. Abuse protection stores keyed hashes of the connecting IP address and email address with attempt counts for an hour. Correspondence delivered to our team is kept as described under Support.

If configured, Google Analytics and our self-hosted Matomo load only after you allow analytics in the cookie banner. Google receives website usage information and uses analytics cookies to distinguish visits. Matomo runs on our own server at analytics.liasoft.de and sets its own first-party cookies, so that usage data is not passed to another analytics company. Neither service receives the query string of a page address. Advertising storage and personalization are disabled. You can withdraw your choice through Cookie settings in the footer, which also removes these cookies. See our [Cookie Policy](/imprint/cookies/) and [Google’s privacy policy](https://policies.google.com/privacy).

If you choose light or dark mode, the website stores that preference locally in your
browser as `covdbg-theme`. It is not sent to our server.

## Service logs and error monitoring

Our servers keep logs of failed requests, including the caller's IP address, so we can act on errors and abuse. We use Sentry for error monitoring on the server side. The covdbg client itself sends no crash reports.

## Retention

| Data | Kept |
|------|------|
| Account, addresses, teams, seats | While the account exists |
| Sign-in sessions | One year, or until ended |
| License decisions | While the account exists |
| Run telemetry | 180 days |
| Financial records | As long as tax law requires |
| Server logs | A short operational period |

## Your rights

Under the GDPR you can ask us to access, correct, delete, or export your data, to restrict or object to processing, and you can withdraw consent where processing rests on it. You can also complain to a supervisory authority. Write to [our team](/company/contact/#email-addresses); we answer within a month.

## Security

Data travels over TLS. Sign-in credentials and project tokens are stored hashed. License decisions are signed so that they cannot be forged. Access to production systems is limited to the people who operate them.

## Changes

We update this policy when the software or the services change. The date at the top says when.
