What an inquiry stores
If you submit the fit-review form, ReleaseOrigin stores the name, work email, company or team, exact npm package name, request type, selected CI-provider category, optional desired outcome, consent, submission time, status, and site source needed to assess and respond. The database has no token, password, credential, private-repository, upload, attachment, file, phone, or mailing-address field.
What the public checker reads
The checker accepts only an exact npm package name and constructs its own npm public registry destinations. If you explicitly enable repository inspection, it may read bounded public workflow-path and workflow-content signals derived only from the current package document’s declared public GitHub or GitLab repository. It reports minimized signal names rather than workflow contents or secret values. It does not accept a repository URL from you, fetch a private repository, download a package tarball, install dependencies, or execute package code.
What the checker retains
Checker inputs and results are not written to the inquiry database. A completed public result may remain briefly in server memory to reduce repeat upstream requests. Short-lived in-memory throttling may use a network address to limit abuse, but ReleaseOrigin does not write that address into its lead records.
Credentials and files are prohibited
Do not submit tokens, passwords, API keys, private keys, credentials, customer data, private links, attachments, or file contents. The inquiry endpoint rejects unsupported fields and recognizable credential-like content. If sensitive information is sent despite these controls, ask for deletion promptly.
How inquiry details are used
Inquiry details are used to assess fit, reply, prepare an accepted scope, deliver agreed work, and maintain necessary business records. They are not sold or used for unrelated advertising.
Analytics, cookies, and hosting
ReleaseOrigin does not use analytics and does not set advertising cookies. Cloudflare hosts and protects the site and may process standard request and security information under its own terms.
Retention and requests
Inquiry records are kept only as long as reasonably needed for fit review, correspondence, delivery, dispute prevention, and applicable recordkeeping. To request access, correction, or deletion, use the inquiry form and write “Privacy request” in the desired-outcome field. Some records may need to be retained where law or a legitimate business obligation requires it.
Changes
If this notice changes materially, the effective date on this page will be updated.