Manzanita
Effective September 2, 2026

Privacy notice

This notice explains the information Manzanita processes to provide managed Apple Silicon runners.

Information we process

Source code and build data

The Manzanita control plane does not proxy or store repository source, build logs, artifacts, or GitHub Actions secrets. A disposable runner VM retrieves job data directly from GitHub, executes the job, returns logs and artifacts to GitHub, and is destroyed after the job. Customers remain responsible for GitHub Actions permissions and secret exposure in their workflows.

How we use and share information

We use information to authenticate users, schedule and meter runners, prevent abuse, support billing, diagnose failures, and secure the service. We use GitHub for identity and CI coordination, Stripe for billing, and Cloudflare for the web control plane and database. We do not sell personal information.

Retention and deletion

Expired login sessions are removed automatically. Webhook delivery records are retained for up to 30 days and audit events for up to one year. Account and job metadata is retained while the organization uses the service or as reasonably needed for security, billing disputes, and legal obligations. Organization owners can delete Manzanita organization data from Dashboard → Account after canceling any active subscription. Stripe and GitHub retain information under their own policies.

Security

We use HTTPS, signed webhooks, least-privilege GitHub App access, short-lived runner credentials, disposable VMs, network isolation, and access-controlled operations. No service can promise absolute security; report suspected issues to security@manzanita.run.

Contact

Questions or privacy requests: hello@manzanita.run. Manzanita operates from Menlo Park, California.