Skip to content
ReleaseOrigin
January guideSampleTemplatesAsk about a pilot

P Privacy

Public evidence. Minimal inquiry data.

Effective September 4, 2026

What an inquiry stores

If you submit the fit-review form, ReleaseOrigin stores the name, work email, company or team, exact npm package name, request type, selected CI-provider category, optional desired outcome, consent, submission time, status, and site source needed to assess and respond. The database has no token, password, credential, private-repository, upload, attachment, file, phone, or mailing-address field.

What the public checker reads

The checker accepts only an exact npm package name and constructs its own npm public registry destinations. If you explicitly enable repository inspection, it may read bounded public workflow-path and workflow-content signals derived only from the current package document’s declared public GitHub or GitLab repository. It reports minimized signal names rather than workflow contents or secret values. It does not accept a repository URL from you, fetch a private repository, download a package tarball, install dependencies, or execute package code.

What the checker retains

Checker inputs and results are not written to the inquiry database. A completed public result may remain briefly in server memory to reduce repeat upstream requests. Short-lived in-memory throttling may use a network address to limit abuse, but ReleaseOrigin does not write that address into its lead records.

Credentials and files are prohibited

Do not submit tokens, passwords, API keys, private keys, credentials, customer data, private links, attachments, or file contents. The inquiry endpoint rejects unsupported fields and recognizable credential-like content. If sensitive information is sent despite these controls, ask for deletion promptly.

How inquiry details are used

Inquiry details are used to assess fit, reply, prepare an accepted scope, deliver agreed work, and maintain necessary business records. They are not sold or used for unrelated advertising.

Analytics, cookies, and hosting

ReleaseOrigin does not use analytics and does not set advertising cookies. Cloudflare hosts and protects the site and may process standard request and security information under its own terms.

Retention and requests

Inquiry records are kept only as long as reasonably needed for fit review, correspondence, delivery, dispute prevention, and applicable recordkeeping. To request access, correction, or deletion, use the inquiry form and write “Privacy request” in the desired-outcome field. Some records may need to be retained where law or a legitimate business obligation requires it.

Changes

If this notice changes materially, the effective date on this page will be updated.

© 2026 ReleaseOrigin.

PrivacyTerms