Privacy notice
This notice explains the information Manzanita processes to provide managed Apple Silicon runners.
Information we process
- GitHub identity, organization membership, installation ID, and the names and visibility of repositories you authorize.
- CI operational metadata such as workflow and branch names, timestamps, status, queue time, runtime, runner assignment, and cache result.
- Billing customer, subscription, invoice, and plan identifiers returned by Stripe. Payment card details are entered on Stripe-hosted Checkout and do not pass through Manzanita.
- Security and reliability data such as session records, signed webhook delivery IDs, audit events, IP-derived login throttling fingerprints, and node health.
- Information you send to support.
Source code and build data
The Manzanita control plane does not proxy or store repository source, build logs, artifacts, or GitHub Actions secrets. A disposable runner VM retrieves job data directly from GitHub, executes the job, returns logs and artifacts to GitHub, and is destroyed after the job. Customers remain responsible for GitHub Actions permissions and secret exposure in their workflows.
How we use and share information
We use information to authenticate users, schedule and meter runners, prevent abuse, support billing, diagnose failures, and secure the service. We use GitHub for identity and CI coordination, Stripe for billing, and Cloudflare for the web control plane and database. We do not sell personal information.
Retention and deletion
Expired login sessions are removed automatically. Webhook delivery records are retained for up to 30 days and audit events for up to one year. Account and job metadata is retained while the organization uses the service or as reasonably needed for security, billing disputes, and legal obligations. Organization owners can delete Manzanita organization data from Dashboard → Account after canceling any active subscription. Stripe and GitHub retain information under their own policies.
Security
We use HTTPS, signed webhooks, least-privilege GitHub App access, short-lived runner credentials, disposable VMs, network isolation, and access-controlled operations. No service can promise absolute security; report suspected issues to security@manzanita.run.
Contact
Questions or privacy requests: hello@manzanita.run. Manzanita operates from Menlo Park, California.